Denial of Service in Lotus Domino 5.08 and earlier HTTP Server

From: Hendrik-Jan Verheij (h.j.verheij@bwss.nl)
Date: 11/30/01


Subject: Denial of Service in Lotus Domino 5.08 and earlier HTTP Server
To: bugtraq@securityfocus.com
Message-ID: <OFE6E25318.5AF1072E-ONC1256B14.005317D1@popin.nl>
From: "Hendrik-Jan Verheij" <h.j.verheij@bwss.nl>
Date: Fri, 30 Nov 2001 16:14:11 +0100


There exists a DOS in the current version of Lotus Domino 5.08 and earlier.

The DOS manifests itself on Lotus Domino servers with the http task
running and ssl enabled.

A connection to the victim on port 443 with the nmap '-sR' switch will
target this port with SunRPC program NULL commands in an attempt to
determine whether it is an RPC port, and if so, what program and version
number it serves up.

Our first attempt brought the domino test server down. Tests on other
setups revealed the same behaviour.

The task that crashes is the nhttp task. It takes down the whole server.

the nmap command used:

nmap -n -p 443 -sR www.vicitim.com

Lotus has acknowledged the issue and the internal reference number is SPR #
MALR4Y6RL8

The issue has been fixed in Lotus Domino 5.09 which is available from
www.notes.net as an incremental upgrade.

Thanks to Ninke Westra for discovering the issue and for the testing.

regards,

Hendrik-Jan Verheij http://redheat.org
BWSS Phone +(31) 0570-665140
BWSS Fax +(31) 0570-665141
h.j.verheij@bwss.nl http://www.bwss.nl
Business Wide Services and Solutions

It was OK before you touched it !



Relevant Pages

  • [NEWS] Lotus Domino DoS (Message Loop)
    ... Lotus Domino DoS (Message Loop) ... When a message is sent to a Lotus Domino server with an envelope similar ... There is a row of tabs on the top; ...
    (Securiteam)
  • Vulnerability discovered on Lotus Domino server "admin4.nsf"
    ... I'm doing an external blackbox PT on a mail server running Lotus ... The server OS is Windows 2000 and web server is Lotus Domino. ... this vulnerability and how to get a proper sense of it. ... vulnerability management needs. ...
    (Pen-Test)
  • [NT] Lotus Domino Physical Path Revealed
    ... Due to problems handling Windows DOS devices, the Domino Server can be ... - Lotus Domino version 5.0.9a on Windows 2000 Server ... The vendor was contacted on 7 February, ...
    (Securiteam)
  • Lotus Domino DoS
    ... Some oddly formed mail envelopes can cause Lotus Domino to ... enter a mail routing loop and consume 100% CPU. ... where domain.com is not local to the server in question, ... the server attempts to bounce the message, ...
    (Bugtraq)
  • Re: Whats this bozo trying to do?
    ... is a http server with a 'under construction' default page. ... look at the www.apache.org for the appropriate patches for your own server. ... tortura é sempre instrumento do estado, dos pais, dos professores.. ...
    (comp.os.linux.security)