[01.gif] [02.gif] [t3.jpg] NSFOCUS Security Advisory(SA2000-03) Topic: Microsoft WIN9X Malformed IPX packet Denial of Service Release Date£º August 16, 2000 Affected system: ================ - Microsoft Windows 95 - Microsoft Windows 98 - Microsoft Windows 98 Second Edition Non-affected system£º ==================== - Microsoft Windows NT - Microsoft Windows 2000 Impact: ========= NSFOCUS security team has found a security flaw in Microsoft Win9x IPX/SPX protocol implementation. Exploitation of this vulnerability , a malicious user can perform DoS attack to cause an affected system to fail remotely. Description£º ============ When a WIN9x host receives a IPX NMPI packet that has the same source and destination machine name of its own, it will be lead to an infinite loop of sending and receiving packets. This attack will consume a large sum of CPU resource of attacked host .The host will crash with no reaction to any key. Below is the format of the packet: FF FF FF FF FF FF ff ff ff ff ff ff 00 65 E0 E0 | MAC1 | MAC2 | LONG |LLC| 03 FF FF 00 62 00 14 00 00 00 00 FF FF FF FF FF | MAC1 FF 05 51 00 00 00 00 ff ff ff ff ff ff 05 50 00 | PORT| |MAC2 | PORT| 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 F1 01 00 00 41 41 20 20 20 20 20 20 20 20 20 20 20 | COMPUTER NAME 20 20 20 41 41 20 20 20 20 20 20 20 20 20 20 20 | COMPUTER NAME 20 20 20 Workaround: =================== Do not install IPX/SPX protocol if you don't need it. Microsoft has been informed. DISCLAIMS: ========== THE INFORMATION PROVIDED IS RELEASED BY NSFOCUS "AS IS" WITHOUT WARRANTY OF ANY KIND. NSFOCUS DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, EXCEPT FOR THE WARRANTIES OF MERCHANTABILITY. IN NO EVENTSHALL NSFOCUS BE LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL,CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF NSFOCUS HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. DISTRIBUTION OR REPRODUTION OF THE INFORMATION IS PROVIDED THAT THE ADVISORY IS NOT MODIFIED IN ANY WAY. ©Copyright 1999-2000 NSFOCUS. All Rights Reserved. Terms of use. NSFOCUS Security Team NSFOCUS INFORMATION TECHNOLOGY CO.,LTD (http://www.nsfocus.com) ©Copyright 2000 NSFOCUS Information Technology Co.,Ltd. All Rights Reserved. Contact:webmaster@nsfocus.com