Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [ISN] Hunt for XP SP2 flaws seen in full swing |
|---|---|
| Date: | Mon, 16 Aug 2004 03:26:55 -0500 (CDT) |
Forwarded from: security curmudgeon <jericho@attrition.org> : http://www.nwfusion.com/news/2004/0813huntforx.html : : By Joris Evers : IDG News Service : 08/13/04 : : While users are testing Service Pack 2 for Windows XP to prevent : compatibility problems, hackers are picking apart the security-focused : software update looking for vulnerabilities, security experts said. : : "We will see new vulnerabilities discovered in SP2 over the next few : weeks. Give it a month or two and we will also see worms that affect : SP2," said Thor Larholm, senior security researcher at PivX Solutions : LLC, a security services company in Newport Beach, Calif. As usual with Windows Service Packs, the first week or two is spent figuring out what features have changed or broken significantly. While most of the griping is about functionality breaking that was made public well in advance, a few other changes crept in that are of interest to the security world. (read below) : "A lot of the current attack vectors are blocked by SP2," Larholm said. : "Folks are now trying to find new ways to plant code on a system. A lot : of these new ways will use e-mail, instant messaging and Web traffic - : any kind of traffic that a PC requests from the outside world - because : that will go through the firewall without restrictions." Fortunately, all the MSIE exploits will still do nicely =) -- ------Original Message----- From: Fyodor [mailto:fyodor@insecure.org] Sent: Wednesday, August 11, 2004 3:31 PM To: nmap-hackers@insecure.org Subject: Windows XP SP2 incompatible with Nmap This is just a heads-up that most Nmap functionality will not work on the just-released Microsoft Windows SP2. Why? Microsoft apparently broke it on purpose! When an Nmap user asked MS why security tools such as Nmap broke, MS responded[1]: "We have removed support for TCP sends over RAW sockets in SP2. We surveyed applications and found the only apps using this on XP were people writing attack tools." I don't know why they consider Nmap an "attack tool", particularly when they recommend it on some of their own pages[2]. Shrug. Removing SP2 re-enables the functionality and causes Nmap to work again. Many problems unrelated to Nmap have been found with SP2 as well[3], though it does some welcome security improvements for people stuck on that platform. I will work on this if I get time, but am currently busy rewriting the core port scanning engine for the next version of Nmap. It is much faster, offers much better multiple-host parallelization, and provides other long-desired features such as completion time estimates. If someone finds a solution to this SP2 problem, please send a patch. It may not be too hard, as Nmap supports operating systems such as Win95 that didn't have raw socket support in the first place. Cheers, Fyodor [1] http://seclists.org/lists/nmap-dev/2004/Apr-Jun/0077.html [2] http://www.microsoft.com/serviceproviders/security/tools.asp [3] http://www.crn.com/sections/breakingnews/breakingnews.jhtml?articleId=23905071 -- The TCPIP.SYS modifications in XP SP2 have also limited the number of concurrent half-open TCP connections to -10-. Yeah. That means you can't try to connect to more than ten things at once unless one of them answers. This breaks most vulnerability scanning, p2p networking, and many game networks, but I think they were aiming to keep worms from spreading. There appears to be no registry key to change this setting. There is a 3rd party patch available for this: http://www.lvllord.de/ (site not resolving now) _________________________________________ Open Source Vulnerability Database (OSVDB) Everything is Vulnerable - http://www.osvdb.org/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [ISN] Cyber Fears on Fed's Web Plan, InfoSec News |
|---|---|
| Next by Date: | [ISN] Linux Security Week - August 16, 2004, InfoSec News |
| Previous by Thread: | [ISN] Hunt for XP SP2 flaws seen in full swing, InfoSec News |
| Next by Thread: | [ISN] US Emergency Alert System open to hack attack, InfoSec News |
| Indexes: | [Date] [Thread] [Top] [All Lists] |