global security disclosure

Labs6.html

Labs6.html
Posted Feb 9, 2000

USSR Advisory #6 - Remote DoS Attack in BFTelnet Server v1.1 for Windows NT. UssrLabs found a Remote DoS Attack in BFTelnet Server v1.1 for Windows NT. The buffer overflow is caused by a long user name 3090 characters. If BFTelnet Server is running as a service the service will exit and no messages are displayed on the screen.

tags | remote, overflow
systems | windows, nt
MD5 | d414b90ba38d6a9713682304501ef0f9

Labs6.html

Change Mirror Download
<html>
<head>
<title>u n d e r g r o u n d s e c u r i t y s y s t e m s r e s e a r c h</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
</head>

<body bgcolor="#FFFFFF" text="#000000" link="#486090" vlink="#485888" alink="#405888" background="fondo_ussr2.jpg">
<table border="0" width="96%" cellspacing="20" cellpadding="20" height="1037">
<tr>
<td height="964">
<center>
<table border="0" cellspacing="2" cellpadding="2" width="100%">
<tr>
<td colspan="2" align="LEFT" valign="MIDDLE" bgcolor="#309880"><font face="Verdana" size="-1" color="#FFFFFF">
<font size="+1"><a name="org"></a>Remote DoS Attack in BFTelnet
Server v1.1 for Windows NT</font></font></td>
</tr>
<tr>
<td width="29%" align="LEFT" valign="TOP">&nbsp;</td>
<td width="71%" align="LEFT" valign="TOP">&nbsp;</td>
</tr>
<tr>
<th width="29%" align="LEFT" valign="TOP" height="32"><font face="Verdana" size="-1">
BFTelnet Server v1.1</font></th>
<td width="71%" align="LEFT" valign="TOP" height="32"><font face="Verdana" size="-1">
</font><font face="Verdana" size="-1"><font face="Verdana" size="-1"><font face="Verdana" size="-1"><font size="+1">BFTelnet
Server v1.1 for Windows NT</font></font><font face="Verdana" size="-1"></font><font face="Verdana" size="-1"></font></font></font></td>
</tr>
<tr>
<th width="29%" align="LEFT" valign="TOP" height="957">
<p>&nbsp;</p>
</th>
<td width="71%" align="LEFT" valign="TOP" height="957">
<p><b><font size="4">Problem:</font></b></p>
<p align="left"> <font face="Arial, Helvetica, sans-serif" size="2">PROBLEM
</font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">UssrLabs
found a Remote DoS Attack in BFTelnet Server v1.1 for Windows
NT.</font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">
The buffer overflow is caused by a long user name 3090 characters.</font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">
If BFTelnet Server is running as a service the service will exit</font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">
and no messages are displayed on the screen. </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">There
is not much to expand on.... just a simple hole </font></p>
<p align="left">&nbsp;</p>
<p align="left"><font size="2" face="Arial, Helvetica, sans-serif"><b>Example:
</b> </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">palometa@hellme]$
telnet example.com </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Trying
example.com... </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Connected
to example.com. </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Escape
character is '^]'. </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Byte
Fusion Telnet, Copyright 1999 Byte Fusion Corporation </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Unregistered
Evaluation. See www.bytefusion.com/telnet.html </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">(Machine
name) Login: [buffer] </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Where
[buffer] is aprox. 3090 characters. </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">At
his point the telnet server close. </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Vendor
Status: </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Contacted
</font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Vendor
Url: www.bytefusion.com</font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">
Program Url: www.bytefusion.com/telnet.html </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">Credit:
USSRLABS </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">SOLUTION:</font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">
Nothing yet. </font></p>
<p align="left"><font face="Arial, Helvetica, sans-serif" size="2">u
n d e r g r o u n d s e c u r i t y s y s t e m s r e s e a r
c h </font></p>
</td>
</tr>
</table>
<p>&nbsp;</p>
</center>
</td>
</tr>
</table>
</body>
</html>

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close