Denial of Service in Lotus Domino 5.08 and earlier HTTP Server

From: Hendrik-Jan Verheij (h.j.verheijat_private)
Date: Fri Nov 30 2001 - 07:14:11 PST

  • Next message: Rapid 7 Security Advisories: "Rapid 7 Advisory R7-0002: Alchemy Eye Remote Unauthenticated Log Viewing"

    There exists a DOS in the current version of Lotus Domino 5.08 and earlier.
    The DOS manifests  itself on Lotus Domino servers with the http task
    running and ssl enabled.
    A connection to the victim on port 443  with the nmap '-sR' switch will
    target this port with SunRPC program NULL commands  in  an  attempt  to
    determine  whether  it is an  RPC port, and if so, what program and version
    number it serves up.
    Our first attempt brought the domino test server down. Tests on other
    setups revealed the same behaviour.
    The task that crashes is the nhttp task. It takes down the whole server.
    the nmap command used:
    nmap -n -p 443 -sR
    Lotus has acknowledged the issue and the internal reference number is SPR #
    The issue has been fixed in Lotus Domino 5.09 which is available from as an incremental upgrade.
    Thanks to Ninke Westra for discovering the issue and for the testing.
    Hendrik-Jan Verheij
    BWSS    Phone +(31) 0570-665140
    BWSS    Fax      +(31) 0570-665141
    Business Wide Services and Solutions
    It was OK before you touched it !

    This archive was generated by hypermail 2b30 : Fri Nov 30 2001 - 14:52:42 PST