Remote D.o.S Attack in DNS PRO v5.7 WinNT From FBLI Software Vulnerability

   

DNS PRO v5.7

DNS PRO v5.7

ddnspro.exe

(Binary D.O.S)

ddnspro.zip

(Source of binary d.o.s)

USSR Advisory Code:    22


Release Date:
December 21, 1999


Systems Affected:
DNS PRO v5.7 and possibly others.


About The Software:
The first DNS Server for Windows NT
- Database engine five time faster.  
- New DNS Console.  
- New more readable file format.  
- New and enhanced DNS control applet.  
- New and enhanced DNS Database applet.  
- Bind 4.9.6 compatible.  
- Cache poisoning secure.  
- Reverse lookup files sorted by IP Address.  
- Event logs filters.  


THE PROBLEM


UssrLabs found a Remote DoS Attack in DNS PRO v5.7 WinNT,
The D.o.S is caused by a multiples connections at the same
time (over 30) in the Dns Port (53), and some characters to
the port.

If DNS PRO v5.7 is running as service, Take all computer
resources = CPU 100%.


There is not much to expand on.... just a simple hole


Vendor Status:
Contacted


Vendor  Url: http://www.fbli.com/
Program Url: http://www.fbli.com/english/dnspro.htm


Credit: USSRLABS


SOLUTION
  That will be fixed soon, vendor say that.


Greetings:
Eeye, Attrition, w00w00, beavuh, Rhino9, ADM, L0pht, HNN,
Technotronic and Wiretrip.