This link has been bookmarked by 58 people . It was first bookmarked on 15 Jun 2006, by Mohan.
-
23 Jul 07
-
02 Jul 07
-
25 Apr 07
-
20 Mar 07
-
05 Mar 07
-
21 Nov 06
-
14 Nov 06
-
10 Nov 06
-
08 Nov 06
-
24 Sep 06
-
MS05-051 Scan v1.0
Vulnerabilities in MSDTC and COM+ Could Allow Remote Code Execution
Copyright 2005© by McAfee, Inc.
http://www.foundstone.com
MS05-051 Scan 1.0 is a Windows based detection and analysis utility that can quickly and accurately identify Microsoft operating systems that are vulnerable to the vulnerabilities released in the MS05-051 bulletin.
MS05-051 Scan is intended for use by enterprise system and network administrators as a fast and reliable utility for identifying at risk Microsoft systems in a passive manner. This tool is non-abrasive in nature and may be run in production environments during production hours.
Limitations of the tool:
The scanner is limited to 10 outgoing connections on WIndows XP SP2. This scanning limitation is caused by SP2. All other platforms will have 64 concurrent scanning threads running.If you have anti-virus running it *may* detect this tool as an exploit. This tool *does NOT* exploit the vulnerabilty it simply determines if the machine is vulnerable or not.
Vulnerability Information:
A remote code execution and local elevation of privilege vulnerability exists in the Microsoft Distributed Transaction Coordinator that could allow an attacker who successfully exploited this vulnerability to take complete control of the affected system.Using a null session, an attacker could make an RPC request to the DTC interface on a Microsoft Windows system and potentially execute arbitrary code.
This Foundstone check detects the absence of the patch by attempting to trigger the vulnerability in a nonintrusive manner over RPC.
Affected systems:
Microsoft Windows 2000 (All Versions)
For more information see:
http://www.microsoft.com/technet/security/bulletin/MS05-051.mspx -
<span class="Utxt2Bold">»</span> <span class="Utxt6Bold">SuperScan<br/> v4.0</span><br><br/> <br><br/> Powerful TCP port scanner, pinger, resolver.<br><br/> Copyright 2003 (c) by Foundstone, Inc.<br><br/> http://www.foundstone.com<br><br/> <br><br/> SuperScan 4 is an update<br/> of the highly popular Windows port scanning tool, SuperScan.<br/> <p></p><hr><br/> <p><b>Windows XP Service Pack 2 has removed raw sockets support which now limits SuperScan and many other network scanning tools. Some functionality can be restored by running the following at the Windows command prompt before starting SuperScan:</b><br/><br/> </p><p><b>net stop SharedAccess</b><br/> </p><hr><br/> <p>Here are some of the new features in this version.<br> <strong><br><br/> </strong><br/> <br><br/> <table border="0" cellpadding="0" width="95%" cellspacing="0" align="center"><br/> <tbody><tr><br/> <td><br/> <table border="0" cellpadding="4" width="100%" cellspacing="0" align="center"><br/> <tbody><tr><br/> <td valign="top" bgcolor="#d7d7d7" width="3%" align="right"><img src="http://www.foundstone.com/../../images/bullet_4.gif" height="9" width="5"></td><br/> <td bgcolor="#d7d7d7" width="97%">Superior scanning speed</td><br/> </tr><br/> </tbody></table><br/> </td><br/> </tr><br/> <tr><br/> <td height="1"></td><br/> </tr><br/> <tr><br/> <td><br/> <table