Bugtraq mailing list archives
Remote D.o.S Attack in DNS PRO v5.7 WinNT From FBLI Software Vulnerability
From: labs () USSRBACK COM (Ussr Labs)
Date: Tue, 21 Dec 1999 04:02:11 -0300
Remote D.o.S Attack in DNS PRO v5.7 WinNT From FBLI Software Vulnerability USSR Advisory Code: 22 Release Date: December 21, 1999 Systems Affected: DNS PRO v5.7 and possibly others. About The Software: The first DNS Server for Windows NT - Database engine five time faster. - Tabs now work in the control panels. - Automatic creation of reverse mapping for class A, B and C.(unavailable anywhere). - New DNS Console. - New more readable file format. - New and enhanced DNS control applet. - New and enhanced DNS Database applet. - Bind 4.9.6 compatible. - Cache poisoning secure. - Reverse lookup files sorted by IP Address. - Event logs filters. THE PROBLEM UssrLabs found a Remote DoS Attack in DNS PRO v5.7 WinNT, The D.o.S is caused by a Multiples connections at the same time (over 30) in the Dns Port (53), and some characters to the port. If DNS PRO v5.7 is running as service, Take all computer resources = CPU 100%. There is not much to expand on.... just a simple hole Do you do the w00w00? This advisory also acts as part of w00giving. This is another contribution to w00giving for all you w00nderful people out there. You do know what w00giving is don't you? http://www.w00w00.org/advisories.html Binary or source for this Problem: http://www.ussrback.com/ Vendor Status: Contacted Vendor Url: http://www.fbli.com/ Program Url: http://www.fbli.com/english/dnspro.htm Credit: USSRLABS SOLUTION That will be fixed soon, vendor say that. Greetings: Eeye, Attrition, w00w00, beavuh, Rhino9, ADM, L0pht, HNN, Technotronic and Wiretrip. u n d e r g r o u n d s e c u r i t y s y s t e m s r e s e a r c h http://www.ussrback.com
Current thread:
- Re: FTP denial of service attack, (continued)
- Re: FTP denial of service attack Theo de Raadt (Dec 07)
- Re: FTP denial of service attack Darren Reed (Dec 07)
- Re: FTP denial of service attack Gregory A Lundberg (Dec 10)
- RSAREF2 buffer overflow patch Gerardo Richarte (Dec 10)
- Re: FTP denial of service attack Theo de Raadt (Dec 07)
- Re: new IE5 remote exploit Shane Hird (Dec 07)
- NT WinLogon VM contains plaintext password visible in admin mode Robert Horvick (Dec 07)
- Re: NT WinLogon VM contains plaintext password visible in admin mode Chris Paget (Dec 08)
- [Debian] New version of sendmail released Aleph One (Dec 07)
- The money: protocol in Internet Explorer Richard M. Smith (Dec 20)
- Re: The money: protocol in Internet Explorer David Litchfield (Dec 21)
- Remote D.o.S Attack in DNS PRO v5.7 WinNT From FBLI Software Vulnerability Ussr Labs (Dec 20)