Originally posted by Logik!
RPC Vulnerability - Remote Shutdown
Warning: RPC Exploits Have Been Created
http://www.crn.com/sections/BreakingNews/breakingnews.asp?ArticleID=43556
One of the main RPC Exploits that is floating around will shutdown your system remotely. If you are victimized by this vulnerability, you will see the following:
"This system is shutting down. Please save all work in progress and log off.
Any unsaved changes will be lost. This shutdown was initiated by NT AUTHORITY/SYSTEM
Message: Windows must now restart because the
Remote Procedure Call (RPC) service terminatd unexpectedly."
You need to install a firewall as quickly as possible, then download and install the patch.
And for all those of you who had previously been suffering from Messenger pop-ups, and resolved it by simply disabling the Messenger Service, you are vulnerable to this.
Make sure you've patched your systems and properly configured your firewalls.
Here's the bulletin:
http://www.microsoft.com/security/security_bulletins/ms03-026.asp
Additional Links:
http://www.ultratech-llc.com/BrainWave/TechDocs/Messenger.html
http://www.ultratech-llc.com/BrainWave/TechDocs/RPC.html