fulldisclosure@catholic.org just disclosed the working version of
03-026. We have checked it out. Without question, the code is great
and working.

But the problem of the code is that it was easily captured, on the
spot by Win-Trap, without the need for signature updating and/or
complicated rules. Please check the attached text file for the log.
Notice the successful sessions were trapped by Win-Trap, but
intentionally let go while the "Exploit appeared to have failed"
messages just meant that Win-Trap refused the exploit code to play
along. Unfortunately, single DoS might exist when attacked even with
Win-Trap protection. Hey, that is much better than allowing the
malicious code to play happily, right? Please check
http://www.phsecurity.com/pdf/DCOM-Report.pdf for a full document.

Considering the fact that the DCOM-RPC exploit code has been released
in the wild, we will release our basic version of Win-Trap as a
shareware soon. At the same time, if you are interested, please drop
us a line to request it before we make it downloadable without jamming
our site.

The development for the DCOM-RPC exploit is just the assumption in our
article titled "The current method against BOF exploit is NOT
working". (http://www.phsecurity.com/pdf/Curren...NotWorking.pdf).
The article suggests that the patch itself is the vulnerability since
it gives out clues to what the patch is about. With the reverse tools
like "exediff" program, a program to list the differences between two
executables with minor differences in source code, one can easily
figure out where the vulnerability is. So, a patch is a temporary
solution and could be a beginning of nightmares (because of the
un-patched vulnerable population of networked computers out there).

What is the best solution against BOF exploitation in general? The
answer is to secure the operating system core itself! Win-Trap
provides the protection against malicious code exploiting buffer
overflow, either stack based or heap-based, and against malicious
programs such as W32.Bugbear and W32.SoBig etc.

With Win-Trap technology conceived, implemented and deployed, the days
of BOF exploitation will be numbered. Critical warnings might not have
to be released week after week. Please read
http://www.phsecurity.com/pdf/BOF-Exploit.pdf for our arguments.

Do enjoy the remaining days of exploit code and realize that a new day
for protection against BOF exploit has arrived.

Please email info@phsecurity.com to request the basic version of
Win-Trap before we put it up on Simtel or elsewhere.

PH Security
http://www.phsecurity.com/