Protocol(s)/Service(s):
MS PPTP TCP/IP port 1723
Brief Description: Causes denial of PPTP services to clients and causes
system instability and crash to blue screen.
Description of Variants: Undetermined what the common variable in hardware
that causes some systems to crash easier than others.
Protocol Description: PPTP Provides VPN services to remote users. (See
detailed PPTP description earlier in this document)
How the Exploit Works:
By sending a stream of packets using Netcat targeting port 1723, the attacker is
able to cause the server to blue screen within a few seconds of initiating the
attack. This is caused by the NT PPTP Server having a flaw in it’s code, causing
it to be unable to handle certain types of data packets. These malformed
packets will cause the system to generate memory leaks in the kernel.
This attack sends malformed packets to the listening TCP/IP port 1723.
This is not a flaw in the protocol itself, it is actually a flaw in the implementation
of the protocol by the vendor (Microsoft).
Diagrams & Screenshots:
Attacker is on Internet. Attacker sends malformed packets to VPN server.
0
Do'stlaringiz bilan baham: |