WINS数据库拒绝服务漏洞

WINS数据库拒绝服务漏洞

漏洞ID 1105328 漏洞类型 未知
发布时间 1997-10-07 更新时间 2005-05-02
图片[1]-WINS数据库拒绝服务漏洞-安全小百科CVE编号 CVE-1999-0294
图片[2]-WINS数据库拒绝服务漏洞-安全小百科CNNVD-ID CNNVD-199710-006
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/20564
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-199710-006
|漏洞详情
WINS数据库的所有记录可以通过删除SNMP导致服务拒绝。
|漏洞EXP
source: http://www.securityfocus.com/bid/2244/info


The Simple Network Management Protocol (SNMP) provides remote network administration functions. Windows NT provides an optional SNMP implementation. Windows NT networks can use Windows Internet Name Service (WINS), a DNS-like service, to register clients on the network. The SNMP service provided with NT Server 4.0 and NT Server 4.0 Terminal Server Edition allow a remote user to delete WINS records, initiating a denial of service against the network. The only caveat to this is that the attacker must know the SNMP community name and be able to access the SNMP service. This does represent a significant vulnerability because regular access control functions are bypassed by the SNMP function, and SNMP community names are often left at their default values (eg., "public"). 

"Since the SNMP toolset implemented under NT will not do
snmp-set-requests, my sample exploit was done using the CMU SNMP
development kit under Unix. The command "rnjdev02:~/cmu$ snmpset -v 1
192.178.16.2 public .1.3.6.1.4.1.311.1.2.5.3.0 a 192.178.16.2"
successfully entirely deleted my WINS database."
|参考资料
VulnerablesoftwareandversionsConfiguration1OR*cpe:/a:microsoft:wins*DenotesVulnerableSoftware*ChangesrelatedtovulnerabilityconfigurationsTechnicalDetailsVulnerabilityType(ViewAll)CVEStandardVulnerabilityEntry:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0294

相关推荐: Webmin Static SSL Key Vulnerability

Webmin Static SSL Key Vulnerability 漏洞ID 1101416 漏洞类型 Design Error 发布时间 2002-10-08 更新时间 2002-10-08 CVE编号 N/A CNNVD-ID N/A 漏洞平台 N/A…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享