Re: IP DOS attacks -- Win95 patches available

From: Paul Leach (paulleat_private)
Date: Fri Nov 21 1997 - 14:34:59 PST

  • Next message: shegget: "XFree86 insecurity"

    Well, I have to mea culpa again. This doesn't fix "land", but it does make
    once again available the fixes for all the others (including the new
    "teardrop" attack) for Winsock1.1 users. I misunderstood the information I
    was given.
    
    
    > ----------
    > From:         Paul Leach
    > Sent:         Friday, November 21, 1997 12:52 PM
    > To:   'BUGTRAQat_private'; 'ntsecurityat_private';
    > 'NTBUGTRAQat_private'
    > Subject:      IP DOS attacks -- Win95 patches available
    >
    > There are patches available for the "land" attack for Windows 95. They
    > include fixes for all the previous IP DOS attacks we have seen, including
    > jolt, ssping, exploit, synk4, teardrop, winnuke (in conjunction with the
    > VTCPUPD patch).
    >
    > There are two patches, one if you have Winsock 1.1, and one if you have
    > Winsock2. (If you have a file called ws2_32.dll in \windows\system, then
    > you've got Wisock2)
    >
    > For Winsock 1.1:
    > http://support.microsoft.com/download/support/mslfiles/Vipup11.exe
    >
    > For Winsock 2:
    > http://support.microsoft.com/download/support/mslfiles/Vipup20.exe
    >
    > You also need to install the VTCPUPD patch:
    >       http://support.microsoft.com/download/support/mslfiles/Vtcpupd.exe
    >
    > Remember -- we can't test all configurations, etc., in this little time,
    > so don't apply to large numbers of machines blindly. I'd advise that you
    > make a backup copy of your current vip.386, vtcp.386 and vnbt.386 before
    > applying -- if things go badly, just put them back. (They're in
    > \windows\system.)
    >
    > Paul
    >
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 13:32:41 PDT