Real-time AntiSpam protection, automated and self-managed content filtering
Black Green Blue Red Gold
RSS
  • Home PageHome
  • About
  • Downloads
  • Store
  • Support
  • Contact

Pragma Patches Telnet DoS Vulnerability

Net Progress Add comments
Pragma Systems Inc., an Internet software products developer for the Windows platform, recently released a patch for their telnet server for Windows NT/2000. The fix eliminates a denial of service (DoS) vulnerability that could cause an application crash if one of two different scenarios is met. The bug, originally reported by the Underground Security Systems Research organization (USSRBack), involves a buffer overflow memory problem in the remote execution daemon (rexecd.exe) in the Pragma Telnet Server. By hitting the server with a carefully constructed Internet packet, a malicious user could crash the Pragma telnet server requiring the server administrator to restart the telnet server application, or, in some situations, to reboot the system.? Telnet and Remote Execution Our testing revealed that the problem is a buffer

overflow caused by a string manipulation with NULL characters. In other words, by introducing approximately 1000 null characters, the REXEC daemon crashes. Buffer overflows are typically caused a user trying to cram more data into a program buffer than the developer originally anticipated. Doing this can have varying effects. But in most cases the buffer overflow causes the vulnerable program to crash. At best, this bug is an inconvenience for the already-harried network administrator who would be required to restart the service. At worst, a buffer overflow could make the server crash, causing a loss of data and service. In order for the vulnerability in Pragma's Telnet Server to be exploited, a malicious user would establish a telnet session. After logging in, this user would then copy the offending code to the server. Once this happens, the next user to log in would kill the telnet server process. Historical Perspective The same problem was found in a previous incarnation of Pragma's telnet server, TelnetD, build 4. In July 2000, this problem was corrected with the release of build 8. Pragma assures us that it has taken steps to prevent this problem from reoccurring in future releases. It is refreshing when a company proactively notifies BugNet of a problem and how they are handling the situation. On September 1, 2000, Pragma notified BugNet of this DoS problem, which was found earlier that week. Since then, Pragma has been working on a patch that was release just days ago. BugNet, with the help of KeyLabs, was able to validate the 6MB patch using sample exploiting code provided by USSRBack. The Telnet Server, build 2 upgrade is available to registered users. Contact Pragma if your system is affected.

August 18th, 2009  
Tags: BugNet, Internet software, Pragma Patches, Pragma's Telnet Server, REXEC daemon crashes, Telnet and Remote Execution, Telnet DoS, TelnetD, USSRBack

Leave a Reply

  • Menu

    • About
    • Contact
    • Downloads
      • List Servers and SMTP Servers
      • Small Business
      • Veriat Enterprise
    • Store
    • Support
  • Categories

    • Anti-Comment Spam Tactics
    • Anti-spam appliances
    • Anti-spam techniques
    • Bug fixing
    • Bug Info
    • Comments
    • Digital Signature
    • Net Progress
    • News
    • Review
    • Spam Facts
    • Spam filtering techniques
    • Spam wars
    • Uncategorized
  • Archives

    • May 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • April 2009
  • Tags

    abusive templates America Online anti spam antispam Anti Spam Web BugNet Data Protection Data Protection Agency Digital ID e-mail e-mails email FTP gold spammers Groupware groupware system hacker Internet Internet Explorer Internet providers Internet service Internet Users Intranet Intranet bets pay off Intranets Rescue Reengineering junk mail LDAP LotRO macro Microsoft NDS NetBIOS Netscape Java Hole Netscape Navigator operating system QuitaSpam spam spammer spammers spam messages spyware Veriat Digital ID Water Windows 95 World of Warcraft
  •  

    February 2012
    M T W T F S S
    « May    
     12345
    6789101112
    13141516171819
    20212223242526
    272829  
  • Blogroll

    • Call Center
    • Direct Buy
    • free software download
    • Internet Security
    • joomla templates
    • Laser Hair Removal
    • ovulation calendar
    • Technical Schools
    • Word to PDF
    • zero emission vehicle
Categories
  • Anti-Comment Spam Tactics
  • Anti-spam appliances
  • Anti-spam techniques
  • Bug fixing
  • Bug Info
  • Comments
  • Digital Signature
  • Net Progress
  • News
  • Review
  • Spam Facts
  • Spam filtering techniques
  • Spam wars
  • Uncategorized

A Veriat Digital ID establishes your identity to others that you communicate with. Digital IDs contain a unique digital code which can be used to verify your digital signature or encrypt messages.Read more

Copyright © 2012 Real-time AntiSpam protection, automated and self-managed content filtering All Rights Reserved XHTML CSS