NT Terminal Server Multiple Connection Request DoS Vulnerability
BID:571
Info
NT Terminal Server Multiple Connection Request DoS Vulnerability
| Bugtraq ID: | 571 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 09 1999 12:00AM |
| Updated: | Aug 09 1999 12:00AM |
| Credit: | Vulnerability discovered and reported to Microsoft by ISS X-Force. Advisories posted to Bugtraq on August 9, 1999 by both ISS X-Force and Microsoft. |
| Vulnerable: |
Microsoft Windows NT Terminal Server 4.0 |
| Not Vulnerable: | |
Discussion
NT Terminal Server Multiple Connection Request DoS Vulnerability
Windows NT 4.0 Terminal Server will start to create a Terminal Server connection immediately upon receiving a TCP connection on port 3389, even before authenticating the system or user making the request. Each connection instance requires about 1MB of memory. If enough requests are made concurrently to a server with low memory and no cap on simultaneous requests, the system will slow down to the point where it is unusable by legitimate users, and in some cases will crash and need to be rebooted.
Windows NT 4.0 Terminal Server will start to create a Terminal Server connection immediately upon receiving a TCP connection on port 3389, even before authenticating the system or user making the request. Each connection instance requires about 1MB of memory. If enough requests are made concurrently to a server with low memory and no cap on simultaneous requests, the system will slow down to the point where it is unusable by legitimate users, and in some cases will crash and need to be rebooted.
Exploit / POC
NT Terminal Server Multiple Connection Request DoS Vulnerability
see discussion
see discussion
Solution / Fix
NT Terminal Server Multiple Connection Request DoS Vulnerability
Solution:
Microsoft has released a Post-SP4 hotfix to deal with this issue. It can be downloaded at:
ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/NT40tse/hotfixes-postSP4/Flood-fix/
The patch causes the server to authenticate the requester before starting to open the connection.
Solution:
Microsoft has released a Post-SP4 hotfix to deal with this issue. It can be downloaded at:
ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/NT40tse/hotfixes-postSP4/Flood-fix/
The patch causes the server to authenticate the requester before starting to open the connection.
References
NT Terminal Server Multiple Connection Request DoS Vulnerability
References:
References: