SAMBA nttrans exploit v1.20

Vulnerability exploited: CAN-2003-0085 - BID-7106

Category: Exploits/Remote

Exploits an incorrect memory copy in SAMBA server and installs a level0 agent.
A buffer overflow in the SMB/CIFS packet fragment re-assembly code for the SMB daemon (smbd) allows remote attackers to execute arbitrary code.

Supported Systems:
    Mandrake Linux 8.1 (i386)
    Mandrake Linux 8.2 (i386)
    RedHat Linux 8 (i386)
    RedHat Linux 7 (i386)
    RedHat Linux 7.1 (i386)
    RedHat Linux 7.2 (i386)
    RedHat Linux 7.3 (i386)
    Debian Linux 3 (i386)
    Solaris 8 (sun4u)
    Samba 2.2.1a running under Mandrake 8.1 kernel 2.4.8-26mdk/x86
    Samba 2.2.3a running under Mandrake 8.2 kernel 2.4.18-6mdk/x86
    Samba 2.2.5 running under RedHat 8.0 kernel 2.4.20/x86
    Samba 2.2.1a running under RedHat 7.2 kernel 2.4.18-3/x86
    Samba 2.2.3a running under RedHat 7.3 kernel 2.4.18-3smp/x86
    Samba 2.0.7 running under RedHat 7.0 kernel 2.2.16-22/x86
    Samba 2.2.7a running under Debian 3.0 kernel 2.4.20/x86
    Samba 2.999+3.0.alpha21-5 running under Debian 3.0 kernel 2.4.20/x86
    Samba 2.2.7a running under Solaris 8/Ultra-5_10
    Samba 2.2.7 running under Solaris 8/Ultra-5_10
    Samba 2.2.6 running under Solaris 8/Ultra-5_10
    Samba 2.2.5 running under Solaris 8/Ultra-5_10
    Samba 2.2.4 running under Solaris 8/Ultra-5_10


This module is included in the latest version of CORE IMPACT, the first automated comprehensive penetration testing product for accurately identifying information security risks. Click here to learn more about the product.