border="0" cellpadding="4" width="100%" cellspacing="0" align="center"><br/> <tbody><tr><br/> <td valign="top" bgcolor="#d7d7d7" width="3%" align="right"><img src="http://www.foundstone.com/../../images/bullet_4.gif" height="9" width="5"></td><br/> <td bgcolor="#d7d7d7" width="97%">Support for unlimited IP ranges</td><br/> </tr><br/> </tbody></table><br/> </td><br/> </tr><br/> <tr><br/> <td height="1"></td><br/> </tr><br/> <tr><br/> <td><br/> <table border="0" cellpadding="4" width="100%" cellspacing="0" align="center"><br/> <tbody><tr><br/> <td valign="top" bgcolor="#d7d7d7" width="3%" align="right"><img src="http://www.foundstone.com/../../images/bullet_4.gif" height="9" width="5"></td><br/> <td bgcolor="#d7d7d7" width="97%">Improved host detection using<br/> multiple ICMP methods </td><br/> </tr><br/> </tbody></table><br/> </td><br/> </tr><br/> <tr><br/> <td height="1"></td><br/> </tr><br/> <tr><br/> <td><br/> <table border="0" cellpadding="4" width="100%" cellspacing="0" align="center"><br/> <tbody><tr><br/> <td valign="top" bgcolor="#d7d7d7" width="3%" align="right"><img src="http://www.foundstone.com/../../images/bullet_4.gif" height="9" width="5"></td><br/> <td bgcolor="#d7d7d7" width="97%">TCP SYN scanning</td><br/> </tr><br/> </tbody></table><br/> </td><br/> </tr><br/> <tr><br/> <td height="1"></td><br/> </tr><br/> <tr><br/> <td><br/> <table border="0" cellpadding="4" width="100%" cellspacing="0" align="center"><br/> <tbody><tr><br/> <td valign="top" bgcolor="#d7d7d7" width="3%" align="right"><img src="http://www.foundstone.com/../../images/bullet_4.gif" height="9" width="5"></td><br/> <td bgcolor="#d7d7d7" width="97%">UDP scanning (two methods)</td><br/> </tr><br/> </tbody></table><br/> </td><br/> </tr><br/> <tr><br/> <td height="1"></td><br/> </tr><br/> <tr><br/> <td><br/> <table border="0" cellpadding="4" width="100%" cellspacing="0" align="center"><br/> <tbody><tr><br/> <td valign="top" bgcolor="#d7d7d7" width="3%" align="right"><img src="http://www.foundstone.com/../../images/bullet_4.gif" height="9" width="5"></td><br/> <td bgcolor="#d7d7d7" width="97%">IP address import supporting ranges<br/> and CIDR formats </td><br/> </tr><br/> </tbody></table><br/> </td><br/> </tr><br/> <tr><br/> <td height="1"></td><br/> </tr><br/> <tr><br/> <td><br/> <table border="0" cellpadding="4" width="100%" cellspacing="0" align="center"><br/> <tbody><tr><br/> <td valign="top" bgcolor="#d7d7d7" width="3%" align="right"><img src="http://www.foundstone.com/../../images/bullet_4.gif" height="9" width="5"></td><br/> <td bgcolor="#d7d7d7" width="97%">Simple HTML report generation</td><br/> </tr><br/> </tbody></table><br/> </td><br/> </tr><br/> <tr><br/> <td height="1"></td><br/> </tr><br/> <tr><br/> <td><br/> <table border="0" cellpadding="4" width="100%" cellspacing="0" align="center"><br/> <tbody><tr><br/> <td valign="top" bgcolor="#d7d7d7" width="3%" align="right"><img src="http://www.foundstone.com/../../images/bullet_4.gif" height="9" width="5"></td><br/> <td bgcolor="#d7d7d7" width="97%">Source port scanning</td><br/> </tr><br/> </tbody></table><br/> </td><br/> </tr><br/> <tr><br/> <td height="1"></td><br/> </tr><br/> <tr><br/> <td><br/> <table border="0" cellpadding="4" width="100%" cellspacing="0" align="center"><br/> <tbody><tr><br/> <td valign="top" bgcolor="#d7d7d7" width="3%" align="right"><img