[12195] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Win95/98 and Novell client DoS

daemon@ATHENA.MIT.EDU (Gyorgy Camaszotisz, Novell DevNet )
Sat Oct 9 15:13:44 1999

Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-Id:  <37FE85E8.441768C6@officenet.hu>
Date:         Sat, 9 Oct 1999 02:01:44 +0200
Reply-To: "Gyorgy Camaszotisz, Novell DevNet SysOp 13" <cama@OFFICENET.HU>
From: "Gyorgy Camaszotisz, Novell DevNet SysOp 13" <cama@OFFICENET.HU>
X-To:         BUGTRAQ@SECURITYFOCUS.COM
To: BUGTRAQ@SECURITYFOCUS.COM

Bruce,

> Novell client opens port 427 TCP.  My services file reports this port to be
> known as 'svrloc'.  You can bluescreen Win95/98 with Novell Client versions
> 3.0 and 3.0.1 by sending a SYN to this port, as you would with 'nmap -sS -p
> 427 <target>'.  This is quite fatal.  The only recovery seems to be a power
> reset.

Novell always recommends using the latest client versions, which is now
Novell Client v3.1 for Windows 95/98, plus Client Service Pack 2. See
the full TID here:

  Required Novell Client versions  (Last modified: 4 OCT 1999)
  http://support.novell.com/cgi-bin/search/tidfinder.cgi?2945422

Professional network administrators use the ZENworks product to upgrade
all clients to the latest version level at once. ZENworks Starter Pack
and the clients can be downloaded for free, so it can be done quite
easily, without purchasing any additional software or visiting every
workstation for manual updates.

I suggest you find a way to test the reported issue with the latest
client, and blame Novell only if it is still there.

Thanks,
Gyorgy

-----------------------------------------------------
   Gyorgy Camaszotisz, CNE
   Office-Net Kkt., Hungary
   Member of Novell DeveloperNet SysOp Team [#13]
-----------------------------------------------------
Niagara Mail Server [http://www.officenet.hu/niagara]

home help back first fref pref prev next nref lref last post