Microsoft pptp vpn vulnerabilities Exploits in Action


© SANS Institute 2000 - 200



Download 2 Mb.
Pdf ko'rish
bet74/144
Sana16.01.2022
Hajmi2 Mb.
#372744
1   ...   70   71   72   73   74   75   76   77   ...   144
Bog'liq
microsoft-pptp-vpn-vulnerabilities-exploits-action 337

© SANS Institute 2000 - 200
                                                5
, Author retains full rights.
 
 
 
 
 
 
 
 
 
 
 
 
Key fingerprint = AF19 FA27 2F94 998D FDB5 DE3D F8B5 06E4 A169 4E46 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Key fingerprint = AF19 FA27 2F94 998D FDB5 DE3D F8B5 06E4 A169 4E46 
 
© SANS Institute 2000 - 200
5                                                                                                                 
Author retains full rights.
48
7:30, CPU utilization dropped, though memory still at 125,220K
Though CPU utilization dropped, system still unresponsive (though not "locked 
up" per se).
7:32: Start> Shutdown>Shutdown, system starts shutdown process, then hangs 
for a few seconds, then aborts shutdown with the following error message:
You do not have permission to shutdown this computer.
7:33, system CPU usage suddenly jumps back up to 100%.
7:34 tried again to shutdown,  this time the system blue screens with dump of 
physical memory and beginning error of SCSI_DISK_DRIVER_INTERNAL 
(there's no SCSI in this system btw, it's all IDE).
upon booting back up, and after the HD corruption was chkfs.
It was utilizing 290MB or ram and about 50% CPU running savedump.exe for 
quite a while (about 5 minutes) after fully booting up. finally it finished and went 
back to normal.
save event logs as pptpattack3systemlogs.evt
System once again idling at 29Mb and 0-1% CPU.
Now, test while a client is connected to see if that offers any protection against 
this attack the way it did for attack1.
results:
Client couldn't connect (attack not yet started). Error logs stated that DHCP 
couldn't be assigned, note the logs are full of DHCP errors too.
list the log errors.
performed another system shutdown to see if maybe the extensive system 
utilization during startup from the savedump.exe caused some issues.
Try again:
DHCP still hosed.
Is this a side effect of the attack? Or is it more likely caused by the repeated 
dumps and blue screening corrupting some key system files.
Will attempt removal, reboot, and reinstallation of MS DHCP Server and see if it 
resolves that particular problem or not.
reinstalling DHCP server eliminated the boot up errors, but still received an error 
that DHCP couldn't be assigned to client when client tried to connect.
Now uninstalling PPTP and RAS, rebooting, and reinstalling PPTP and RAS to 
see if that fixes it.
Finally reconfigured new DHCP scopes since I had removed and reinstalled 
DHCP those were removed. k.
0



Download 2 Mb.

Do'stlaringiz bilan baham:
1   ...   70   71   72   73   74   75   76   77   ...   144




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish