Windows Server 2003 and XP SP2 LAND attack vulnerability

According to a segnalation by Dejan Levaja, seems that Windows Server 2003 and Windows XP SP2 (with Windows Firewall turned off)  are vulnerable to what is called a "LAND attack" (sending TCP packet with SYN flag set, source and destination IP address and source and destination port as of destination machine, results in 15-30 seconds DoS condition).

By creating malicious packets and sending a single LAND packet to file server causes Windows explorer freezing on all workstations currently connected to the server. CPU on server goes 100%.

I've mentioned the problem because nework managers must be alerted (set your Firewall to detect LAND attacks) and expecially because Microsoft was alerted some days ago and no response are given at the moment.

Print | posted on Sunday, March 06, 2005 8:50 PM

Comments on this post

No comments posted yet.

Your comment:

 (will show your gravatar)
 
Please add 1 and 1 and type the answer here: