Bugtraq mailing list archives

Ut oh..another port on NT4


From: luttgenj () KIC OR JP (Jason T. Luttgens)
Date: Sat, 25 Jan 1997 20:03:22 +0900


Ok...continuation of looking at NT4 server. I have SP2 installed and post-SP2 hotfixes...

Upon experimenting on port 65589 I found another way to get the CPU utilization to rise.
This time the kernel percentage rises with it. All you have to do is telnet to port 65589, type in
one character (it seems as though it must be a letter), and hit enter. You will be disconnected
from the host and it's CPU utilization will rise. How much it rises and affects the system seems
to highly depend on the setup. On a P75 with 32MB RAM, it's pegged at 100%. On a dual P133
with 64MB RAM, it averages at 65-70%. However, this only lasts approximately 5 minutes.
The processes eating up the CPU time were a combination of services.exe and dns.exe.
I have tested this multiple times and never did it last more than 5-6 minutes. One note, twice
NT Dr. Watson appeared and said an error occurred in application dns.exe and terminated it.
The dns.exe is MS's dns server that comes with NT4. Also, a few times the machines seemed
to really freak out. We tried to shut down the dual P133 once, and we got the login screen
back every time we tried. After multiple attempts and shutting it down it locked up, and we had
to hit the reset button. Again, the machine locking up only happened once....
As in my previous finding, I have no NT3.5 machines to try this on....

Microsoft, get to work again....another post-SP2 patch...and maybe more after I'm through..

Jason



Current thread: