Microsoft Windows NT SynAttackProtect denial of service
| nt-synattackprotect-dos (5573) |
Description:
Windows NT is vulnerable to a denial of service attack if the value for SynAttackProtect registry entry is configured to '1' or '2'. A remote attacker can use the CyberCop Scanner TCP Sequence Prediction check (module 13002) against a vulnerable system to cause the system to crash.
The default value setting for the SynAttackProtect is 0; however, Microsoft recommends changing this value to 2 to prevent a different denial of service attack caused by retransmission of SYN-ACK packets.
Consequences:
Denial of Service
Remedy:
No remedy available as of July 9, 2011.
References:
- BugTraq Mailing List, Wed Nov 22 2000 - 09:13:52 CST: Killing NT 4.0 (HOT FIXES or NO / SP6a) Remotely using SynAttackProtect Key Corrected version and solution FOUND :).
- Microsoft TechNet: Security Considerations for Network Attacks.
- BID-1987: Microsoft NT 4.0 SynAttackProtect Denial of Service Vulnerability
Platforms Affected:
- Microsoft Windows NT 4.0
Reported:
Nov 21, 2000
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
