Microsoft Windows NT/2000 NetBIOS Name Conflict Vulnerability
BID:1514
Info
Microsoft Windows NT/2000 NetBIOS Name Conflict Vulnerability
| Bugtraq ID: | 1514 |
| Class: | Serialization Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 27 2000 12:00AM |
| Updated: | Jul 27 2000 12:00AM |
| Credit: | Discovered by Network Associates COVERT Labs and publicized in a Microsoft Security Bulletin (MS00-047) on July 27, 2000. |
| Vulnerable: |
Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows NT/2000 NetBIOS Name Conflict Vulnerability
An attacker can send the NetBIOS name service a NetBIOS Name Conflict message even when the receiving machine is not in the process of registering its NetBIOS name. The target will then not attempt to use that name in any future netwrok connection attempts. This can lead to intermittent connectivity problems, or the loss of all NetBIOS functionality.
An attacker can send the NetBIOS name service a NetBIOS Name Conflict message even when the receiving machine is not in the process of registering its NetBIOS name. The target will then not attempt to use that name in any future netwrok connection attempts. This can lead to intermittent connectivity problems, or the loss of all NetBIOS functionality.
Exploit / POC
Microsoft Windows NT/2000 NetBIOS Name Conflict Vulnerability
Sir Dystic <[email protected]> has provided the following exploit:
Source - nbname.cpp
Binary - nbname.exe
Sir Dystic <[email protected]> has provided the following exploit:
Source - nbname.cpp
Binary - nbname.exe
Solution / Fix
Microsoft Windows NT/2000 NetBIOS Name Conflict Vulnerability
Solution:
Microsoft has released the following patch which mitigates the vulnerability. Conflict messages will only be responded to during the initial name registration process after the patch is applied.
Microsoft Windows NT Enterprise Server 4.0
Microsoft Windows NT Terminal Server 4.0
Microsoft Windows NT Workstation 4.0 SP6a
Microsoft Windows NT Enterprise Server 4.0 SP3
Microsoft Windows NT Workstation 4.0 SP5
Microsoft Windows NT Enterprise Server 4.0 SP4
Microsoft Windows NT Workstation 4.0 SP2
Microsoft Windows NT Enterprise Server 4.0 SP5
Microsoft Windows NT Workstation 4.0 SP4
Microsoft Windows NT Terminal Server 4.0 SP2
Microsoft Windows NT Terminal Server 4.0 SP4
Microsoft Windows NT Server 4.0 SP6a
Microsoft Windows NT Enterprise Server 4.0 SP1
Microsoft Windows 2000 Professional
Microsoft Windows NT Terminal Server 4.0 SP1
Microsoft Windows NT Enterprise Server 4.0 SP2
Microsoft Windows NT Server 4.0 SP3
Microsoft Windows NT Terminal Server 4.0 SP3
Microsoft Windows NT Workstation 4.0 SP6
Microsoft Windows NT Server 4.0 SP1
Microsoft Windows NT Workstation 4.0
Microsoft Windows NT Enterprise Server 4.0 SP6
Microsoft Windows NT Server 4.0
Microsoft Windows NT Terminal Server 4.0 SP6
Microsoft Windows NT Workstation 4.0 SP3
Microsoft Windows NT Enterprise Server 4.0 SP6a
Microsoft Windows NT Server 4.0 SP6
Microsoft Windows NT Server 4.0 SP5
Microsoft Windows NT Server 4.0 SP2
Microsoft Windows NT Terminal Server 4.0 SP5
Microsoft Windows NT Workstation 4.0 SP1
Microsoft Windows 2000 Advanced Server
Microsoft Windows NT Server 4.0 SP4
Microsoft Windows 2000 Server
Solution:
Microsoft has released the following patch which mitigates the vulnerability. Conflict messages will only be responded to during the initial name registration process after the patch is applied.
Microsoft Windows NT Enterprise Server 4.0
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Terminal Server 4.0
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24516
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Enterprise Server 4.0 SP3
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Workstation 4.0 SP5
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Enterprise Server 4.0 SP4
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Workstation 4.0 SP2
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Enterprise Server 4.0 SP5
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Workstation 4.0 SP4
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Terminal Server 4.0 SP2
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24516
Microsoft Windows NT Terminal Server 4.0 SP4
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24516
Microsoft Windows NT Server 4.0 SP6a
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Enterprise Server 4.0 SP1
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows 2000 Professional
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=23370
Microsoft Windows NT Terminal Server 4.0 SP1
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24516
Microsoft Windows NT Enterprise Server 4.0 SP2
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Server 4.0 SP3
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Terminal Server 4.0 SP3
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24516
Microsoft Windows NT Workstation 4.0 SP6
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Server 4.0 SP1
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Workstation 4.0
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Enterprise Server 4.0 SP6
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Server 4.0
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Terminal Server 4.0 SP6
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24516
Microsoft Windows NT Workstation 4.0 SP3
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Enterprise Server 4.0 SP6a
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Server 4.0 SP6
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Server 4.0 SP5
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Server 4.0 SP2
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Terminal Server 4.0 SP5
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24516
Microsoft Windows NT Workstation 4.0 SP1
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows 2000 Advanced Server
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=23370
Microsoft Windows NT Server 4.0 SP4
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows 2000 Server
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=23370
References
Microsoft Windows NT/2000 NetBIOS Name Conflict Vulnerability
References:
References:
- Frequently Asked Questions: Microsoft Security Bulletin (MS00-047) (Microsoft)
- NBName (Sir Dystic)
- Q269239: NetBIOS Vulnerability May Cause Duplicate Name on the Network Conflicts (Microsoft)