73-997563179
Oct 21 2001, 11:06 PM
Windows NT 4.0 Server, Terminal Server Edition; Windows 2000 Server, Advanced Server, and Datacenter Server A remote user can send a specific series of RDP packets to cause the server to crash.
http://www.microsoft.com/technet....052.asp
73-997563179
Oct 21 2001, 11:17 PM
[UPDATE]
Due to unforeseen complications some customers experienced after applying this patch to protect against a denial of service (DoS) attack, Microsoft has temporarily recalled it.
The patch was designed to fix a hole in the RDP (Remote Data Protocol) implementation in the terminal service in Windows NT 4.0 and Windows 2000. RDP is a communication protocol used by Windows terminal servers and clients. By sending a particular series of data packets to an affected server, a malicious hacker could cause the server to fail, according to Microsoft's advisory
Rebooting the server after an attack will restore it to normal, but any work in progress at the time of the attack would be lost.
Microsoft received 34 calls from customers reporting that the patch caused Windows Terminal Services to stop functioning and in some cases it refused to let machines boot up to log on. Most people who reported problems were able to restore full functionality by simply uninstalling the patch. The patch will be available again shortly.