Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Redmond's Salvation
Tim Mullen, 2004-08-11

Service Pack 2 for XP represents a sea change in Microsoft's security posture. Here's why you should ignore the naysayers and start planning your upgrade.

Comments Mode:
Redmond's Salvation? What? 2004-08-11
Dave (2 replies)
Redmonds Salvation? What? Think. 2004-08-14
FL Jim (1 replies)
Redmond's Salvation 2004-08-11
Anonymous (1 replies)
Redmond's Salvation 2004-08-12
Anonymous (1 replies)
Redmond's Salvation 2004-08-13
Rob Hughes (1 replies)
Redmond's Salvation 2004-08-15
Anonymous (1 replies)
Redmond's Salvation 2004-08-18
Hytham
Redmond's Salvation 2004-08-11
Anonymous (2 replies)
Redmond's Salvation 2004-08-12
Anonymous (1 replies)
Redmond's Salvation 2004-08-13
Anonymous
Redmond's Salvation 2004-08-13
Anonymous
Redmond's Salvation 2004-08-11
Texas Opinion (2 replies)
Redmonds Salvation 2004-08-14
FL Jim
Redmond's Salvation 2004-08-15
Anonymous
Redmond's Salvation 2004-08-11
Anonymous (1 replies)
Redmond's Salvation 2004-08-15
Anonymous
Redmond's Salvation 2004-08-11
Harsem
4 words for you! 2004-08-12
Anonymous (2 replies)
4 words for you! 2004-08-14
Anonymous
Another 4 words for you! 2004-08-17
Andy
NMAP? 2004-08-12
Anonymous (2 replies)
NMAP? 2004-08-16
Anonymous
NMAP? 2004-08-17
Hytham
Be careful, SP2 opens ports 2004-08-12
Anonymous (1 replies)
Be careful, SP2 opens ports 2004-08-12
Anonymous
Redmond's Salvation 2004-08-12
Anonymous (1 replies)
Why nobody is talking about this changes ?
With this hardcorded stuff it's not possible to use the system at full capacity.

Quote :

Two significant changes in Windows XP Service Pack 2 render the system
unusable by Windows network admins.

1) Outbound conection throttling. Windows XP Service Pack 2's
TCPIP.SYS throttles outbound connections.

When a minimum of ten threads are in the SYN_SENT state (which
includes for example ten unanswered ARP WHO HAS requests made on a
/24 segment when scanning a local LAN for rogue machines) TCPIP.SYS
queue's the remaining outbound connection attempts and sends a
warning to the System Event Log

EventID: 4226
Source: TCPIP
Message: TCP/IP has reached the security limit imposed
on the number of concurrent TCP connect attempts

2) Raw socket TCP data segments are filtered. Windows XP Service Pack
2's "Windows Fireall and Internet Conection Sharing (ICS)"
service filters attemts to send data using "Raw Sockets."
Stopping or disabling (net stop SharedAccess) the WF/ICS service
re-enables "Raw Sockets."

The WIN32 version of the circa 2000 "DoS via Stream3" tool
still sends packets with mangled flags and spoofed source addresses
on Windows XP Service Pack 2 (when WF/ICS service is stopped.)

Spoofed packets sent using
s = socket(AF_INET, SOCK_RAW, IPPROTO_RAW);
setsockopt(s, IPPROTO_IP, IP_HDRINCL, (char *)&Val, sizeof(Val);
are *not throttled* in TCPIP.sys

As a "Raw Socket" DDDoS platform, Windows XP Service Pack 2
remains viable for an attacker. Adding code to turn off the WF/ICS
service to four year old DoS code should bear fruit for malicious
coderz.

At the same time, Windows XP SP 2 remains utterly useless for remote
vulnerability scanning and remote assessments by admins.


[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/259/27904#27904
Redmond's Salvation 2004-08-13
Anonymous
Redmond's Salvation 2004-08-12
Peter
A better idea 2004-08-12
Aenox (1 replies)
Typewriters are vulnerable too! 2004-08-12
Anonymous (1 replies)
Typewriters are vulnerable too! 2004-08-17
Anonymous
Redmond's Salvation 2004-08-12
Frizzle
Redmond's Salvation 2004-08-12
Anonymous
Big Improvements..... yeah right 2004-08-12
Bug Me Not <sf@dodgeit.com> (1 replies)
Big Improvements..... yeah right 2004-08-12
Anonymous (2 replies)
Big Improvements..... yeah right 2004-08-12
Anonymous
Big Improvements..... yeah right 2004-08-14
Anonymous
Well and good, but... 2004-08-12
Penguinisto (1 replies)
Well and good, but... 2004-08-12
MaxeyPad
Redmond's Salvation 2004-08-12
Anonymous (1 replies)
Redmond&#39;s Salvation 2004-08-12
LinuxFire (1 replies)
Redmond&amp;#39;s Salvation 2004-08-19
Reynaldo Ruiz
Redmond's Salvation 2004-08-16
Anonymous
Redmond's Salvation 2004-08-16
m0rpheus
Redmond's Salvation 2004-08-19
Reynaldo Ruiz
Redmond's Salvation 2004-08-21
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus