Microsoft Windows NT/2000 NetBIOS名称冲突漏洞(MS00-047)

漏洞信息详情

Microsoft Windows NT/2000 NetBIOS名称冲突漏洞(MS00-047)

漏洞简介

Microsoft Windows NT/2000是微软发布的非常流行的操作系统。
Windows系统中实现了NetBIOS名称服务(NBNS)协议用作Windows Internet名称服务(WINS)。根据设计,NBNS允许网络对等端帮助管理名称冲突,但这个协议是个未认证的协议,可能会被欺骗。攻击者可以滥用名称冲突机制,导致其他机器认为其名称发生了冲突,这样机器就无法在网络中注册名称,或放弃已注册的名称。
远程攻击者可以通过向NetBIOS名称服务发送NetBIOS名称冲突消息导致拒绝服务。

漏洞公告

厂商补丁:
Microsoft
———
Microsoft已经为此发布了一个安全公告(MS00-047)以及相应补丁:

MS00-047:Patch Available for “NetBIOS Name Server Protocol Spoofing”

链接:http://www.microsoft.com/technet/security/bulletin/MS00-047.asp” target=”_blank”>
http://www.microsoft.com/technet/security/bulletin/MS00-047.asp

补丁下载:

Windows 2000:

http://www.microsoft.com/Downloads/Release.asp?ReleaseID=23370” target=”_blank”>
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=23370

Windows NT 4.0 Workstation, Server和Server, Enterprise Edition:

http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138” target=”_blank”>
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138

Windows NT 4.0 Server, Terminal Server Edition:

http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24516” target=”_blank”>
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24516

参考网址

来源: XF
名称: netbios-name-server-spoofing
链接:http://xforce.iss.net/static/5035.php

来源: BID
名称: 1514
链接:http://www.securityfocus.com/bid/1514

来源: MS
名称: MS00-047
链接:http://www.microsoft.com/technet/security/bulletin/MS00-047.asp

来源: BID
名称: 1515
链接:http://www.securityfocus.com/bid/1515

来源: NAI
名称: 20000727 Windows NetBIOS Name Conflicts
链接:http://www.nai.com/research/covert/advisories/044.asp

来源:NSFOCUS
名称:8265※8264
链接:http://www.nsfocus.net/vulndb/8265※8264

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享