USSR Advisory #6 - Remote DoS Attack in BFTelnet Server v1.1 for Windows NT. UssrLabs found a Remote DoS Attack in BFTelnet Server v1.1 for Windows NT. The buffer overflow is caused by a long user name 3090 characters. If BFTelnet Server is running as a service the service will exit and no messages are displayed on the screen.
d414b90ba38d6a9713682304501ef0f9<html>
<head>
<title>u n d e r g r o u n d s e c u r i t y s y s t e m s r e s e a r c h</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
</head>
<body bgcolor="#FFFFFF" text="#000000" link="#486090" vlink="#485888" alink="#405888" background="fondo_ussr2.jpg">
<table border="0" width="96%" cellspacing="20" cellpadding="20" height="1037">
<tr>
<td height="964">
<center>
<table border="0" cellspacing="2" cellpadding="2" width="100%">
<tr>
<td colspan="2" align="LEFT" valign="MIDDLE" bgcolor="#309880"><font face="Verdana" size="-1" color="#FFFFFF">
<font size="+1"><a name="org"></a>Remote DoS Attack in BFTelnet
Server v1.1 for Windows NT</font></font></td>
</tr>
<tr>
<td width="29%" align="LEFT" valign="TOP"> </td>
<td width="71%" align="LEFT" valign="TOP"> </td>
</tr>
<tr>
<th width="29%" align="LEFT" valign="TOP" height="32"><font face="Verdana" size="-1">
BFTelnet Server v1.1</font></th>
<td width="71%" align="LEFT" valign="TOP" height="32"><font face="Verdana" size="-1">
</font><font face="Verdana" size="-1"><font face="Verdana" size="-1"><font face="Verdana" size="-1"><font size="+1">BFTelnet
Server v1.1 for Windows NT</font></font><font face="Verdana" size="-1"></font><font face="Verdana" size="-1"></font></font></font></td>
</tr>
<tr>
<th width="29%" align="LEFT" valign="TOP" height="957">
<p> </p>
</th>
<td width="71%" align="LEFT" valign="TOP" height="957">
<p><b><font size="4">Problem:</font></b></p>
<p align="left"> <font face="Arial, Helvetica, sans-serif" size="2">PROBLEM
</font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">UssrLabs
found a Remote DoS Attack in BFTelnet Server v1.1 for Windows
NT.</font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">
The buffer overflow is caused by a long user name 3090 characters.</font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">
If BFTelnet Server is running as a service the service will exit</font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">
and no messages are displayed on the screen. </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">There
is not much to expand on.... just a simple hole </font></p>
<p align="left"> </p>
<p align="left"><font size="2" face="Arial, Helvetica, sans-serif"><b>Example:
</b> </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">palometa@hellme]$
telnet example.com </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Trying
example.com... </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Connected
to example.com. </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Escape
character is '^]'. </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Byte
Fusion Telnet, Copyright 1999 Byte Fusion Corporation </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Unregistered
Evaluation. See www.bytefusion.com/telnet.html </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">(Machine
name) Login: [buffer] </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Where
[buffer] is aprox. 3090 characters. </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">At
his point the telnet server close. </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Vendor
Status: </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Contacted
</font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Vendor
Url: www.bytefusion.com</font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">
Program Url: www.bytefusion.com/telnet.html </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Credit:
USSRLABS </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">SOLUTION:</font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">
Nothing yet. </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">u
n d e r g r o u n d s e c u r i t y s y s t e m s r e s e a r
c h </font></p>
</td>
</tr>
</table>
<p> </p>
</center>
</td>
</tr>
</table>
</body>
</html>
Comments
No comments yet, be the first!