Remote D.o.S Attack in DNS PRO v5.7 WinNT From FBLI Software

From: Ussr Labs (labsat_private)
Date: Mon Dec 20 1999 - 23:02:11 PST

  • Next message: Alain Thivillon: "serious Lotus Domino HTTP denial of service"

    Remote D.o.S Attack in DNS PRO v5.7 WinNT From FBLI Software Vulnerability
    
    USSR Advisory Code:    22
    
    Release Date:
    December 21, 1999
    
    Systems Affected:
    DNS PRO v5.7 and possibly others.
    
    About The Software:
    The first DNS Server for Windows NT
    - Database engine five time faster.
    - Tabs now work in the control panels.
    - Automatic creation of reverse mapping for class A, B and C.(unavailable
      anywhere).
    - New DNS Console.
    - New more readable file format.
    - New and enhanced DNS control applet.
    - New and enhanced DNS Database applet.
    - Bind 4.9.6 compatible.
    - Cache poisoning secure.
    - Reverse lookup files sorted by IP Address.
    - Event logs filters.
    
    THE PROBLEM
    
    UssrLabs found a Remote DoS Attack in DNS PRO v5.7 WinNT, The D.o.S is
    caused by a
    Multiples connections at the same time (over 30) in the Dns Port (53), and
    some characters to the port.
    If DNS PRO v5.7 is running as service, Take all computer resources = CPU
    100%.
    
    There is not much to expand on.... just a simple hole
    
    Do you do the w00w00?
    This advisory also acts as part of w00giving. This is another contribution
    to w00giving for all you w00nderful people out there. You do know what
    w00giving is don't you? http://www.w00w00.org/advisories.html
    
    Binary or source for this Problem:
    http://www.ussrback.com/
    
    Vendor Status:
    Contacted
    
    Vendor   Url: http://www.fbli.com/
    Program Url: http://www.fbli.com/english/dnspro.htm
    
    Credit: USSRLABS
    
    SOLUTION
      That will be fixed soon, vendor say that.
    
    Greetings:
    Eeye, Attrition, w00w00, beavuh, Rhino9, ADM, L0pht, HNN, Technotronic and
    Wiretrip.
    
    u n d e r g r o u n d  s e c u r i t y  s y s t e m s  r e s e a r c h
    http://www.ussrback.com
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:22:17 PDT