Microsoft Windows SynAttackProtect Predictable Hash Remote Denial of Service Vulnerability
BID:15613
Info
Microsoft Windows SynAttackProtect Predictable Hash Remote Denial of Service Vulnerability
| Bugtraq ID: | 15613 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2005 12:00AM |
| Updated: | Nov 28 2005 12:00AM |
| Credit: | Discovered by Luigi Mori <[email protected]>. |
| Vulnerable: |
Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: |
Microsoft Windows Server 2003 Web Edition SP1 Microsoft Windows Server 2003 Standard Edition SP1 Microsoft Windows Server 2003 Enterprise Edition SP1 Microsoft Windows Server 2003 Datacenter Edition SP1 |
Discussion
Microsoft Windows SynAttackProtect Predictable Hash Remote Denial of Service Vulnerability
Microsoft Windows is prone to a denial of service vulnerability.
The vulnerability arises due to a design error in the function responsible for the hash table management for 'SynAttackProtect'. Reports indicate that the affected function used by the TCP/IP stack creates a predictable hash, allowing an attacker to send a large number of SYN packets with an identical hash value.
A successful attack can eventually lead to a denial of service condition due to the lookup algorithm becoming very inefficient at performing searches.
Microsoft Windows is prone to a denial of service vulnerability.
The vulnerability arises due to a design error in the function responsible for the hash table management for 'SynAttackProtect'. Reports indicate that the affected function used by the TCP/IP stack creates a predictable hash, allowing an attacker to send a large number of SYN packets with an identical hash value.
A successful attack can eventually lead to a denial of service condition due to the lookup algorithm becoming very inefficient at performing searches.
Exploit / POC
Microsoft Windows SynAttackProtect Predictable Hash Remote Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Windows SynAttackProtect Predictable Hash Remote Denial of Service Vulnerability
Solution:
It has been reported that Windows 2003 SP1 and Windows 2000 SP4 with Update Roll-Up are not vulnerable to this issue. This was not confirmed by Symantec.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that Windows 2003 SP1 and Windows 2000 SP4 with Update Roll-Up are not vulnerable to this issue. This was not confirmed by Symantec.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Windows SynAttackProtect Predictable Hash Remote Denial of Service Vulnerability
References:
References:
- Technet Security (Microsoft)
- Flaw in Syn Attack Protection on non-updated Microsoft OSes can lead to DoS ("Luigi Mori"
)