Hi all,
I’m new here so please forgive me if this post is in the wrong category. Having said that here goes:
I have a BS5/BM5 system that’s been up and running for a while now and the software have been updated twice. All in all I’m happy with the setup, despite some software related quirks.
When checking my home computer network (in which BM5 is a part) with Nessus, a security scanner (www.nessus.org), BM5 was flagged with several vulnerabilities.
Microsoft categorizes two of these as critical:
MS08-067: Microsoft Windows Server Service Crafted RPC Request Handling Remote Code Execution (958644)
MS09-001: Microsoft Windows SMB Vulnerabilities Remote Code Execution (958687)
MS-08-067 is perhaps the most severe of these two - it allows an outside hacker to run his or her own software or commands on the BM5, e.g. someone could steal or erase your entire music collection, or use the BM5 to steal personal data from other computers connected to the BM5.
Microsoft released a patch addressing this problem in October 2008, however it appears as if this patch has been omitted in the updates from B&O.
By using Metasploit -tool for exploit research and penetration testing (www.metasploit.com) you can verify that the BM5 is wide open to hackers.
Does anyone here know if there is a patch available or could anyone suggest appropriate rules for a firewall?