New User, Welcome!     Login

Next Page >>

Terminal Services

SYMSA-2007-013: Lotus Notes Memory Mapped Files Vulnerability

  working environments. Domino is designed for e-mail, scheduling,
  instant messaging and data driven applications.

  There exists a vulnerability in the way memory mapped files are
  used under Windows. The result of which is that if the Lotus Notes
  Client is used in a Microsoft Terminal Services or Citrix
  environment users can read each others Lotus Notes session data
  including items such as E-Mail.

  This vulnerability also impacts the server product.


[security bulletin] HPSBST02314 SSRT080016 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-003 to MS08-013

Installation Instructions: (if applicable) 


Download patches to a system other than the SMA 
Copy the patch to a floppy diskette or to a CD 
Execute the patch by using Terminal Services to the SMA or by attaching a keyboard, monitor and mouse to the SMA. 

Note: The Microsoft Windows Installer 3.1 is supported on SMA v2.1. For more information please refer at the following website: http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c&hash=SYSSXDF&displaylang=en 


PRODUCT SPECIFIC INFORMATION 

[security bulletin] HPSBST02260 SSRT071471 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS07-051 to MS07-054

Installation Instructions: (if applicable) 


Download patches to a system other than the SMA 
Copy the patch to a floppy diskette or to a CD 
Execute the patch by using Terminal Services to the SMA or by attaching a keyboard, monitor and mouse to the SMA. 

Note: The Microsoft Windows Installer 3.1 is supported on SMA v2.1. For more information please refer at the following website: http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c&hash=SYSSXDF&displaylang=en 


PRODUCT SPECIFIC INFORMATION 

[security bulletin] HPSBST02372 SSRT080133 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-052 to MS08-055

Installation Instructions: (if applicable) 


Download patches to a system other than the SMA 
Copy the patch to a floppy diskette or to a CD 
Execute the patch by using Terminal Services to the SMA or by attaching a keyboard, monitor and mouse to the SMA. 

Note: The Microsoft Windows Installer 3.1 is supported on SMA v2.1. For more information please refer at the following website: http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c&hash=SYSSXDF&displaylang=en 


PRODUCT SPECIFIC INFORMATION 

HPSBST02350 SSRT080102 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-037 to MS08-040

Installation Instructions: (if applicable) 


Download patches to a system other than the SMA 
Copy the patch to a floppy diskette or to a CD 
Execute the patch by using Terminal Services to the SMA or by attaching a keyboard, monitor and mouse to the SMA. 

Note: The Microsoft Windows Installer 3.1 is supported on SMA v2.1. For more information please refer at the following website: http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c&hash=SYSSXDF&displaylang=en 


PRODUCT SPECIFIC INFORMATION 

[security bulletin] HPSBST02394 SSRT080183 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-070 to MS08-077

Installation Instructions: (if applicable) 


Download patches to a system other than the SMA 
Copy the patch to a floppy diskette or to a CD 
Execute the patch by using Terminal Services to the SMA or by attaching a keyboard, monitor and mouse to the SMA. 

Note: The Microsoft Windows Installer 3.1 is supported on SMA v2.1. For more information please refer at the following website: http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c&hash=SYSSXDF&displaylang=en 


PRODUCT SPECIFIC INFORMATION 

HPSBST02291 SSRT071498 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS07-061 and MS07-062

Installation Instructions: (if applicable) 


Download patches to a system other than the SMA 
Copy the patch to a floppy diskette or to a CD 
Execute the patch by using Terminal Services to the SMA or by attaching a keyboard, monitor and mouse to the SMA. 

Note: The Microsoft Windows Installer 3.1 is supported on SMA v2.1. For more information please refer at the following website: http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c&hash=SYSSXDF&displaylang=en 


PRODUCT SPECIFIC INFORMATION 

HPSBST02255 SSRT071456 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS07-042 to MS07-050

Installation Instructions: (if applicable) 


Download patches to a system other than the SMA 
Copy the patch to a floppy diskette or to a CD 
Execute the patch by using Terminal Services to the SMA or by attaching a keyboard, monitor and mouse to the SMA. 