src="http://www.foundstone.com/../../images/bullet_4.gif" height="9" width="5"></td><br/> <td bgcolor="#d7d7d7" width="97%">Fast hostname resolving</td><br/> </tr><br/> </tbody></table><br/> </td><br/> </tr><br/> <tr><br/> <td height="1"></td><br/> </tr><br/> <tr><br/> <td><br/> <table border="0" cellpadding="4" width="100%" cellspacing="0" align="center"><br/> <tbody><tr><br/> <td valign="top" bgcolor="#d7d7d7" width="3%" align="right"><img src="http://www.foundstone.com/../../images/bullet_4.gif" height="9" width="5"></td><br/> <td bgcolor="#d7d7d7" width="97%">Extensive banner grabbing</td><br/> </tr><br/> </tbody></table><br/> </td><br/> </tr><br/> <tr><br/> <td height="1"></td><br/> </tr><br/> <tr><br/> <td><br/> <table border="0" cellpadding="4" width="100%" cellspacing="0" align="center"><br/> <tbody><tr><br/> <td valign="top" bgcolor="#d7d7d7" width="3%" align="right"><img src="http://www.foundstone.com/../../images/bullet_4.gif" height="9" width="5"></td><br/> <td bgcolor="#d7d7d7" width="97%">Massive built-in port list description<br/> database </td><br/> </tr><br/> </tbody></table><br/> </td><br/> </tr><br/> <tr><br/> <td height="1"></td><br/> </tr><br/> <tr><br/> <td><br/> <table border="0" cellpadding="4" width="100%" cellspacing="0" align="center"><br/> <tbody><tr><br/> <td valign="top" bgcolor="#d7d7d7" width="3%" align="right"><img src="http://www.foundstone.com/../../images/bullet_4.gif" height="9" width="5"></td><br/> <td bgcolor="#d7d7d7" width="97%">IP and port scan order randomization</td><br/> </tr><br/> </tbody></table><br/> </td><br/> </tr><br/> <tr><br/> <td height="1"></td><br/> </tr><br/> <tr><br/> <td><br/> <table border="0" cellpadding="4" width="100%" cellspacing="0" align="center"><br/> <tbody><tr><br/> <td valign="top" bgcolor="#d7d7d7" width="3%" align="right"><img src="http://www.foundstone.com/../../images/bullet_4.gif" height="9" width="5"></td><br/> <td bgcolor="#d7d7d7" width="97%">A selection of useful tools (ping,<br/> traceroute, Whois etc) </td><br/> </tr><br/> </tbody></table><br/> </td><br/> </tr><br/> <tr><br/> <td height="1"></td><br/> </tr><br/> <tr><br/> <td><br/> <table border="0" cellpadding="4" width="100%" cellspacing="0" align="center"><br/> <tbody><tr><br/> <td valign="top" bgcolor="#d7d7d7" width="3%" align="right"><img src="http://www.foundstone.com/../../images/bullet_4.gif" height="9" width="5"></td><br/> <td bgcolor="#d7d7d7" width="97%">Extensive Windows host enumeration<br/> capability </td><br/> </tr><br/> </tbody></table><br/> </td><br/> </tr><br/> </tbody></table><br/> </p><p><span class="Utxt6Bold">Note that SuperScan 4 is intended<br/> for Windows 2000 and XP only. Administrator privileges<br/> are required<br/> to run the program.<br/> It will not <strong>run</strong> on Windows 95/98/ME. You may<br/> need to try <a rel="nofollow" href="http://www.foundstone.com/superscan3.htm"><b>SuperScan v3</b></a> if this will not work with your system.</span></p><br/>
-
-
28 Aug 06
-
26 Jun 06
-
20 Jun 06
-
15 Jun 06
-
03 May 06
-
20 Mar 06
-
18 Feb 06
-
01 Jan 06
-
19 Nov 05
-
15 Nov 05
-
28 Oct 05
-
22 Oct 05
-
07 Oct 05
-
26 Jul 05
-
22 Mar 05
-
14 Nov 04
-
12 Oct 04
-
28 Apr 04
-
08 Aug 03
Page Comments
Would you like to comment?
Join Diigo for a free account, or sign in if you are already a member.