[1185] in winnt
[Security-fyi] exploit for MS03-026 RPC vulnerability
daemon@ATHENA.MIT.EDU (Setchmo@aol.com)
Tue Aug 12 11:03:49 2003
From: Setchmo@aol.com
Message-ID: <c3.36be336e.2c6a5bb1@aol.com>
Date: Tue, 12 Aug 2003 11:03:13 EDT
To: leblancl@mit.edu
CC: goguen@mit.edu, infosys@mit.edu, mitvirus@mit.edu, security-fyi@mit.edu,
winpartners@mit.edu
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="part1_c3.36be336e.2c6a5bb1_boundary"
--part1_c3.36be336e.2c6a5bb1_boundary
Content-Type: text/plain; charset="US-ASCII"
Content-Transfer-Encoding: 7bit
"If a machine is a target of the currently available exploit programfor the
MS03-026 vulnerability, it will in some cases pop up a windowtitled "System
Shutdown" with the text:This system is shutting down. Please save all work in
progressand log off. Any unsaved changes will be lost. This shutdownwas initiated
by NT AUTHORITY\SYSTEMTime before shutdown: 00:00:59Message:Windows must
now restart because the Remote Procedure Call(RPC) service terminated
unexpectedly(The machine then reboots in 59 seconds.)This indicates an unsuccessful
exploit attempt on an unpatchedmachine. If customers see this message, they should
most likely savetheir work and then disconnect from the network, or else
patch themachine immediately after it reboots."
Do you have a patch for this? I may have solved this by deleting files in my
start menu folder named tftp2160 and tftp3796. Any further information would
be helpful.
Thanks Linda et Al
Seth
--part1_c3.36be336e.2c6a5bb1_boundary
Content-Type: text/html; charset="US-ASCII"
Content-Transfer-Encoding: quoted-printable
<HTML><FONT FACE=3Darial,helvetica><FONT SIZE=3D2>
<BR>"If a machine is a target of the currently available exploit programfor=20=
the MS03-026 vulnerability, it will in some cases pop up a windowtitled "Sys=
tem Shutdown" with the text:This system is shutting down. Please save all wo=
rk in progressand log off. Any unsaved changes will be lost. This shutdownwa=
s initiated by NT AUTHORITY\SYSTEMTime before shutdown: 00:00:59=
Message:Windows must now restart because the Remote Procedure Call(RPC) serv=
ice terminated unexpectedly(The machine then reboots in 59 seconds.)This ind=
icates an unsuccessful exploit attempt on an unpatchedmachine. If customers=20=
see this message, they should most likely savetheir work and then disconnect=
from the network, or else patch themachine immediately after it reboots."
<BR>
<BR> Do you have a patch for this? I may have solved this by deleting files=20=
in my start menu folder named tftp2160 and tftp3796. Any further infor=
mation would be helpful.
<BR>
<BR>Thanks Linda et Al
<BR>
<BR>Seth
<BR></FONT></HTML>
--part1_c3.36be336e.2c6a5bb1_boundary--