This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

New Windows XPSP2 vulnerability

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?date=2005-07-14
Updated July 15th 2005 04:09 UTC
"badpack3t announced the discovery of a so far unpatched vulnerability in Windows XP SP2. The vulnerability in due to a flaw in the remote desktop assistant. This service is NOT FIREWALLED in XP SP2's default firewall configuration. badpack3t was able to cause a blue screen. However, there is a chance that this could be used to execute code remotely.
RDP uses port 3389 TCP. In one MSFT document, 3389 UDP is mentioned, but we could not verify that RDP listens on 3389 UDP.
- http://www.microsoft.com/windowsxp/using/mobility/rdfaq.mspx (Remote Desktop)
Our sensors did see a slight increase in port 3389 TCP scanning ( http://isc.sans.org/port_details.php?port=3389 ) starting about two weeks ago. The increase is small, and somewhat consistent with a small number of new scanners.
Other references to this issue:
- http://secunia.com/advisories/16071/
- https://www.immunitysec.com/pipermail/daily…uly/002185.html …"

:ph34r:
FYI…

- http://isc.sans.org/diary.php?date=2005-07-15
Updated July 15th 2005 17:40 UTC
"Windows 0 day exploit?
News of a 0 day exploit against Windows Remote Desktop this morning has been light on details. A remote DOS is possible and has been discussed on the daily dave mailing list. Remote Desktop is not enabled by default on Windows XP SP2 systems however the terminal services service is running in support of Remote Assistance and Fast user switching. The server does not start a listener on port 3389 until a remote assistance request is sent. However if you enable Remote Desktop your system may be vulnerable.
I doubt that this is the last we are going to hear of this…"

:ph34r:
FYI…

- http://isc.sans.org/diary.php?date=2005-07-15
Updated July 15th 2005 21:45 UTC
"Update:
There is no known *PUBLIC* exploit code in the wild for this vulnerability. The author could release POC code but has chosen not to do so at this time. More information here:
- http://www.securityfocus.com/bid/14259 and here: - - https://www.immunitysec.com/pipermail/daily…uly/002189.html

- http://security-protocols.com/modules.php?…rticle&sid;=2783
"SP research labs (Tom Ferris) has found a remote kernel DoS flaw within Microsoft Windows XP SP2 fully patched, with the firewall on. I have been working with Microsoft to get a patch out for this. I notified them 5/4/2005 about the flaw, and they have been working on it since then. Microsoft told me the patch was going to be released in August. We know its only a DoS, which is kind of boring so this is why we decided to report it to Microsoft. ;-) Here is a screenshot of the crash if you're interested. So, be sure to look out for our advisory and PoC the second Tuesday in August. Thanks, Tom Ferris…"
- http://www.security-protocols.com/upcoming/xp-sp2-remote.jpg

:oops:
FYI…

Microsoft Security Advisory (904797)
Vulnerability in Remote Desktop Protocol (RDP) Could Lead to Denial of Service
- http://www.microsoft.com/technet/security/…ory/904797.mspx
Published: July 16, 2005
"…Our initial investigation has revealed that a denial of service vulnerability exists that could allow an attacker to send a specially crafted Remote Desktop Protocol (RDP) request to an affected system. Our investigation has determined that this is limited to a denial of service, and therefore an attacker could not use this vulnerability to take complete control of a system. Services that utilize the Remote Desktop Protocol are not enabled by default, however if a service were enabled, an attacker could cause this system to restart.
Note Remote Desktop is enabled by default on Windows XP Media Center Edition…

Workarounds
Microsoft has tested the following workarounds. While these workarounds will not correct the underlying vulnerability, they help block known attack vectors. When a workaround reduces functionality, it is identified in the following section.

Block TCP port 3389 at the firewall.
This port is used to initiate a connection with the affected component. Blocking it at the network perimeter firewall will help protect systems that are behind that firewall from attempts to exploit this vulnerability. Additionally, on Windows XP and Windows Server 2003, the Windows Firewall can help protect individual machines. By default, the Windows Firewall does not allow connections to this port. For information on how to disable the Windows Firewall exception for Remote Desktop on these platforms, please visit the following Web site.

Disable Terminal Services or the Remote Desktop feature if they are not required.
If these services are no longer required on a system, you should consider disabling them as a security best practice. Disabling unused and unneeded services helps to reduce your exposure to security vulnerabilities.

For information on how to disable Remote Desktop via Group Policy, Customers should review Microsoft Knowledge Base Article 306300. http://support.microsoft.com/?kbid=306300

Secure Remote Desktop Connections by using an IPsec policy.
Specific configurations would be dependent upon the individual environment. For information about Internet Protocol Security (IPsec), visit the following Web site.

Secure Remote Desktop Connections by employing a Virtual Private Network (VPN) connection…"


:ph34r: