[NT] Microsoft Distributed Transaction Controller Packet Relay DoS (MS05-051)

From: SecuriTeam (support_at_securiteam.com)
Date: 10/12/05

  • Next message: SecuriTeam: "[NT] Microsoft Distributed Transaction Controller TIP DoS (MS05-051)"
    To: list@securiteam.com
    Date: 12 Oct 2005 09:13:13 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      Microsoft Distributed Transaction Controller Packet Relay DoS (MS05-051)
    ------------------------------------------------------------------------

    SUMMARY

    The Distributed Transaction Controller provides a method for disparate
    processes to complete atomic transactions. The Transaction Internet
    Protocol (TIP) is one the ways that the DTC service can be accessed. This
    service is part of a standard installation on Windows NT 4.0, Windows
    2000, Windows XP and Windows 2003.

    Remote exploitation of a denial of service vulnerability within various
    versions of Microsoft Corp.'s Windows operating system allows attackers to
    flood systems with connection attempts from legitimate MSDTC servers.

    DETAILS

    Vulnerable Systems:
     * Microsoft Windows 2000 SP4

    The vulnerability specifically exists because of the functionality in the
    TIP protocol that allows a remote IP address and port number to be
    specified for a connection. The attack can be performed by connecting to
    the MSDTC server and providing an identifier that contains the IP address
    and port number to flood. After a specific sequence of commands, the
    attacker can force an error and cause the DTC service to connect to the
    target IP and port. The DTC service will continue to make connections to
    that host and port, one at a time, per stalled transaction.

    If the target host and port provides anything other than a certain set of
    response messages to the IDENTIFY request on the connection, the DTC
    service will disconnect and then reconnect to the service. The attacker
    can keep submitting new transactions to the DTC service, increasing the
    total number of connections made to the target.

    Analysis:
    Successful exploitation of this vulnerability could allow an attacker to
    proxy a denial of service attack through a MSDTC server that they do not
    otherwise have access to. An attacker could easily scan public IP ranges
    and find servers with TIP enabled and then force them to flood a target
    with repeated connections attempts.

    This attack can also be used to cause a DoS on the MSDTC server itself by
    specifying a loopback address with port 445. This service should not be
    exposed to public networks, thus mitigating the risk of this
    vulnerability.

    Vendor response:
    The vendor security advisory and appropriate patches are available at:
    <http://www.microsoft.com/technet/security/Bulletin/MS05-051.mspx>
    http://www.microsoft.com/technet/security/Bulletin/MS05-051.mspx

    CVE Information:
     <http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1980>
    CAN-2005-1980

    Disclosure Timeline:
    03/23/2005 Initial vendor notification
    03/23/2005 Initial vendor response
    10/11/2005 Coordinated public disclosure

    ADDITIONAL INFORMATION

    The information has been provided by
    <mailto:idlabs-advisories@lists.idefense.com> iDEFENSE Labs Security
    Advisories.
    The original article can be found at:
    <http://www.idefense.com/application/poi/display?id=319&type=vulnerabilities> http://www.idefense.com/application/poi/display?id=319&type=vulnerabilities

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[NT] Microsoft Distributed Transaction Controller TIP DoS (MS05-051)"

    Relevant Pages

    • RE: Port-Knocking vulnerabilities?
      ... Port Knocking is obfuscation and not a security technique. ... It was and is designed not as a security function, but as a channel to hide communications on compromised hosts. ... Subject: Port-Knocking vulnerabilities? ... what an attacker could ...
      (Security-Basics)
    • RE: Exhange 2003
      ... I work for an enterprise email security company and saw something rather ... no restriction on ports or types of traffic just on host... ... if you don't establish the TCP connection to ... >Nbtstat command is sending packets to udp 137 port of destination. ...
      (Pen-Test)
    • [UNIX] IRC Connection Tracking Helper Module (Patch Available)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The NetFilter subsystem in Linux kernels>= 2.4.14 contains a connection ... tracking helper module for the IRC DCC protocol. ... source ip, source port, destination IP, destination port) and mask ...
      (Securiteam)
    • RE: Port-Knocking vulnerabilities?
      ... Network Security Officer ... Port knocking) you can sniff packets and capture for analysis. ... not necessarily endorsed by BDO Kendalls. ... If an attacker can do that, ...
      (Security-Basics)
    • [NT] Buffer Overrun in Windows Help and Support Center Could Lead to System Compromise (MS03-044)
      ... Get your security news from a reliable source. ... A security vulnerability exists in the Help and Support Center function ... *Microsoft Windows Millennium Edition ... An attacker could exploit the vulnerability by constructing a URL that, ...
      (Securiteam)