Note: The Microsoft Windows Installer 3.1 is supported on SMA v2.1. For more information please refer at the following website: http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c&hash=SYSSXDF&displaylang=en 


PRODUCT SPECIFIC INFORMATION 

[security bulletin] HPSBST02397 SSRT080187 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-078

Installation Instructions: (if applicable) 


Download patches to a system other than the SMA 
Copy the patch to a floppy diskette or to a CD 
Execute the patch by using Terminal Services to the SMA or by attaching a keyboard, monitor and mouse to the SMA. 

Note: The Microsoft Windows Installer 3.1 is supported on SMA v2.1. For more information please refer at the following website: http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c&hash=SYSSXDF&displaylang=en 


PRODUCT SPECIFIC INFORMATION 

[security bulletin] HPSBST02304 SSRT080003 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-001 to MS08-002

Installation Instructions: (if applicable) 


Download patches to a system other than the SMA 
Copy the patch to a floppy diskette or to a CD 
Execute the patch by using Terminal Services to the SMA or by attaching a keyboard, monitor and mouse to the SMA. 

Note: The Microsoft Windows Installer 3.1 is supported on SMA v2.1. For more information please refer at the following website: http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c&hash=SYSSXDF&displaylang=en 


PRODUCT SPECIFIC INFORMATION 

[security bulletin] HPSBST02344 SSRT080087 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-030 to MS08-036

Installation Instructions: (if applicable) 


Download patches to a system other than the SMA 
Copy the patch to a floppy diskette or to a CD 
Execute the patch by using Terminal Services to the SMA or by attaching a keyboard, monitor and mouse to the SMA. 

Note: The Microsoft Windows Installer 3.1 is supported on SMA v2.1. For more information please refer at the following website: http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c&hash=SYSSXDF&displaylang=en 


PRODUCT SPECIFIC INFORMATION 

[security bulletin] HPSBST02386 SSRT080164 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-067 to MS08-069

Installation Instructions: (if applicable) 


Download patches to a system other than the SMA 
Copy the patch to a floppy diskette or to a CD 
Execute the patch by using Terminal Services to the SMA or by attaching a keyboard, monitor and mouse to the SMA. 

Note: The Microsoft Windows Installer 3.1 is supported on SMA v2.1. For more information please refer at the following website: http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c&hash=SYSSXDF&displaylang=en 


PRODUCT SPECIFIC INFORMATION 

[security bulletin] HPSBST02379 SSRT080143 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-056 to MS08-066

Installation Instructions: (if applicable) 


Download patches to a system other than the SMA 
Copy the patch to a floppy diskette or to a CD 
Execute the patch by using Terminal Services to the SMA or by attaching a keyboard, monitor and mouse to the SMA. 

Note: The Microsoft Windows Installer 3.1 is supported on SMA v2.1. For more information please refer at the following website: http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c&hash=SYSSXDF&displaylang=en 


PRODUCT SPECIFIC INFORMATION 

[security bulletin] HPSBST02336 SSRT080071 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-026 to MS08-029

Installation Instructions: (if applicable) 


Download patches to a system other than the SMA 
Copy the patch to a floppy diskette or to a CD 
Execute the patch by using Terminal Services to the SMA or by attaching a keyboard, monitor and mouse to the SMA. 

Note: The Microsoft Windows Installer 3.1 is supported on SMA v2.1. For more information please refer at the following website: http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c&hash=SYSSXDF&displaylang=en 


PRODUCT SPECIFIC INFORMATION 

[security bulletin] HPSBST02320 SSRT080028 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-014 to MS08-017

Installation Instructions: (if applicable) 


Download patches to a system other than the SMA 
Copy the patch to a floppy diskette or to a CD 
Execute the patch by using Terminal Services to the SMA or by attaching a keyboard, monitor and mouse to the SMA. 

