Re: Microsoft's Network Monitor - Buffer Overrun / Page Fault / V

From: Friedrichs, Oliver (Oliver_Friedrichsat_private)
Date: Tue Dec 15 1998 - 14:51:09 PST

  • Next message: Patrick Oonk: "Security Bulletins Digest (fwd)"

    >There is a problem with both the SMS version of Network Monitor
    >and the version on the NT Server 4 CD-ROM whereby if it "sniffs"
    >a NetBIOS session request from a machine where the NetBIOS Scope
    >ID is 190 or more characters when the capture is stopped and the
    >results are viewed the Network Monitor process (netmon.exe)
    >experiences a memory problem.
    
    I found this awhile ago as well.  The same type of overflow also
    occurs virtually anytime it decodes a NetBIOS name larger than
    15 characters.
    
    What scares me more are network based ID systems which may
    do something similar when decoding packets.
    
    - Oliver
      Network Associates, Inc.
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:24:56 PDT