WindowsXP DoS
WindowsXP DoS
" Steve,
I've reviewed your note with the Windows network
development architects, as well as our Corporate IT Security
and Security Response groups. Your instincts are correct --
they thoroughly understood the nature of the issue . . ."
— A Microsoft Executive
With all due respect to Microsoft, I believe that either the right
people within the organization are not yet fully aware of this issue,
or that they have not really "thoroughly understood the nature of
the issue."
Microsoft has a lot of really smart people — from Bill Gates and Steve Ballmer
right on down the line. But they are human, and they sometimes make human
mistakes. Sometimes it's worse than that, and as a company they're stubborn in
the face of some really bad decisions. Like script-enabling their eMail clients so
the virus du jour, like Melissa, can impersonate the user and happily eMail itself
across the Internet to everyone in our address books.
What a DUMB thing.
This time, with the disaster of Windows XP support for "RAW SOCKETS" looming,
there is still time to get Microsoft to yank it out. But as the correspondence
below demonstrates, I have not yet managed to reach the right people or
convince them that they must. I need YOUR help!
Smooth and orderly traffic flow across the Internet requires machines to inform
each other of various non-data events such as closed ports, network congestion,
unreachable IP addresses, etc. The ICMP (Internet Control Message Protocol) was
created to fill this need.
[Link] 11.06.2001
Denial of Service with Windows XP Seite 3 von 18
ICMP, and other, message traffic. As shown in the diagram above, the Berkeley
Sockets system provides this power through the use of a so-called "Raw Socket".
A Raw Socket short-circuits the TCP/IP stack to open a "backdoor" directly into
the underlying network data transport.
Beyond their use for supporting simple "ping" and "traceroute" commands, the
original Berkeley designers intended Raw Sockets to be used for Internet
protocol research purposes only. Because they fully appreciated the inherent
danger of abuse of Raw Sockets, they deliberately denied Raw Socket access to
any applications not running with maximum Unix "root" privileges. User-level
applications were thus prevented from accessing and potentially abusing the Raw
Sockets capability. (See asterisk '*' in diagram above.)
[Link] 11.06.2001
Denial of Service with Windows XP Seite 4 von 18
As proven by the success of the Windows NT server platform (lacking full Raw
Sockets support) and the successes of the Internet-connected Windows
95/98/ME platforms (also lacking full Raw Sockets), full Raw Socket support is
absolutely unnecessary for the use of ANY benign Internet applications.
Extensions to the Internet protocols, which represent a valid use for Raw
Sockets, would be performed within the operating system's network core.
"Sockets" are an application-level interface, not a system level resource, and
applications have no valid need for full Raw Sockets. None.
In other words, what Microsoft has done with Windows 2000 and Windows XP, is
to add a number of powerful and completely unnecessary networking features
because, they say, "some people complained about Windows lack of full Raw
Socket support". However, it will ONLY be Internet hostile and malicious code
that needs and uses the advanced "direct access" provided by Windows' new full
Raw Socket support.
Until the advent of Windows 2000 & XP, the familiar, complex, potent, and
untraceable Denial of Service and Distributed Denial of Service attacks have
only been generated from Unix-family operating systems. Due to the sheer
volume of Windows XP machines soon to be loose in the world, Unix systems will
quickly be supplanted as the premiere launching pad for new torrents of Denial of
Service floods. This will have an unfortunate corollary effect for XP users:
[Link] 11.06.2001
Denial of Service with Windows XP Seite 5 von 18
Hi Greg,
I'm writing to you first for some navigational direction. Windows 2000 and the
forthcoming new MS platforms offer something never before seen in any
Microsoft platform: A complete implementation of the Windows sockets RAW
SOCKETS specification.
Before now, the many tens of thousands of Trojans and Zombies being
installed into insecure Windows boxes across the Internet on high-bandwidth
connections have been COMPLETELY UNABLE to spoof their source IP's. This
has been a blessing, since, until now, only UNIX derived boxes have had
complete RAW_SOCK support.
But with Windows 2000, and WinXP, etc. ... Windows applications will be able
to forge their "return address" -- which spells catastrophe for the integrity of
the Internet.
