****************
Exploit Code
****************
(6) Microsoft License Logging Service Overflow (MS05-010)
Description: Immunitysec, Inc. has released an exploit for the
“CRITICAL” buffer overflow in the Microsoft’s License Logging service
in its CANVAS product. Further, the researchers at Immunitysec claim
that no authentication is required to exploit the buffer overflow on
Microsoft Advanced Server 2000 SP3 and SP4 (depending on the way SP4 is
installed) platforms. Microsoft does not list these products as
critically vulnerable in the MS05-010 advisory.
References:
Postings by Dave Aitel
http://www.immunitysec.com/downloads/llssrv_miss.pdf
http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0087.html
http://archives.neohapsis.com/archives/vulnwatch/2005-q1/0087.html
Previous @RISK Newsletter Posting
http://www.sans.org/newsletters/risk/display.php?v=4&i=6#widely1
*******************************************************************
(7) Safenet Sentinel License Manager Buffer Overflow
Description: Hat-Squad team has released an exploit for the “CRITICAL”
overflow in the Sentinel License Manager service discussed in the last
week’s @RISK newsletter.
Council Site Actions: The affected software is not in production or
widespread use, or is not officially supported at any of the council
sites. They reported that no action was necessary.
References:
Exploit Code
http://www.hat-squad.com/en/000163.html
Previous @RISK Newsletter Posting
http://www.sans.org/newsletters/risk/display.php?v=4&i=10#other1
**********************************************************