Remote DoS attack discovered in DNS Pro 5.7 for Windows NT, caused by over 30 connections to port 53 at the same time.
6a5b1d3203440661fa1a3460290844a5985c7115edfcea8d58a274dcc8be800a
Remote D.o.S Attack in DNS PRO v5.7 WinNT From FBLI Software Vulnerability
USSR Advisory Code: 22
Release Date:
December 21, 1999
Systems Affected:
DNS PRO v5.7 and possibly others.
About The Software:
The first DNS Server for Windows NT
- Database engine five time faster.
- Tabs now work in the control panels.
- Automatic creation of reverse mapping for class A, B and C.(unavailable
anywhere).
- New DNS Console.
- New more readable file format.
- New and enhanced DNS control applet.
- New and enhanced DNS Database applet.
- Bind 4.9.6 compatible.
- Cache poisoning secure.
- Reverse lookup files sorted by IP Address.
- Event logs filters.
THE PROBLEM
UssrLabs found a Remote DoS Attack in DNS PRO v5.7 WinNT, The D.o.S is
caused by a
Multiples connections at the same time (over 30) in the Dns Port (53), and
some characters to the port.
If DNS PRO v5.7 is running as service, Take all computer resources = CPU
100%.
There is not much to expand on.... just a simple hole
Do you do the w00w00?
This advisory also acts as part of w00giving. This is another contribution
to w00giving for all you w00nderful people out there. You do know what
w00giving is don't you? http://www.w00w00.org/advisories.html
Binary or source for this Problem:
http://www.ussrback.com/
Vendor Status:
Contacted
Vendor Url: http://www.fbli.com/
Program Url: http://www.fbli.com/english/dnspro.htm
Credit: USSRLABS
SOLUTION
That will be fixed soon, vendor say that.
Greetings:
Eeye, Attrition, w00w00, beavuh, Rhino9, ADM, L0pht, HNN, Technotronic and
Wiretrip.
u n d e r g r o u n d s e c u r i t y s y s t e m s r e s e a r c h
http://www.ussrback.com