I would appreciate having you forward this note to whomever should receive
it. I need to understand Microsoft's formal position on this before I go off and
make a big bunch of noise and draw the world's attention to this impending
threat to the operation and security of the global Internet.
Oh! ... and while I've been intending to mention this danger for some time, I
stumbled upon a chunk of hacker source code a few days ago that frightened
me a lot:
[Link] 11.06.2001
Denial of Service with Windows XP Seite 6 von 18
>-------------------------------------------------------------
>
> 6. Some words about DDoS from Windows OS.
> The new feature IP_HDRINCL that comes with win2k can make
> windows to a powerful DDoS server because it enables IP-
> spoofing!
>
> THE IP_HDRINCL
> setsockopt(ssock, IPPROTO_IP, IP_HDRINCL, (char *)&bOpt,
> sizeof(bOpt));
>
> That means win2k-servers can become a base for DDoS that
> is equal to Unix servers.
>
>------------------------------------------------------------
I sincerely hope that you and Microsoft will sufficiently appreciate the
significance of this problem, and the danger it represents.
Please keep me in the cc-chain and let me know what, if anything, transpires.
Greg was terrific about following up. I received a few progress reports as my note
went through "channels". Then a couple of days later I received the following
complete reply:
Steve,
I've reviewed your note with the Windows network development architects, as
well as our Corporate IT Security and Security Response groups. Your
instincts are correct -- they thoroughly understood the nature of the issue ... I
guess the response is sort of "good news, bad news" story, depending on your
point-of-view. In a nutshell, it will be very much harder to get hostile code
running on a Windows XP system than on a Windows 9x, or even a Windows
2000 system ... but a determined hacker still can ... If you'd like to speak to
someone about the issue in more detail, I'd be happy to arrange.
Your concern is the ease of spoofing the IP address under which a Windows
2000 or Windows XP system operates on the Internet. You believe that our
providing a raw sockets option will make it much easier for malicious parties
to develop zombie code that is capable of operating with a spoofed source
address.
Windows 9x and NT systems have for some time offered the capability to
send raw packets from the NDIS layer. This capability is just as exploitable for
[Link] 11.06.2001
Denial of Service with Windows XP Seite 7 von 18
The real issue here is more the ability to get control of the zombie system
than the ease of writing the zombie code that exploits it. If I can get code
running on a system, it's pretty much guaranteed that I can write code to
exploit it. The issue is only one of how much code I have to load onto the
zombie and how hard it is to get it right (neither a trivial issue, but neither a
showstopper for the hacker).
In summary, our security folks believe that it will be significantly harder to get
an army of zombies running on XP systems than has been the case today with
Windows 9x. Unfortunately, even if we prohibited sock_raw, determined
hackers can go around that restriction ...
Finally, as to the actual "why are providing a raw sockets option" ? , I'm told
it's less about "need", and more a response to customer demand for Winsock
standard compliance.
As I said, please let me know if you'd like to speak with someone about this.
And if you think we are absolutely nuts, then I really would like to know about
that, too. I can only assume that you will expose your point of view to your
readership on your web site, and if you think we are being insanely
irresponsible, then I'd rather hear it from you first, than read it on your site...
Greg
I will respond, in detail, to these points Microsoft has raised. But first I would like to
raise and respond to some of the other questions raised early in this controversy . . .
[Link] 11.06.2001
Denial of Service with Windows XP Seite 8 von 18
[...] Even with all the tests above, nmap is unable to distinguish between
the TCP stacks of Win95, WinNT, or Win98. This is rather surprising,
especially since Win98 came out about 4 years after Win95. You would
think they would have bothered to improve the stack in some way (like
supporting more TCP options) and so we would be able to detect the
change and distinguish the operating systems. Unfortunately, this is not
the case. The NT stack is apparently the same crappy stack they put into
'95. And they didn't bother to upgrade it for '98.
But do not give up hope, for there is a solution. You can simply start with
early Windows DOS attacks (Ping of Death, Winnuke, etc) and move up a
little further to attacks such as Teardrop and Land. After each attack, ping
them to see whether they have crashed. When you finally crash them, you
will likely have narrowed what they are running down to one service pack
or hotfix.
I have not added this functionality to nmap, although I must admit it is
very tempting :).