Note: The Microsoft Windows Installer 3.1 is supported on SMA v2.1. For more information please refer at the following website: http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c&hash=SYSSXDF&displaylang=en 


PRODUCT SPECIFIC INFORMATION 

[security bulletin] HPSBST02360 SSRT080117 rev.2 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-041 to MS08-051

Installation Instructions: (if applicable) 


Download patches to a system other than the SMA 
Copy the patch to a floppy diskette or to a CD 
Execute the patch by using Terminal Services to the SMA or by attaching a keyboard, monitor and mouse to the SMA. 

Note: The Microsoft Windows Installer 3.1 is supported on SMA v2.1. For more information please refer at the following website: http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c&hash=SYSSXDF&displaylang=en 


PRODUCT SPECIFIC INFORMATION 

[security bulletin] HPSBST02314 SSRT080016 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-003 to MS08-013

Installation Instructions: (if applicable) 


Download patches to a system other than the SMA 
Copy the patch to a floppy diskette or to a CD 
Execute the patch by using Terminal Services to the SMA or by attaching a keyboard, monitor and mouse to the SMA. 

Note: The Microsoft Windows Installer 3.1 is supported on SMA v2.1. For more information please refer at the following website: http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c&hash=SYSSXDF&displaylang=en 


PRODUCT SPECIFIC INFORMATION 

[security bulletin] HPSBST02329 SSRT080048 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-018 to MS08-025

Installation Instructions: (if applicable) 


Download patches to a system other than the SMA 
Copy the patch to a floppy diskette or to a CD 
Execute the patch by using Terminal Services to the SMA or by attaching a keyboard, monitor and mouse to the SMA. 

Note: The Microsoft Windows Installer 3.1 is supported on SMA v2.1. For more information please refer at the following website: http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c&hash=SYSSXDF&displaylang=en 


PRODUCT SPECIFIC INFORMATION 

[security bulletin] HPSBST02299 SSRT071506 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS07-063 to MS07-069

Installation Instructions: (if applicable) 


Download patches to a system other than the SMA 
Copy the patch to a floppy diskette or to a CD 
Execute the patch by using Terminal Services to the SMA or by attaching a keyboard, monitor and mouse to the SMA. 

Note: The Microsoft Windows Installer 3.1 is supported on SMA v2.1. For more information please refer at the following website: http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c&hash=SYSSXDF&displaylang=en 


PRODUCT SPECIFIC INFORMATION 

[security bulletin] HPSBST02280 SSRT071480 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS07-055 to MS07-060

Installation Instructions: (if applicable) 

Download patches to a system other than the SMA 
Copy the patch to a floppy diskette or to a CD 
Execute the patch by using Terminal Services to the SMA or by attaching a keyboard, monitor and mouse to the SMA. 
Note: The Microsoft Windows Installer 3.1 is supported on SMA v2.1. For more information please refer at the following website: http://www.microsoft.com/downloads/details.aspx?FamilyID=889482fc-5f56-4a38-b838-de776fd4138c&hash=SYSSXDF&displaylang=en 


PRODUCT SPECIFIC INFORMATION 


Remote Desktop Command Fixation Attacks

to compromise a well protected Windows Terminal or CITRIX server with
a simple social engineering attack and some knowledge about the
platform we are about to exploit.

The attack is rather simple. All the bad guys have to do is to compose
a malicious RDP (for Windows Terminal Services) or ICA (for CITRIX)
file and send it to the victim. The victim is persuaded to open the
file by double clicking on it. When the connection is established, the
user will enter their credentials to login and as such let the hackers
in. Vicious!


RE: Remote Desktop Command Fixation Attacks

> to compromise a well protected Windows Terminal or CITRIX server with
> a simple social engineering attack and some knowledge about the
> platform we are about to exploit.
> 
> The attack is rather simple. All the bad guys have to do is to compose
> a malicious RDP (for Windows Terminal Services) or ICA (for CITRIX)
> file and send it to the victim. The victim is persuaded to open the
> file by double clicking on it. When the connection is established, the
> user will enter their credentials to login and as such let the hackers
> in. Vicious!
> 

RE: Remote Desktop Command Fixation Attacks

to compromise a well protected Windows Terminal or CITRIX server with
a simple social engineering attack and some knowledge about the
platform we are about to exploit.

The attack is rather simple. All the bad guys have to do is to compose
a malicious RDP (for Windows Terminal Services) or ICA (for CITRIX)
file and send it to the victim. The victim is persuaded to open the
file by double clicking on it. When the connection is established, the
user will enter their credentials to login and as such let the hackers
in. Vicious!


Re: Remote Desktop Command Fixation Attacks

> to compromise a well protected Windows Terminal or CITRIX server with
> a simple social engineering attack and some knowledge about the
> platform we are about to exploit.
>
> The attack is rather simple. All the bad guys have to do is to compose
> a malicious RDP (for Windows Terminal Services) or ICA (for CITRIX)
> file and send it to the victim. The victim is persuaded to open the
> file by double clicking on it. When the connection is established, the
> user will enter their credentials to login and as such let the hackers
> in. Vicious!
>

Re: Remote Desktop Command Fixation Attacks

pdp (architect) wrote:
> The attack is rather simple. All the bad guys have to do is to compose
> a malicious RDP (for Windows Terminal Services) or ICA (for CITRIX)
> file and send it to the victim. The victim is persuaded to open the
> file by double clicking on it. When the connection is established, the
> user will enter their credentials to login and as such let the hackers
> in. Vicious!

So, "all you have to do" is persuade the user to run an attachment and 
type in credentials.  Wouldn't it be simpler to just email the user a 

RE: Microsoft Terminal Services vulnerable to MITM-attacks.

-----Original Message-----
From: Ansgar Wiechers [mailto:bugtraq@planetcobalt.net] 
Sent: Wednesday, February 09, 2011 7:46 AM
To: bugtraq@securityfocus.com
Subject: Re: Microsoft Terminal Services vulnerable to MITM-attacks.

On 2011-02-08 sam.vaughey@gmail.com wrote:
> Does this issue still exist ? 

Depends on the configuration. Unless configured to require network level

Re: [Full-disclosure] Remote Desktop Command Fixation Attacks

> to compromise a well protected Windows Terminal or CITRIX server with
> a simple social engineering attack and some knowledge about the
> platform we are about to exploit.
>
> The attack is rather simple. All the bad guys have to do is to compose
> a malicious RDP (for Windows Terminal Services) or ICA (for CITRIX)
> file and send it to the victim. The victim is persuaded to open the
> file by double clicking on it. When the connection is established, the
> user will enter their credentials to login and as such let the hackers
> in. Vicious!
>

RE: Microsoft Terminal Services vulnerable to MITM-attacks.

-----Original Message-----
From: sam.vaughey@gmail.com [mailto:sam.vaughey@gmail.com] 
Sent: Tuesday, February 08, 2011 6:16 AM
To: bugtraq@securityfocus.com
Subject: Re: Microsoft Terminal Services vulnerable to MITM-attacks.

Does this issue still exist ? 




RE: Remote Desktop Command Fixation Attacks

> to compromise a well protected Windows Terminal or CITRIX server with
> a simple social engineering attack and some knowledge about the
> platform we are about to exploit.
>
> The attack is rather simple. All the bad guys have to do is to compose
> a malicious RDP (for Windows Terminal Services) or ICA (for CITRIX)
> file and send it to the victim. The victim is persuaded to open the
> file by double clicking on it. When the connection is established, the
> user will enter their credentials to login and as such let the hackers
> in. Vicious!
>

RE: [Full-disclosure] Remote Desktop Command Fixation Attacks

> to compromise a well protected Windows Terminal or CITRIX server with
> a simple social engineering attack and some knowledge about the
> platform we are about to exploit.
>
> The attack is rather simple. All the bad guys have to do is to compose
> a malicious RDP (for Windows Terminal Services) or ICA (for CITRIX)
> file and send it to the victim. The victim is persuaded to open the
> file by double clicking on it. When the connection is established, the
> user will enter their credentials to login and as such let the hackers
> in. Vicious!
>

Next Page>>

Copyright © 1995-2013 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!