[Dailydave] SMBLoris

Dave Aitel dave.aitel at gmail.com
Tue Aug 8 18:27:57 UTC 2017


So I know it's Microsoft Tuesday, but we've been working on that SMBLoris
bug a bit more for release to customers as well, and as part of that, we're
spending a lot of time thinking about it, as deceptively simple as it is.

The thing I'm wondering is why people outside of FinancialSec  think DoS is
almost a non-issue. Most companies have only a few domain controllers, and
when those go down, the company goes down. And they have to be reachable on
these exact ports, from anywhere in the company, essentially.

It seems like this is one of those things that got a tiny splash of
attention, but could be worth more. :)

-dave
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.immunityinc.com/pipermail/dailydave/attachments/20170808/783fa3ea/attachment.html>


More information about the Dailydave mailing list