Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Windows ICMP DoS (potential code execution)

  Microsoft Security Bulletin MS06-032 Vulnerability in TCP/IP Could Allow Remote Code Execution (917953)

  DOS во встроенном NAT сервере Windows 2000

From:Минаев Андрей <angel3000_(at)_hotbox.ru>
Date:14.06.2006
Subject:Server crash on ICMP packets with Loose Source and Record Route IP options.

Short message translation:

There  are  DoS  conditions  in Windows 2000 built-in NAT server. Tested
configuration:  Windows  2000 English Standard/Advanced Service Pack 4 +
Update  Rollup  1  for  Service  Pack  4  with NAT server enabled. While
routing  packets with options "Loose Source and Record Route" defined by
RFC  791 through server, Windows crashes to BSOD with error in tcpip.sys
or  ntoskrnl.exe,  or  system  hangs  or  system began instable work. It
doesn't  metter  if  packets are from internal or external networks. Use
attached  script  to test vulnerability. On Windows 2003 problem doesn't
present.  It's also likely same problem to present in Windows 2000 + ISA
2000.

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server