what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

iDEFENSE Security Advisory 2003-04-09.t

iDEFENSE Security Advisory 2003-04-09.t
Posted Apr 10, 2003
Authored by iDefense Labs | Site idefense.com

iDEFENSE Security Advisory 04.09.03 - A vulnerability exists in Microsoft's Internet Security and Acceleration Server that allows attackers to cause a denial-of-service condition by spoofing a specially crafted packet to the target system. Another impact of this vulnerability is the capability of a remote attacker to generate an infinite packet storm between two unpatched systems implementing ISA Server or MS Proxy 2.0 over the Internet.

tags | advisory, remote, spoof
SHA-256 | b573e2b6f6a85ab874cda45b55e19be72c075584f1a76e5079e895a43dc4c0de

iDEFENSE Security Advisory 2003-04-09.t

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

iDEFENSE Security Advisory 04.09.03:
http://www.idefense.com/advisory/04.09.03.txt
Denial of Service in Microsoft Proxy Server 2.0 and Internet Security and
Acceleration Server 2000
April 9, 2003

I. BACKGROUND

Microsoft Corp.'s Internet Security and Acceleration Server (ISA) Server
integrates an extensible, multi-layer enterprise firewall and a scalable
high-performance web cache. It builds on Microsoft Windows 2000 security
and directory for policy-based security, acceleration and management of
internetworking. More information is available at
http://www.microsoft.com/isaserver/ . MS Proxy 2.0 is the predecessor to
ISA Server, more information is available at
http://www.microsoft.com/isaserver/evaluation/previousversions/default.asp


II. DESCRIPTION

A vulnerability exists in ISA Server and MS Proxy 2.0 that allows
attackers to cause a denial-of-service condition by spoofing a specially
crafted packet to the target system. Another impact of this vulnerability
is the capability of a remote attacker to generate an infinite packet
storm between two unpatched systems implementing ISA Server or MS Proxy
2.0 over the Internet.

Both ISA Server and MS Proxy 2.0, by default, install a WinSock Proxy
(WSP) service wspsrv.exe, designed for testing and diagnostic purposes.
The WSP service creates a User Datagram Protocol socket bound to port
1745. A specially crafted packet can cause WSP to generate a continuous
flood of requests and reply requirements.

III. ANALYSIS

In the case of the attack scenario for an internal LAN attacker causing a
denial of service, this malformed packet must meet the following criteria:

* The source and destination IP are the same as the ISA Server.
* The source and destination port is 1745.
* The data field is specially crafted and resembles the request format.

An attacker with access to the LAN can anonymously generate a specially
crafted UDP packet that will cause the target ISA Server to fall into a
continuous loop of processing request and reply packets. This will cause
the ISA Server to consume 100 percent of the underlying system's CPU
usage. It will continue to do so until the system reboots or the WinSock
Proxy (WSP) service restarts.

In the case of the attack scenario of a remote attacker causing a packet
storm between two systems running ISA Server or MS Proxy 2.0, the
malformed packet must meet the following criteria:

* The source IP is one of the targets
* The destination IP is the other target
* The source and destination port is 1745.
* The data field is specially crafted and resembles the request format.

IV. DETECTION

iDEFENSE has verified that Microsoft ISA Server 2000 and MS Proxy 2.0 are
both vulnerable to the same malformed packet characteristics described
above.

Wspsrv.exe is enabled by default in Proxy Server 2.0. The Microsoft
Firewall server is enabled by default in ISA Server firewall mode and ISA
Server integrated mode installations. It is disabled in ISA Server cache
mode installations.

V. WORKAROUND

To prevent the second attack scenario, apply ingress filtering on the
Internet router on UDP port 1745 to prevent a malformed packet from
reaching the ISA Server and causing a packet storm.

VI. RECOVERY

Restart either the WinSock Proxy Service or the affected system to resume
normal operation.

VII. VENDOR FIX/RESPONSE

Microsoft has provided fixes for Proxy Server 2.0 and ISA Server at
http://www.microsoft.com/technet/security/bulletin/MS03-012.asp .

VIII. CVE INFORMATION

The Mitre Corp.'s Common Vulnerabilities and Exposures (CVE) Project has
assigned the identification number CAN-2003-0110 to this issue.

IX. DISCLOSURE TIMELINE

01/23/2003 Issue disclosed to iDEFENSE
02/24/2003 security@microsoft.com contacted
02/24/2003 Response from Iain Mulholland, MSRC
02/25/2003 iDEFENSE clients notified
03/03/2003 Status request from iDEFENSE
03/11/2003 Status request from iDEFENSE
03/11/2003 Response from Iain Mulholland, MSRC
03/13/2003 Status request from iDEFENSE
03/18/2003 Status request from iDEFENSE
03/18/2003 Response from Iain Mulholland, MSRC
03/24/2003 Status request from iDEFENSE
03/25/2003 Response from Iain Mulholland, MSRC
04/09/2003 Public Disclosure



Get paid for security research
http://www.idefense.com/contributor.html

Subscribe to iDEFENSE Advisories:
send email to listserv@idefense.com, subject line: "subscribe"


About iDEFENSE:

iDEFENSE is a global security intelligence company that proactively
monitors sources throughout the world — from technical
vulnerabilities and hacker profiling to the global spread of viruses
and other malicious code. Our security intelligence services provide
decision-makers, frontline security professionals and network
administrators with timely access to actionable intelligence
and decision support on cyber-related threats. For more information,
visit http://www.idefense.com .


-----BEGIN PGP SIGNATURE-----
Version: PGP 8.0

iQA/AwUBPpR3/frkky7kqW5PEQKypwCdGfcO0FcsIAohajEwZMfnZrmGYh4AoMc5
S+jzjh3evev/30oPRtg/1W75
=N1F/
-----END PGP SIGNATURE-----

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close