[Dailydave] Useless fact of the day!
Rhys Kidd
rhyskidd at gmail.com
Sat Jan 6 08:39:50 EST 2007
RPC memory exhaustion bugs are all the rage atm it would seem,
hopefully this will provide the traction for MSRC to give it
priority....
It's also interesting that ISC believe for servers that the current
UPnP and SPOOLSS bugs are 'Important', whereas the more recent
NetrWkstaUserEnum() bug is only 'Less Urgent'.
They are pretty much the same, due to unvalidated client input, and in
fact the NetrWkstaUserEnum() opnum ( through the wkssvc named pipe )
is usually bindable over an anonymous NULL session.
- Rhys
More information about the Dailydave
mailing list