The Wayback Machine - https://web.archive.org/web/20000621042153/http://www.microsoft.com:80/security/bulletins/netdos.asp
  All Products  |   Support  |   Search  |   microsoft.com Guide  
 Security Home  |   New Headlines  |   Bulletins  |   Events & Training  |  
Headlines
New to Security?
Security Bulletins
    2000 Bulletins
    1999 Bulletins
    1998 Bulletins
    1997 Bulletins
Services
    Product Security Notification Service
    Mailing Lists
Products & Features
    Windows NT
    Certificate Server
    Exchange
    FrontPage
    Internet Explorer
    Internet Information Server
    Proxy Server
    SNA Server
    SQL Server
    Systems Management Server
Technologies
    Authenticode
    CryptoAPI
    Digital Certificates
    Kerberos
    SSL/TLS
    Server Gated Cryptography
    Smart Cards
    Virtual Private Networks
Government Issues
    Crypto Regulation
    C2 Evaluation
    E3/FC-2 Evaluation
    FIPS 140-1 Evaluation
Resources
    Books
    Case Studies
    Events
    Periodicals
    Seminars
    Slide Presentations
    Training
    White Papers
    Outside Resources
    Windows 2000 Walkthroughs
Contact Us
    Customer Support
    Send Us A Note
    Software Piracy
    Internet Hoaxes
    Alert Us


Microsoft Security Bulletin

Update on Network Denial of Service Attacks (Teardrop/NewTear/Bonk/Boink)

Posted March 3, 1998
Last Updated March 6, 1998

Since March 2, 1998, there have been numerous reports of malicious network-based, denial-of-service attacks launched against Internet-connected systems. We were notified of these attacks, which affected some Internet-connected Microsoft� Windows NT� and Windows� 95 systems, by customers and security alert organizations, including CIAC and CERT. This issue was also reported on the NTBUGTRAQ mailing list. Special thanks to Russ Cooper, the list moderator, for his assistance in this issue.

Based on analysis of data received from customers and alert groups, this is not a new issue. Systems that contain up-to-date patches were not vulnerable to this wave of attacks. This vulnerability exploited by this attack was addressed by a patch issued in early January. The attack is called by various names, including Teardrop2, NewTear, Bonk, Boink. These are all varied attacks that exploit the same vulnerability, which was addressed in the patch released in January.

For more information specifically on the NewTear/Bonk/Boink attack and the available updates for that vulnerability, please read our bulletin on that issue.

What Microsoft is Doing
Since the attacks began, we have worked with customers and security response organizations to obtain network traces of the attacks in action, as well as Windows NT memory dumps from affected machines. The network traces indicate an exploit that uses a fragmented UDP network packet to cause a failure similar to the NewTear/Bonk/Boink issue from early in January. None of the attacked machines from which we obtained memory dumps had the latest patches installed, and the memory dumps indicated a failure consistent with the NewTear/Bonk/Boink attack.

Additionally, replaying the network traces we obtained from attacked customers against patched systems had no effect, while these same traces replayed against an unpatched system caused it to crash. This was further evidence that the wide-spread attack since Monday was a NewTear/Bonk/Boink-type attack.

We will continue to work with customers who are affected by this issue, and with the security response organizations to ensure that there is no new issue here, and to ensure that all customers are aware of the security updates necessary to protect against these network denial of service attacks.

The following are some alerts have been posted by other alert organizations on this issue:

Additional information and discussion is available on a number of newsgroups, including the NTBUGTRAQ.

What Customers Should Do
Customers in large corporations, or campus-style networks should contact their network administrators if they are being attacked. Additionally, reporting these incidents to a response organization like CERT could assist in determining the scope of this attack. In some cases it is useful to work with your Internet Service Provider, or upstream Internet Service Provider to attempt to determine the source of an on-going attack. It might also be appropriate to notify law enforcement officials (see the end of this document for details).

Customers should evaluate their current environment to determine their exposure, and install all relevant security updates. Information about available updates is included in the following sections.

Windows NT 4.0
Customers should install Windows NT 4 Service Pack 3. The following post-SP3 hotfixes relating to possible denial of service attacks are also available. These patches can be installed in any order relevant to each other.

Note: There were earlier TCP/IP denial of service fixes for Windows NT (icmp-fix, oob-fix, land-fix) that are superceded by the ones listed above.

Windows 95
We have released a complete Winsock refresh for Windows 95 called the “Winsock 2 Update”. This update contains fixes for all known vulnerabilities in the Windows 95 TCP/IP stack. Customers concerned about TCP/IP security and denial of service issues on Windows 95 should install this update. This update works for all existing Windows 95 systems, and can be installed on top of systems that already have existing security updates installed.

The “Winsock 2 Update” update (approximately 192k) is available from http://www.microsoft.com/windows95/info/ws2.htm. This is a fully supported and regression tested update.

Note: There is a caveat on installing the dun 1.2b after installing this update, so please read the release notes before installing.

Windows 98 Release Candidate 0 (RC0)
This product contains all up-to-date TCP/IP fixes. Windows 98 RC0 is not vulnerable to this attack.

Notifying Law Enforcement of a Computer Crime
With the recent series of attacks on systems connected to the internet, many users have asked if there are laws against this and, if there are, what they have to do to get help. There are a number of laws at the state, local and federal level that may assist users that have been affected by these malicious computer attacks.

The first step is to contact your local law enforcement office with jurisdiction over computer related crimes. In most areas the local FBI office would be a good place to start. They would be able to help you decide what criminal activity, if any, might have taken place. Many FBI agents nationwide have had specialized computer training to handle this type of investigation. For more assistance you can contact FBI's CITAC Watch hotline at 202-324-6715.

� 1999 Microsoft Corporation. All rights reserved. Terms of Use.