Bugtraq mailing list archives

Re: Possible DOS in WinNT RAS (PPTP)


From: grantag () SWBELL NET (grantag)
Date: Tue, 27 Apr 1999 10:12:28 -0500


Is the problem possibly hardware specific?  What kind of hardware are you
using?  I'm just curious if you've tested it on multiple systems.

Good find.

Allen McClure
Network Engineer
Tricon Global Restaurants, Inc.

-----Original Message-----
From: Simon Helson <simon () CONCEPTS CO NZ>
To: BUGTRAQ () netspace org <BUGTRAQ () netspace org>
Date: Monday, April 26, 1999 4:56 PM
Subject: Possible DOS in WinNT RAS (PPTP)


Please excuse if this has been posted before, I did a quick search of the
archives and found nothing
This hasn't been sent to MS, as I don't know an email address to send it
to, Aleph, if you find it worthy of sending, please forward a copy to the
MS people for their attention. Cheers.

I was playing around with PPTP last night, and discovered that, with "very"
minimal effort, I could cause my friends NT Server (version 4, service pack
4) to reboot instantly, without shutting down. All I did was telnet to the
port (1723) on the NT box, and then send the following data.

hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh
h
hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh
h
hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh
h
hhhhhhhhhhhhhhhhhhhhhhhhhhhh (that's 256 'h's for those who don't want to
count:-)

and hit return. nothing. BUT, then I hit ^D and all hell broke loose. The
NT server dropped like a stone, full hardware reboot.

I tested this multiple times and always got the same response.

The NT Server was version 4, with Service pack 4 applied.

Cheers

Simon




Current thread: