[nsp-sec] Report of successful WINS (ms09-039) compromise

Gabriel Iovino giovino at ren-isac.net
Mon Aug 17 13:37:00 EDT 2009


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Greetings,

We just got a report of two WINS servers at a .edu being compromised via
the MS09-039[1] vulnerability over the weekend.

The only information I have at this moment is the attacking IP was:

221.214.82.183

Is anyone aware of public exploit code?

I'll share more when I get more.

Gabe

- --
Gabriel Iovino
Principal Security Engineer, REN-ISAC
http://www.ren-isac.net
24x7 Watch Desk +1(317)278-6630

[1] http://www.microsoft.com/technet/security/bulletin/ms09-039.mspx


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAkqJlTwACgkQwqygxIz+pTsbzQCfb5ImW2sSnHOpQXtzXn0SDPOE
gNIAniwSIO7SiKcUoNqlQ7xckur6x9SB
=/BQ5
-----END PGP SIGNATURE-----



More information about the nsp-security mailing list