Microsoft Windows NT SynAttackProtect denial of service
| nt-synattackprotect-dos (5573) |
Description:
Windows NT is vulnerable to a denial of service attack if the value for SynAttackProtect registry entry is configured to '1' or '2'. A remote attacker can use the CyberCop Scanner TCP Sequence Prediction check (module 13002) against a vulnerable system to cause the system to crash.
The default value setting for the SynAttackProtect is 0; however, Microsoft recommends changing this value to 2 to prevent a different denial of service attack caused by retransmission of SYN-ACK packets.
Platforms Affected:
- Microsoft, Windows NT 4.0
Remedy:
No remedy available as of August 16, 2008.
Consequences:
Denial of Service
References:
- BugTraq Mailing List, Wed Nov 22 2000 - 09:13:52 CST, Killing NT 4.0 (HOT FIXES or NO / SP6a) Remotely using SynAttackProtect Key Corrected version and solution FOUND :) at http://archives.neohapsis.com/archives/bugtraq/2000-11/0315.html.
- Microsoft TechNet, Security Considerations for Network Attacks at http://www.microsoft.com/TechNet/security/dosrv.asp.
- BID-1987: Microsoft NT 4.0 SynAttackProtect Denial of Service Vulnerability
Reported:
Nov 21, 2000
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
