NT Telnetd Vulnerability
BID:140
Info
NT Telnetd Vulnerability
| Bugtraq ID: | 140 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | Unknown |
| Published: | Jan 02 1999 12:00AM |
| Updated: | Jan 02 1999 12:00AM |
| Credit: | Tomas Halgas ([email protected]) first reported this on bugtraq - http://www.geek-girl.com/bugtraq/1999_1/0018.html. |
| Vulnerable: |
Microsoft Windows NT 3.5.1 SP5 Microsoft Windows NT 3.5.1 SP4 Microsoft Windows NT 3.5.1 SP3 Microsoft Windows NT 3.5.1 SP2 Microsoft Windows NT 4.0 SP5 Microsoft Windows NT 4.0 SP4 Microsoft Windows NT 4.0 SP3 Microsoft Windows NT 4.0 SP2 Microsoft Windows NT 4.0 SP1 Microsoft Windows NT 4.0 |
| Not Vulnerable: | |
Discussion
NT Telnetd Vulnerability
A vulnerability exists within Microsoft's Telnetd daemon which allows a denial of service condition. The popular scanning tool, Nmap 2.01 or later can crash telnetd services when using the SYN scanning flag (-sS).
A vulnerability exists within Microsoft's Telnetd daemon which allows a denial of service condition. The popular scanning tool, Nmap 2.01 or later can crash telnetd services when using the SYN scanning flag (-sS).
Exploit / POC
NT Telnetd Vulnerability
nmap -sS -p 23 <target>
nmap -sS -p 23 <target>
Solution / Fix
NT Telnetd Vulnerability
Solution:
Remove the NT telnetd service. The telnetd which ships with NT is not a supported product but a part of the resource kit.
Solution:
Remove the NT telnetd service. The telnetd which ships with NT is not a supported product but a part of the resource kit.
References
NT Telnetd Vulnerability
References:
References: