Share on Facebook Share on Twitter Email
Answers.com

WinNuke

 
Wikipedia: WinNuke

The term WinNuke refers to a remote denial-of-service attack (DoS) that affected the Microsoft Windows 95, Microsoft Windows NT and Microsoft Windows 3.1x computer operating systems. The exploit sent a string of OOB (out of band) data to the target computer on TCP port 139 (NetBIOS)[1], causing it to lock up and display a Blue Screen of Death. This did not damage or change the data on the computer's hard disk, but any unsaved data would be lost.

The so-called OOB simply means that the malicious TCP packet contained an Urgent Pointer (URG). The Urgent Pointer is a rarely used field in the TCP header, used to indicate that some of the data in the TCP stream should be processed quickly by the recipient. Affected operating systems didn't handle the Urgent Pointer field correctly.

A person under the screen-name "_eci" published his C source code for the exploit on June 7, 1997[citation needed]. With the source code being widely used and distributed, Microsoft was forced to create security patches, which were released a few weeks later. For a time, numerous flavors of this exploit appeared going by such names as fedup, gimp, killme, killwin, knewkem, liquidnuke, mnuke, muerte, nuke, nukeattack, nuker102, pnewq, project1, pstlince, simportnuke, sprite, sprite32, vconnect, vzmnuker, wingenocide, winnukeit, winnuker02, winnukev95, wnuke3269, wnuke4, and wnuke95.

A company called SemiSoft Solutions from New Zealand created a small program, called AntiNuke, that blocks WinNuke without having to install the official patch[2].

Years later, a second incarnation of WinNuke that uses another, similar exploit was found[3].

See also

References

  1. ^ http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-1999-0153 National Vulnerability Database (NVD) National Vulnerability Database (CVE-1999-0153)
  2. ^ http://robert.grefstad.com/win/error_winnuke.html
  3. ^ http://articles.techrepublic.com.com/5100-10878_11-1054537.html WinNuke lives on, and it's coming to a system near you

External links


Search unanswered questions...
Enter a question here...
Search: All sources Community Q&A Reference topics
 
 
Learn More
Nuke
Script kiddie
Internet Relay Chat flood

Post a question - any question - to the WikiAnswers community:

 

Copyrights:

Wikipedia. This article is licensed under the Creative Commons Attribution/Share-Alike License. It uses material from the Wikipedia article "WinNuke" Read more