Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] [EEYEB20051011B] - Microsoft Distributed Transaction Coordinator Denial of Service |
|---|---|
| Date: | Tue, 9 May 2006 13:02:06 -0700 |
Microsoft Distributed Transaction Coordinator Denial of Service http://www.eeye.com/html/research/advisories/AD20060509b.html Release Date: May 9, 2006 Date Reported: October 11, 2005 Patch Development Time (In Days): 210 Severity: Low (Denial of Service) Systems Affected: Windows NT 4.0 Windows 2000 SP4 Windows XP SP1/SP2 Windows Server 2003 References: This vulnerability has been assigned CVE-2006-1184 Overview: In July 2005, eEye Digital Security notified Microsoft of a critical vulnerability in the Distributed Transaction Coordinator service included with Windows, a report which culminated in the release of the MS05-051 hotfix on October 11th. Following its release, we observed that the hotfix only mitigated the vulnerability, reducing its maximum potential to a denial-of-service attack against the MSDTC service but failing to treat the underlying flaw, and we again reported the finding to Microsoft. In short, an anonymous attacker can slightly modify an existing MSDTC exploit and use it to crash the service, regardless of whether or not the MS05-051 hotfix is installed. Technical Details: The MSDTC RPC vulnerability publicly addressed by MS05-051 took advantage of an unusual memory manager implementation in the MIDL_user_allocate function of MSDTCPRX.DLL, which would accept any allocation size but would only allocate at most 4KB of memory. RPCRT4 would then attempt to store management data at (memory address + requested size), effectively allowing arbitrary memory to be modified, because any arbitrarily large allocation attempt would succeed while only reserving at most 4KB. The MS05-051 hotfix added an upper limit to the allocation size, 0xFA8 on Windows Server 2003 and 0xFB0 on Windows 2000. This check is insufficient to prevent attempts to access memory beyond the allocated 4KB, and in fact, on Windows 2000, MSDTC in its default state may be made to crash with a single BuildContextW request where 'UuidString' or 'GuidIn' has a maximum character count of 0x7D0. Protection: Retina Network Security Scanner has been updated to identify this vulnerability. Blink - Endpoint Vulnerability Prevention - preemptively protects from this vulnerability. Vendor Status: Microsoft has released a patch for this vulnerability, http://www.microsoft.com/technet/security/Bulletin/MS06-018.mspx. Credit: Derek Soeder Greetings: The next one. Copyright (c) 1998-2006 eEye Digital Security Permission is hereby granted for the redistribution of this alert electronically. It is not to be edited in any way without express consent of eEye. If you wish to reprint the whole or any part of this alert in any other medium excluding electronic medium, please email alert@eEye.com for permission. Disclaimer The information within this paper may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are no warranties, implied or express, with regard to this information. In no event shall the author be liable for any direct or indirect damages whatsoever arising out of or in connection with the use or spread of this information. Any use of this information is at the user's own risk. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Unfiltered Header Injection in Apache 1.3.34/2.0.57/2.2.1, Zaninotti, Thiago |
|---|---|
| Next by Date: | [Full-disclosure] [EEYEB20051011A] - Microsoft Distributed Transaction Coordinator Heap Overflow, eEye Advisories |
| Previous by Thread: | Unfiltered Header Injection in Apache 1.3.34/2.0.57/2.2.1, Zaninotti, Thiago |
| Next by Thread: | [Full-disclosure] [EEYEB20051011A] - Microsoft Distributed Transaction Coordinator Heap Overflow, eEye Advisories |
| Indexes: | [Date] [Thread] [Top] [All Lists] |