Bugtraq mailing list archives

Remote D.o.S Attack in DNS PRO v5.7 WinNT From FBLI Software Vulnerability


From: labs () USSRBACK COM (Ussr Labs)
Date: Tue, 21 Dec 1999 04:02:11 -0300


Remote D.o.S Attack in DNS PRO v5.7 WinNT From FBLI Software Vulnerability

USSR Advisory Code:    22

Release Date:
December 21, 1999

Systems Affected:
DNS PRO v5.7 and possibly others.

About The Software:
The first DNS Server for Windows NT
- Database engine five time faster.
- Tabs now work in the control panels.
- Automatic creation of reverse mapping for class A, B and C.(unavailable
  anywhere).
- New DNS Console.
- New more readable file format.
- New and enhanced DNS control applet.
- New and enhanced DNS Database applet.
- Bind 4.9.6 compatible.
- Cache poisoning secure.
- Reverse lookup files sorted by IP Address.
- Event logs filters.

THE PROBLEM

UssrLabs found a Remote DoS Attack in DNS PRO v5.7 WinNT, The D.o.S is
caused by a
Multiples connections at the same time (over 30) in the Dns Port (53), and
some characters to the port.
If DNS PRO v5.7 is running as service, Take all computer resources = CPU
100%.

There is not much to expand on.... just a simple hole

Do you do the w00w00?
This advisory also acts as part of w00giving. This is another contribution
to w00giving for all you w00nderful people out there. You do know what
w00giving is don't you? http://www.w00w00.org/advisories.html

Binary or source for this Problem:
http://www.ussrback.com/

Vendor Status:
Contacted

Vendor   Url: http://www.fbli.com/
Program Url: http://www.fbli.com/english/dnspro.htm

Credit: USSRLABS

SOLUTION
  That will be fixed soon, vendor say that.

Greetings:
Eeye, Attrition, w00w00, beavuh, Rhino9, ADM, L0pht, HNN, Technotronic and
Wiretrip.

u n d e r g r o u n d  s e c u r i t y  s y s t e m s  r e s e a r c h
http://www.ussrback.com


Current thread: