Nmap Announce mailing list archives

Re: [Fwd: [SecureXpert Labs Advisory SX-98.12.23-01] Widespread DoSvulnerability]


From: Ken Williams <jkwilli2 () unity ncsu edu>
Date: Mon, 4 Jan 1999 08:41:17 -0500 (EST)

On Mon, 4 Jan 1999, Peter van Dijk wrote:

Date: Mon, 4 Jan 1999 08:57:46 +0100
From: Peter van Dijk <peter () attic vuurwerk nl>
To: nmap-hackers () insecure org
Subject: Re: [Fwd: [SecureXpert Labs Advisory SX-98.12.23-01] Widespread
    DoSvulnerability]

Note that _nobody_ has succeeded in making Windows crash using nmap, which renders
the whole advisory useless because that's the only real news in it. Read the
BUGTRAQ archives for more details.

On Mon, Jan 04, 1999 at 09:43:42AM +0200, Claudiu Ionescu wrote:


-------- Original Message --------
Subject: [SecureXpert Labs Advisory SX-98.12.23-01] Widespread
DoSvulnerability
Date: Wed, 23 Dec 1998 09:31:23 -0500
From: Richard Reiner <rreiner () FSCINTERNET COM>
Reply-To: Bugtraq List <BUGTRAQ () netspace org>
Organization: FSC Internet Corp.
To: BUGTRAQ () netspace org

SecureXpert Labs Advisory SX-98.12.23-01

Greetz, Peter.
-- 
<squeezer> AND I AM GONNA KILL MIKE                |          Peter van Dijk
<squeezer> hardbeat, als je nog nuchter bent:      | peter () attic vuurwerk nl
<squeezer>   @date = localtime(time);                   |  realtime security d00d
<squeezer>   $date[5] += 2000 if ($date[5] < 37);  | 
<squeezer>   $date[5] += 1900 if ($date[5] < 99);  |    -x- available -x-


not true.  winnt telnetd goes down like a $5 whore with a simple
nmap-2.02 'nmap -sS billyg.microsoft.com' tcp SYN stealth port scan.

-------- Recent BugTraq Message --------

Date: Sat, 2 Jan 1999 09:39:08 +0100
From: Tomas Halgas <maniac () JADIERKO LOCALHOST SK>
To: BUGTRAQ () netspace org
Subject: nmap can crash microsoft telnetd

Nmap 2.01++ can crash microsoft winnt telnetd. Only need to have option
-sS enabled when scanning...
You will get a aplication popup with message like this - program made an
illegal operation.

-------- End of Recent BugTraq Message --------

Regards,

Ken Williams

Packet Storm Security        http://www.Genocide2600.com/~tattooman/
NC State CS Dept  http://www.csc.ncsu.edu/   jkwilli2 () unity ncsu edu
PGP DSS/DH/RSA Keys          http://www4.ncsu.edu/~jkwilli2/pgpkey/

/* This email is distributed under the GNU General Public Licence.  
 * You may modify it as you wish and distribute it freely, but if 
 * you try to sell it, I will show you just how smelly and messy a 
 * coredump can be.
 */
___________________________________________________________________ 
Get Your Email Sniffed and Decrypted for Free at http://www.nsa.gov




Current thread: