The symptoms you describe sound like a reboot had not been done after the patch was
applied. If it happens again, check the registry key
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session
Manager\PendingFileRenameOperations and you should see a list of the files that
NT/2K/XP will copy and rename during the next reboot. The files in question are in use
when the patch is applied and are not replaced directly.
Maybe a reboot was done after deleting the backup files and deleting them was not the
cure but the reboot was?
-----Original Message-----
From: Carlton Foster [mailto:[EMAIL PROTECTED]
Sent: Wed 11/19/2003 01:58
To: Discussion of Nessus software
Cc:
Subject: Re: URGENT - Help with 11808 and 11835
Ok, that part seems simple enough. Now, on 2000 and above systems, I
know Nessus has been right every time in our environment. On the NT
systems, it has been right on every machine I have personally checked.
However, we have found something I need help understanding.
Unfortunately, I have to figure it out by 8am EST...
On atleast one NT4 Workstation system, the user looked for the files MS
says verify the patch installed:
Date Time Version Size File name
------------------------------------------------------
11-Aug-2003 11:29 4.0.1381.7230 701,200 Ole32.dll
11-Aug-2003 11:29 4.0.1381.7230 345,872 Rpcrt4.dll
11-Aug-2003 11:29 4.0.1381.7230 107,792 Rpcss.exe
They found these files in the system32 directory as they should be. But
they also found older versions of these files in a backup directory.
Upon deleting the older files and rescanning, the machine no longer
appeared as vulnerable.
This is where and why I am having a hard time with this. Since my
Nessus scanners do not have any SMB account info, and I do not have
access to nor an account on the machine in question, can anyone explain
this? Now, I told you what the user told me. I do not know what else
they may have done, like reboot...
I have faith in the Nessus scan results I am getting, but unfortunately
I have to convince alot more than me. Any thoughts, ideas, insights,
suggestions, are greatly appreciated.
Thanks again,
Carl
Renaud Deraison wrote:
>On Tue, Nov 18, 2003 at 05:07:34PM -0500, Carlton Foster wrote:
>
>
>>We are still finding a number of NT4 systems vulnerable according to
>>plugin 11808 for MS03-026 and 11835 for MS03-039. I need a question
>>answered definitively to end the debate.
>>
>>I am not a programmer and I am very new to Nessus, but if I understand
>>11808 and 11835 correctly, they are not reading file versions from the
>>hard drive, but are actually trying to exploit the vulnerability. Is
>>this correct?
>>
>>Using tcpdump to watch the test using just 11808 and 11835, we see no
>>evidence of files being looked for, but management requires a firm
>>statement that I cannot provide. Can someone please state clearly how
>>11808 and 11835 work so that I can pass it along.
>>
>>
>
>Microsoft slightly changed the behavior of their API with MS03-026 and
>MS03-029 (different error code returned for otherwise invalid requests).
>What these plugins do is that they determine the presence of the patch
>by sending invalid requests and looking at the returned error codes.
>
>The latest versions are supposed to be very accurate so my guess is that
>it's a real alert.
>
> -- Renaud
>_______________________________________________
>Nessus mailing list
>[EMAIL PROTECTED]
>http://mail.nessus.org/mailman/listinfo/nessus
>
>
>
_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus
_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus