[Dailydave] Useless fact of the day!

Rhys Kidd rhyskidd at gmail.com
Sat Jan 6 08:39:50 EST 2007


RPC memory exhaustion bugs are all the rage atm it would seem,
hopefully this will provide the traction for MSRC to give it
priority....

It's also interesting that ISC believe for servers that the current
UPnP and SPOOLSS bugs are 'Important', whereas the more recent
NetrWkstaUserEnum() bug is only 'Less Urgent'.

They are pretty much the same, due to unvalidated client input, and in
fact the NetrWkstaUserEnum() opnum ( through the wkssvc named pipe )
is usually bindable over an anonymous NULL session.

- Rhys


More information about the Dailydave mailing list