Vulnerability Development mailing list archives

Re: old DOS still good 4 win2k


From: danders () KPMG COM AU (Anders, David)
Date: Thu, 22 Jun 2000 15:04:37 +1000


That's nice and all, but have you tried the same testing on W2k Gold, the
Professional, Server and Advanced Server versions?

-----Original Message-----
From: c1cc10 [mailto:cappellaiomatt () YAHOO COM]
Sent: Thursday, 22 June 2000 10:59
To: VULN-DEV () SECURITYFOCUS COM
Subject: old DOS still good 4 win2k


Well, nothing new on the flatline, but I think that can be useful to
send this one. We tested out the win 2k beta version, and we've found
that some old attacks are still valid to cause a DOS.
Specifically the simple ping flood from a PII 300 to another PII 300
with  64Mb RAM, can freez the box.
Another problem is in the management of the oversized udp packets. The
jolt2 can slow down the sistem, but if you spoof the sender address
putting it as the sender is the receiver, then the box freezes.
That's it.

Byez

C1cc10 & Lupux

__________________________________________________
Do You Yahoo!?
Talk to your friends online with Yahoo! Messenger.
http://im.yahoo.com


**********************************************************************
" This email is intended only for the use of the individual or entity
named above and may contain information that is confidential and
privileged. If you are not the intended recipient, you are hereby
notified that any dissemination, distribution or copying of this
Email is strictly prohibited. When addressed to our clients, any
opinions or advice contained in this Email are subject to the
terms and conditions expressed in the governing KPMG client
engagement letter. If you have received this Email in error, please
notify us immediately by return email or telephone +61 2 93357000
and destroy the original message. Thank You. "
**********************************************************************...


Current thread: