Denicomp Winsock RSHD/NT Standard Error Denial of Service Vulnerability
BID:3659
Info
Denicomp Winsock RSHD/NT Standard Error Denial of Service Vulnerability
| Bugtraq ID: | 3659 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2001-1184 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | Discovered and posted to Bugtraq by martin rakhmanoff <[email protected]>. |
| Vulnerable: |
Denicomp Winsock RSHD/NT 2.21 (Intel) Denicomp Winsock RSHD/NT 2.20 (Intel) |
| Not Vulnerable: | |
Discussion
Denicomp Winsock RSHD/NT Standard Error Denial of Service Vulnerability
Winsock RSHD/NT is a Remote Shell Daemon for Windows NT and Windows 2000. It uses the standard Unix rsh and rcp commands. rsh (ie "remote shell") allows the execution of a non-interactive program on another system running the server component, 'rshd'. The daemon listens for connections coming from an rsh command through TCP/IP, and, on receiving a connection, validates access and executes the specified program.
Upon connecting to the daemon, rsh will supply a port number for the daemon to send standard error data. If the port number specified is invalid, Winsock RSHD/NT will attempt to connect to the invalid port and all port numbers below 1024 (including negative port numbers). Potentially consuming CPU resources and leading to a denial of service.
Winsock RSHD/NT is a Remote Shell Daemon for Windows NT and Windows 2000. It uses the standard Unix rsh and rcp commands. rsh (ie "remote shell") allows the execution of a non-interactive program on another system running the server component, 'rshd'. The daemon listens for connections coming from an rsh command through TCP/IP, and, on receiving a connection, validates access and executes the specified program.
Upon connecting to the daemon, rsh will supply a port number for the daemon to send standard error data. If the port number specified is invalid, Winsock RSHD/NT will attempt to connect to the invalid port and all port numbers below 1024 (including negative port numbers). Potentially consuming CPU resources and leading to a denial of service.
Exploit / POC
Denicomp Winsock RSHD/NT Standard Error Denial of Service Vulnerability
martin rakhmanoff <[email protected]> has provided the following exploit. 'WRSHDNTDoS.c' is for Winsock RSHD/NT 2.20 and 'WRSHDNTDoS2.21.c' is for Winsock RSHD/NT 2.21.
martin rakhmanoff <[email protected]> has provided the following exploit. 'WRSHDNTDoS.c' is for Winsock RSHD/NT 2.20 and 'WRSHDNTDoS2.21.c' is for Winsock RSHD/NT 2.21.
Solution / Fix
Denicomp Winsock RSHD/NT Standard Error Denial of Service Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Denicomp Winsock RSHD/NT Standard Error Denial of Service Vulnerability
References:
References:
- Denicomp Products Page (Denicomp)