Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Bugtraq: Bugtraq

Trend Micro Officescan Denial of Service

 

 

Bugtraq bugtraq RSS feed   Index | Next | Previous | View Threaded


marc.ruef at computec

Jul 17, 2000, 1:25 PM

Post #1 of 1 (517 views)
Permalink
Trend Micro Officescan Denial of Service

Hi!

I've send you "Trend Micro Officescan Denial of Service" (TMOSDOS for
Windows; compiled win32-exe and the Visual Basic source) which is an
optimized tool for the issue explained on
http://online.securityfocus.com/bid/1013

All advisories describe that a denial of service attack is possible
during sending random data or open more than five connections to the
target port. TMOSDOS opens just one tcp connection, sends just seven
characters ("get / ") to the target and closes after a few seconds the
connection: Thats more effective than the old methods. It seems that
there is an third argument needed to proceed the get-request correctly.
Other seven character requests (e.g. "1234567") don't cause a denial of
service.

Most Intrusion Detection Systems are not able to detect this attack
correctly: They point always to BackOrific because the destination port
is often tcp/12345.

Bye, Marc

--
Computer, Technik & Security
http://www.computec.ch
Attachments: tmosdos.zip (13.7 KB)

Bugtraq bugtraq RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.