Datamation Logo

Microsoft’s Telnet Server Vulnerable to DoS Attack

February 12, 2002
Datamation content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More .

Two Microsoft products, the Telnet service in Windows 2000, and the Telnet daemon (telnetd) in Interix 2.2, have an unchecked buffer in their code, thereby providing a buffer-overflow vulnerability that could allow a hacker to ‘own’ those servers.

By sending a malformed request to such a server, an attacker could cause it to fail, and / or leave it in a state where the attacker could run code of their own choice, including Distributed Denial of Service (DDoS) attacks.

A compromised system would allow code to be run in the same context as the Telnet services. In the case of Windows 2000, the code would execute within the SYSTEM context, thus would allowing the attacker to execute commands with the same privileges as the operating system. This means the code could take any action, including reformatting the hard drive, spawning a remote command shell with SYSTEM privileges, installing programs, or shutting down the system.

Even so, the severity of this vulnerability is only moderate, assuming that firewalls are in place. While Telnet services are installed by default, they do not run by default, and have to be invoked.

Microsoft has issued patches which will check the buffer in question. They are available at www.microsoft.com/windows2000/downloads/security/q307298/default.asp for Windows 2000 and www.microsoft.com/downloads/release.asp?ReleaseID=35969 for Interix. In addition, the fix for Win2K is included within Windows 2000 Security Roll-up Package 1.

This story was first published on CrossNodes, an internet.com site.

  SEE ALL
ARTICLES
 

Subscribe to Data Insider

Learn the latest news and best practices about data science, big data analytics, artificial intelligence, data security, and more.

Datamation Logo

Datamation is the leading industry resource for B2B data professionals and technology buyers. Datamation's focus is on providing insight into the latest trends and innovation in AI, data security, big data, and more, along with in-depth product recommendations and comparisons. More than 1.7M users gain insight and guidance from Datamation every year.

Advertisers

Advertise with TechnologyAdvice on Datamation and our other data and technology-focused platforms.

Advertise with Us

Our Brands


Privacy Policy Terms & Conditions About Contact Advertise California - Do Not Sell My Information

Property of TechnologyAdvice.
© 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.