Re: Microsoft IKE DoS... source port 500?

From: Nelson Brito (nelson@tw-award.com)
Date: 10/12/01


From: "Nelson Brito" <nelson@tw-award.com>
To: <abegetchell@home.com>, <vuln-dev@securityfocus.com>
Date: Fri, 12 Oct 2001 08:31:02 -0300



[...]

: source port of 500? Is this one of those 'unofficial standards' and
: hence the reason for Microsoft's implementation processing these packets
: as normal?

[...]

If you send a UDP scan from nmap you will see this port IS OPEN, so you can
realize that when UDP packet is send to any port, this port procced if it is
work.

PS: Attached is a proof-of-concept code that I sent to Security Focus.

Sem mais,

--
Nelson Brito




Relevant Pages

  • Re: What is going on with my Dialup?
    ... also forward it to an unused port, and have that port provide the ... verses the RST or ICMP 3,3. ... The lack of response causes the remote computer to make ... Others think that by not responding to unwanted packets, ...
    (comp.os.linux.networking)
  • Re: OT .. Road Warrior communications question
    ... The data on the Internet is sent in little packets. ... The packets addressed to port 80 ... Likewise, at the mail server receiving the packets, it knows the return ... Why would e-mail work on the web but not from your e-mail software? ...
    (alt.guitar.bass)
  • Re: Logs: Many hits with source port of 80
    ... The hits from source port 80 to dest port 37852 are IMHO almost ... you should probably see a couple other packets - perhaps ... packets if either you send the load balancer a packet, ... >>I have seen similar hits for the past three months. ...
    (Incidents)
  • Re: Error 720 connecting to server via VPN
    ... By default the router's firewall is configured to drop ICMP packets ... Select WAN Setup> Advanced> Respond to Ping on Internet Port. ... server and the Internet allow GRE packets. ... routers on the user's network are also configured to allow GRE packets. ...
    (microsoft.public.windows.server.sbs)
  • Re: WORM? ... server generating NBT-NS (port 137) traffic on WAN interface
    ... You have a concern about the outbound port 137 traffic in the SBS domain. ... The UDP 137 is related to the NetBIOS Over TCP/IP name service. ... I did run NETMON on the SBS2003 box, it did find the extraneous packets ... ... connected to the Internet (If the SBS server is the 2 NICs scenario). ...
    (microsoft.public.windows.server.sbs)