Tom's Hardware > Forum > Windows 2000/NT > Windows 2000/NT General Discussion > Terminal Service Denial of Service

Terminal Service Denial of Service

Forum Windows 2000/NT : Windows 2000/NT General Discussion - Terminal Service Denial of Service

Tom's Hardware: Over 1.4 million members in 6 different countries available to answer all your high-tech questions. Sign up now! Its free!
Word :    Username :           
 

Archived from groups: microsoft.public.win2000.security (More info?)

 

Basically an attacker using NMap at the same time utilizing a SYN scan method
could cause Terminal Services to restart.

Are there any possible remediations for this vulnerability?

Thanks.
Sal

Sponsored Links
Register or log in to remove.

Archived from groups: microsoft.public.win2000.security (More info?)

 

Sal wrote:
> Basically an attacker using NMap at the same time utilizing a SYN
> scan method could cause Terminal Services to restart.
>
> Are there any possible remediations for this vulnerability?
>
> Thanks.
> Sal

Not sure - this isn't really my area, but note that TS questions are best
asked in m.p.windows.terminal_services....you may get a lot more help there.
Also provide more detail about your setup - firewall, VPN (if used), etc....

Reply to Anonymous

Archived from groups: microsoft.public.win2000.security (More info?)

 

You can use a VPN to connect to TS and possibly a firewall could deter the
attack or modifiyng the tcp/ip parameters on the TS. The links below have
more details on what tcp/ip parameters can be hardened via the registry.
For instance Set SynAttackProtect to 2 could be implemented. --- Steve

http://www.microsoft.com/technet/i [...] pip2k.mspx
http://support.microsoft.com/defau [...] 42&sd=tech
http://support.microsoft.com/defau [...] 69&sd=tech




"Sal" <Sal@discussions.microsoft.com> wrote in message
news:D74559E3-8791-4C6E-B031-369D4C00CA85@microsoft.com...
> Basically an attacker using NMap at the same time utilizing a SYN scan
> method
> could cause Terminal Services to restart.
>
> Are there any possible remediations for this vulnerability?
>
> Thanks.
> Sal

Reply to Anonymous

Archived from groups: microsoft.public.win2000.security (More info?)

 

"Sal" <Sal@discussions.microsoft.com> wrote in message
news:D74559E3-8791-4C6E-B031-369D4C00CA85@microsoft.com...

> Basically an attacker using NMap at the same time utilizing a SYN scan
method
> could cause Terminal Services to restart.
>
> Are there any possible remediations for this vulnerability?

Did you google? Where did you read about this? Is there a CVE number or
BID number? If you're talking about this vulnerability:

http://www.securityfocus.com/bid/5376/discussion/
http://www.winnetmag.com/Article/A [...] 37878.html

"The discoverer posted a workaround for Windows 2000 that suggests removing
all permissions on msgina.dll for Power Users, Users, and Everyone."

Not to be cold, but there are a large number of ways someone could DoS you,
and it seems unlikely that anyone would perform this old attack against you
to do it.

Are you really sure you want to be making Terminal Services available from
the Internet? I agree that keeping this port closed at the firewall and
forcing Internet users to VPN or dial into the network first to do TS may be
preferable.

Presumably Microsoft may have already investigated this and may have
determined that it was not feasible to code a solution.


kind regards,

Karl Levinson, CISSP, MCSE, MS MVP Security
levinson_k@despammed.com

Reply to Anonymous

Archived from groups: microsoft.public.win2000.security (More info?)

 

Thank You all for the repsonses.

"Sal" wrote:

> Basically an attacker using NMap at the same time utilizing a SYN scan method
> could cause Terminal Services to restart.
>
> Are there any possible remediations for this vulnerability?
>
> Thanks.
> Sal

Reply to Sal
Tom's Hardware > Forum > Windows 2000/NT > Windows 2000/NT General Discussion > Terminal Service Denial of Service
Go to:

There are 1057 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Sponsored links
  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them