<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Real-time AntiSpam protection, automated and self-managed content filtering &#187; Pragma&#8217;s Telnet Server</title>
	<atom:link href="http://veriat.com/tag/pragmas-telnet-server/feed" rel="self" type="application/rss+xml" />
	<link>http://veriat.com</link>
	<description></description>
	<lastBuildDate>Thu, 27 May 2010 23:10:07 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Pragma Patches Telnet DoS Vulnerability</title>
		<link>http://veriat.com/pragma-patches-telnet-dos-vulnerability.html</link>
		<comments>http://veriat.com/pragma-patches-telnet-dos-vulnerability.html#comments</comments>
		<pubDate>Tue, 18 Aug 2009 10:46:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Net Progress]]></category>
		<category><![CDATA[BugNet]]></category>
		<category><![CDATA[Internet software]]></category>
		<category><![CDATA[Pragma Patches]]></category>
		<category><![CDATA[Pragma's Telnet Server]]></category>
		<category><![CDATA[REXEC daemon crashes]]></category>
		<category><![CDATA[Telnet and Remote Execution]]></category>
		<category><![CDATA[Telnet DoS]]></category>
		<category><![CDATA[TelnetD]]></category>
		<category><![CDATA[USSRBack]]></category>

		<guid isPermaLink="false">http://veriat.com/?p=311</guid>
		<description><![CDATA[Pragma Systems Inc., an Internet software products developer for the Windows platform, recently released a patch for their telnet server for Windows NT/2000. The fix eliminates a denial of service (DoS) vulnerability that could cause an application crash if one of two different scenarios is met. The bug, originally reported by the Underground Security Systems [...]]]></description>
			<content:encoded><![CDATA[<p>Pragma Systems Inc., an Internet software products developer for the Windows platform, recently released a patch for their telnet server for Windows NT/2000. The fix eliminates a denial of service (DoS) vulnerability that could cause an application crash if one of two different scenarios is met. The bug, originally reported by the Underground Security Systems Research organization (USSRBack), involves a buffer overflow memory problem in the remote execution daemon (rexecd.exe) in the Pragma Telnet Server. By hitting the server with a carefully constructed Internet packet, a malicious user could crash the Pragma telnet server requiring the server administrator to restart the telnet server application, or, in some situations, to reboot the system.?<span id="more-311"></span></p>
<p><strong>Telnet and Remote Execution </strong></p>
<p>Our testing revealed that the problem is a buffer overflow caused by a string manipulation with NULL characters. In other words, by introducing approximately 1000 null characters, the REXEC daemon crashes. Buffer overflows are typically caused a user trying to cram more data into a program buffer than the developer originally anticipated. Doing this can have varying effects. But in most cases the buffer overflow causes the vulnerable program to crash. At best, this bug is an inconvenience for the already-harried network administrator who would be required to restart the service. At worst, a buffer overflow could make the server crash, causing a loss of data and service.</p>
<p>In order for the vulnerability in Pragma&#8217;s Telnet Server to be exploited, a malicious user would establish a telnet session. After logging in, this user would then copy the offending code to the server. Once this happens, the next user to log in would kill the telnet server process.</p>
<p><strong>Historical Perspective</p>
<p></strong>The same problem was found in a previous incarnation of Pragma&#8217;s telnet server, TelnetD, build 4. In July 2000, this problem was corrected with the release of build 8. Pragma assures us that it has taken steps to prevent this problem from reoccurring in future releases.</p>
<p>It is refreshing when a company proactively notifies BugNet of a problem and how they are handling the situation. On September 1, 2000, Pragma notified BugNet of this DoS problem, which was found earlier that week. Since then, Pragma has been working on a patch that was release just days ago.</p>
<p>BugNet, with the help of KeyLabs, was able to validate the 6MB patch using sample exploiting code provided by USSRBack. The Telnet Server, build 2 upgrade is available to registered users. Contact Pragma if your system is affected.</p>
]]></content:encoded>
			<wfw:commentRss>http://veriat.com/pragma-patches-telnet-dos-vulnerability.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

