exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

sa_04.txt

sa_04.txt
Posted Oct 12, 2000
Site nsfocus.com

NSFocus Security Advisory(SA2000-04) - A denial of service flaw has been found in the Microsoft Win9x netbios client. An attacker can modify his host file share service and perform DoS attack against a Win9x client that visits it. Windows 95, 98, and 98se are vulnerable.

tags | exploit, denial of service
systems | windows
SHA-256 | 9236c974af81c4c844db26363d287b64b22ac6b3a14b0d4342716a88acbe836a

sa_04.txt

Change Mirror Download

[01.gif] [02.gif]


[t4.jpg]
NSFOCUS Security Advisory(SA2000-04)
Topic£ºMicrosoft Win9x client driver type comparing vulnerability
Release Date£º August 20, 2000
Affected System:
================
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows 98 Second Edition
Non-affected system£º
===================
- Microsoft Windows NT
- Microsoft Windows 2000
Impact:
=========
NSFOCUS security team has found a security flaw in Microsoft Win9x
NETBIOS client. Exploitation of this vulnerability, a malicious
attacker can modify his host file share service and perform DoS attack
to a Win9x client that visits it.
Description£º
============
When Win9x client accessing NETBIOS file shared services and comparing
the driver types, if the returned type from server is none of
below:"£¿£¿£¿£¿£¿"," A£º"," LPT1£º"," COMM"or"IPC"£¬it will lead to
the sixth result, which is fake cause there are only five of them. So,
win9x client will get a wrong driver pointer from conversion, transfer
the control to the wrong driver function address and finally crash.
Workaround:
====================
Don't access the untrusted host's file share service.
Microsoft has been informed.
DISCLAIMS:
==========
THE INFORMATION PROVIDED IS RELEASED BY NSFOCUS "AS IS" WITHOUT
WARRANTY OF ANY KIND. NSFOCUS DISCLAIMS ALL WARRANTIES, EITHER EXPRESS
OR IMPLIED, EXCEPT FOR THE WARRANTIES OF MERCHANTABILITY. IN NO
EVENTSHALL NSFOCUS BE LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING
DIRECT, INDIRECT, INCIDENTAL,CONSEQUENTIAL, LOSS OF BUSINESS PROFITS
OR SPECIAL DAMAGES, EVEN IF NSFOCUS HAS BEEN ADVISED OF THE
POSSIBILITY OF SUCH DAMAGES. DISTRIBUTION OR REPRODUTION OF THE
INFORMATION IS PROVIDED THAT THE ADVISORY IS NOT MODIFIED IN ANY WAY.
©Copyright 1999-2000 NSFOCUS. All Rights Reserved. Terms of use.
NSFOCUS Security Team <security@nsfocus.com>
NSFOCUS INFORMATION TECHNOLOGY CO.,LTD
(http://www.nsfocus.com)

©Copyright 2000 NSFOCUS Information Technology Co.,Ltd. All Rights
Reserved.
Contact:webmaster@nsfocus.com
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close