Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Group policy DoS in Windows NT/2000

  Security Bulletin MS02-016 Q318593: Opening Group Policy Files for Exclusive Read Blocks Policy Application

  SECURITY.NNOV: file locking and security

From:Jonathan Hunter <jonathan.hunter+dated+1043753340.86cf13_(at)_ptel.co.uk>
Date:24.01.2003
Subject:DoS attack on Windows 2000 Terminal Server

This one's short and simple..

Description
-----------

Any user with sufficient permission to log on to a Windows 2000 Terminal
Server (via RDP or ICA) and access its filesystem can reboot the server
at will.


Exploit
-------

- Open %SYSTEMROOT%\SYSTEM32\MSGINA.DLL for exclusive access (read lock).
 I used Radsoft's HEXVIEW.EXE from Rix2K to do this.

- Open a new connection to the server via RDP/ICA

- Click the nice, helpful "Restart" button in the warning dialog that
 appears ("msgina.dll failed to load")

Tested on Windows 2000 Server (IE55, SP2) and Windows 2000 Server (IE55,
SP3). I do not have easy access to other platforms at the moment.


Workaround
----------

- Remove all permissions from MSGINA.DLL for "Power Users", "Users" and
 "Everyone"

Note: The above workaround has been tested on Windows 2000 Server (IE55,
SP2) and users were still able to log in as normal. I am not aware of a
need for MSGINA.DLL to be accessible by normal users, but if there are
any such circumstances Microsoft will need to produce an alternative fix.


Vendor status
-------------

Contacted on 16/01/2003. Replied to my email the next day requesting
additional time to investigate. No further replies since 17/01/2003.


Thanks
------

Thanks to PPH for the use of a Windows 2000 Server IE55,SP2 machine!

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server