Telecom and Logistics Associates 

new6.gif (1031 bytes) TLAalert    Security Service 

Translate this page from:  publication: Christian ALT 
  Save Time and Money

TLAnews: Security NEWs Service

 5.7.2000 SecurityVulnerabilities in Windows 2000 Telnet Server and partial Denial of Service
The same kinds of vulnerabilities were also found on some Windows 2000 network services

En français: Vulnerabilités dans Windows 2000 serveur Telnet  et déni de service partiel
Le même type de vulnérabilités a aussi été trouvé sur certains services réseau de Windows 2000

Home
Consulting
Tech Doc
FW-1 FAQ
Training
Products
TLAnews
Archive
Advertising
 

TLAnews.com
Information for security concerned people

 

Register to TLAnews letter
 

 

 

 


English version
Vulnerability in Microsoft Windows 2000 Telnet Server
Microsoft Windows 2000 Server is supplied with a Telnet server for remote
console access.  A Denial of Service vulnerability exists in this server which
may be exploited by a local or remote attacker.

Multiple ports/protocols partial Denial of Service
Multiple services on Windows 2000 Server are vulnerable to a simple attack which
allows remote network users to drive the CPU utilization to 100% in an extremely short period of time, at little cost to the attacker's machine.

The ports that were found vulnerable include TCP ports 7, 9, 21, 23, 7778
and UDP ports 53, 67, 68, 135, 137, 500, 1812, 1813, 2535, 3456. using on a unix machine

nc target.host 7 < /dev/zero" for the
TCP variant or "nc -u target.host 53 < /dev/zero" for the UDP variant

Résumé en français
Vulnerabilité dans Microsoft Windows 2000 Telnet Serveur
Le serveur telnet sous Windows 2000 peut être stoppé en envoyant une série de zéro binaire au serveur telnet. Cela se réalise facilement avec une machine Unix en utilisant la commande:

nc target.host 23 < /dev/zero

Multiple ports/protocols en deni de service partiel
De multiple services sont vulnérables sous Windows 2000 à une simple attaque sur les ports UDP 53, 67, 68, 135, 137, 500, 1812, 1813, 2535, 3456

et sur les ports TCP 7, 9, 21, 23, 7778

variante pour TCP

nc target.host 7 < /dev/zero

varainte pur UDP

nc -u target.host 53 < /dev/zero


Vulnerability in Microsoft Windows 2000 Telnet Server

FSC Internet / SecureXpert Labs

SecureXpert Labs Advisory [SX-20000620-1] - Denial of Service
vulnerability in Microsoft Windows 2000 Telnet Server

Summary

Microsoft Windows 2000 Server is supplied with a Telnet server for remote
console access.  A Denial of Service vulnerability exists in this server which
may be exploited by a local or remote attacker.

Details

A remote user can cause the telnet server to stop responding to requests by
sending a stream of binary zeros to the telnet server.  This can easily be
reproduced from a Linux system using netcat with an input of /dev/zero,
with a command such as "nc target.host 23 < /dev/zero".  The Windows
2000 Telnet Server stops responding to requests after a few seconds.  If
the Telnet Server is set to restart upon failure, it will restart and
immediately fail. This will occur repeatedly until the Telnet Server exceeds
its restart count, at which point the service remains down.

Status

Microsoft Corp. has been informed of this vulnerability, and has assigned it
incident ID# [MSRC 290].  As of Tuesday June 2000, Microsoft has successfully
reproduced the vulnerability and SecureXpert Labs staff are working with Microsoft
to prepare a fix.

Credits

Mike Murray, SecureXpert Labs
Max Degtyar, SecureXpert Labs
Richard Reiner, SecureXpert Labs

About SecureXpert DIRECT

SecureXpert DIRECT is an advance security advisory service provided by
SecureXpert Labs.  Subscriptions are free of charge and may be obtained
online at http://www.securexpert.com/services.html.

Multiple ports/protocols partial Denial of Service in Microsoft Windows 2000 Server

FSC Internet Corp. / SecureXpert Labs

SecureXpert Labs Advisory [SX-20000620-2] - Multiple ports/protocols
partial Denial of Service in Microsoft Windows 2000 Server

Summary

Multiple ports and protocols on Microsoft Windows 2000 Server are susceptible
to a simple network attack which raises CPU utilization on Windows 2000
Server to 100%.

Details

Multiple services on Windows 2000 Server are vulnerable to a simple attack which
allows remote network users to drive the CPU utilization to 100% in an
extremely short period of time, at little cost to the attacker's machine.

The ports that were found vulnerable include TCP ports 7, 9, 21, 23, 7778
and UDP ports 53, 67, 68, 135, 137, 500, 1812, 1813, 2535, 3456.

While this attack does not cause an immediate lockup of the machine, it
does cause excessive CPU resource utilization on the target machine.

This can easily be reproduced from a Linux system using netcat with an input
of /dev/zero, with a command such as "nc target.host 7 < /dev/zero" for the
TCP variant or "nc -u target.host 53 < /dev/zero" for the UDP variant.

Due to the large number of services affected, this could likely allow a
very quick and easy distributed attack

Status

Microsoft Corp. has been informed of this vulnerability, and has assigned it
incident ID# [MSRC 291].  SecureXpert Labs staff are working with
Microsoft to reproduce the vulnerability and prepare a fix.

Credits

Mike Murray, SecureXpert Labs
Max Degtyar, SecureXpert Labs
Richard Reiner, SecureXpert Labs

About SecureXpert DIRECT

SecureXpert DIRECT is an advance security advisory service provided by
SecureXpert Labs.  Subscriptions are free of charge and may be obtained
online at http://www.securexpert.com/services.html.

 
Author information.
Copyright © [Telecom and Logistics Associates Sàrl]. All rights reserved.
Revised: juillet 05, 2000 .

All information provided is of a general nature and is not intended to address the circumstances of any particular individual or entity. Although we endeavor to provide accurate and timely information, there can be no guarantee that such information is accurate as of the date it is received or that it will continue to be accurate in the future. No one should act upon such information without appropriate professional advice after a thorough examination of the facts of the particular situation.