Re: Windows 95/NT DoS

Alan Cox (alan@LXORGUK.UKUU.ORG.UK)
Sun, 11 May 1997 16:40:27 +0100

> Not sure why, but it only appears to work if the host is running
> netbios (port 139). Attacking another port ie, httpd (port 80) does not
> have any effect.

Guessing how the kernel implementation works under NT I'd suspect the kernel
services are providing call back functions and netbios forgot to supply
one for out of bounds data.

That also explains why telnet to NT boxes sort of always works (telnet uses
OOB data sometimes)