Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: Cause of MS SSL DoS attack

Re: Cause of MS SSL DoS attack

From: David Barroso <dbarroso_at_s21sec.com>
Date: Tue, 29 Nov 2005 08:52:20 +0100

Hello SanjayR,
that's the reason for the DoS, MS does not check if the Cipher Suite
length is a valid value or not, crashing when looking for all the
non-existent ciphers.

Regards

On lun, 2005-11-28 at 17:58 +0530, SanjayR wrote:
> Hi All;
> I am trying to understand the main cause of DoS for MS SSL vulnerability
> (MS04-011, CAN-2004-0120). Everywhere, I get one information
> that specially malformed SSL messages can cause DoS, but what exactly is
> causing the DoS is not mentioned. After seeing the exploit code, I could
> see that normally, during SSL handshake, client sends available Cipher
> suites to server, which are around 30 (at most). therefore Cipher Suite
> length is at most 60 bytes (in general). but under this attack, i found it
> to be 39729!! there are many unknown types of cipher suites. Is this the
> cause of DoS? I shall be thankful for any information.
>
> -Sanjay
> .
>
>
Received on Nov 29 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos