From shok@cannabis.dataforce.net Wed Dec 22 17:10:39 1999 From: Matt Conover To: w00w00@blackops.org Date: Thu, 23 Dec 1999 01:03:19 +0300 (MSK) Subject: ussr adv and #13 Remote D.o.S Attack in DNS PRO v5.7 WinNT From FBLI Software Vulnerability USSR Advisory Code: 22 Release Date: December 21, 1999 Systems Affected: DNS PRO v5.7 and possibly others. About The Software: The first DNS Server for Windows NT - Database engine five time faster. - Tabs now work in the control panels. - Automatic creation of reverse mapping for class A, B and C.(unavailable anywhere). - New DNS Console. - New more readable file format. - New and enhanced DNS control applet. - New and enhanced DNS Database applet. - Bind 4.9.6 compatible. - Cache poisoning secure. - Reverse lookup files sorted by IP Address. - Event logs filters. THE PROBLEM UssrLabs found a Remote DoS Attack in DNS PRO v5.7 WinNT, The D.o.S is caused by a Multiples connections at the same time (over 30) in the Dns Port (53), and some characters to the port. If DNS PRO v5.7 is running as service, Take all computer resources = CPU 100%. There is not much to expand on.... just a simple hole Do you do the w00w00? This advisory also acts as part of w00giving. This is another contribution to w00giving for all you w00nderful people out there. You do know what w00giving is don't you? http://www.w00w00.org/advisories.html Binary or source for this Problem: http://www.ussrback.com/ Vendor Status: Contacted Vendor Url: http://www.fbli.com/ Program Url: http://www.fbli.com/english/dnspro.htm Credit: USSRLABS SOLUTION That will be fixed soon, vendor say that. Greetings: Eeye, Attrition, w00w00, beavuh, Rhino9, ADM, L0pht, HNN, Technotronic and Wiretrip. u n d e r g r o u n d s e c u r i t y s y s t e m s r e s e a r c h http://www.ussrback.com