If you read though Fyodor's fingerprinting description, you will see that nmap is a
superlatively sensitive detection tool that can generally sense even the tiniest changes
in the implementation of a system's TCP/IP stack. Yet Microsoft's stack apparently
never changed . . . until it suddenly changed significantly.
An intriguing rumor is that Microsoft lifted the source code for their now advanced
TCP/IP stack directly from version 4 of the FreeBSD operating system project.
Although I've heard this from several different sources, I have not confirmed it one
way or the other. But if true, it might be germane within the context of this
controversy: Perhaps Microsoft just doesn't know how to turn off the full Raw Sockets
support, even if they wanted to.
In any event, several people have been quoted in the press defending Microsoft's
stance by simply stating that "following standards is a good thing".
I agree that following good and safe standards can be a good thing. But it seems to
me that blindly following a standard for its own sake, just because someone said it
was "standard", and lacking an understanding and independent evaluation of that
standard's merit in the intended application, is tantamount to replacing your own
judgement with someone else's. I would disagree that, for a well-informed person,
doing that is always a good thing.
It must also be that these people have never actually programmed the Windows
Sockets system (as I have extensively). Because there is very little about Microsoft's
Sockets — with their wild extensions (which I love by the way) — that in any way
follows any "standard". So the truth is, that either with or without full Raw Socket
support, Windows Sockets never has been, and never can be, "standard" in any way,
shape, or form.
These people miss the essential aspect of "scale". If Microsoft were going to sell only a
few thousand copies of Windows XP, I would not be wasting either your time or mine
[Link] 11.06.2001
Denial of Service with Windows XP Seite 9 von 18
with this entire issue. But whereas Windows 98 and Windows ME have been largely
uninteresting upgrades, Microsoft has loaded so many new goodies into WinXP that it
will make for a compelling Christmas season.
Therefore, my concern is with the DEFAULT feature-set of the system and with the
probable size of that feature-set's installed base. Sure, I wish that Windows 2000 were
also "Raw Sockets Neutered" so that malicious hackers could not assume that all
Windows 2000 machines were exploitable. I have no problem with the idea of an after-
market add-on download pack from Microsoft, or of making the "deluxe stack"
available in a Windows XP resource kit or MSDN subscription.
Microsoft Reacts
After the May 31st release of my widely read DDoS attack report, in which I was
strongly critical of Microsoft's publicly stated and confirmed intentions to equip the
consumer-targeted Windows XP with full Raw Sockets capabilities, Microsoft produced
and publicized a formal response on their TechNet web site. You should take a look at
that so that you have an updated sense for Microsoft's position:
[Link]
I will summarize what I read as Microsoft's stated position, point-by-point, and reply
to each in turn:
Microsoft's Position:
HUH?!!
This is a very disappointing position for Microsoft to be taking. Within the present
context, they MUST KNOW that this is simply not the truth. The entire debate centers
upon the distinction between partial and full Raw Socket support. So I can only
presume that Microsoft is hoping to achieve some quick public relations damage-
control, even at the ultimately extreme cost of sacrificing the truth.
[Link] 11.06.2001
Denial of Service with Windows XP Seite 10 von 18
Here are three pieces of concrete evidence demonstrating that Microsoft is apparently
losing its grip on reality in their desperate need to discredit my position in this matter:
Proof #1:
My original note to Microsoft quoted from the "readme" file of a Windows DDoS
attack tool named Skydance v3.03:
"The new feature IP_HDRINCL that comes with win2k can make windows into a
powerful DDoS server because it enables IP-spoofing!" ...and...
"That means win2k-servers can become a base for DDoS that is equal to Unix
servers."
Also appearing on that readme page under the section "Client Usage", is the
following:
"The Client will try to use a spoofed source address. You should test your
spoofing-ability first to ensure that you can not be revealed. The test will fail on
WinNT and Win9x/Me systems. It should not fail under Win2000."
How much more plain can that be? Windows 9x/ME and WinNT DO NOT HAVE
the Raw Socket capability to spoof the machine's actual IP address. This was
only added into Windows 2000 and is now being carried down into the consumer
market by Windows XP.
Here, located on the "megasecurity" hacker site (provided with their knowledge
and permission), is the entire "readme" page for this typical Windows DDoS
attack tool. Note that it is not currently useable on any consumer-grade Windows
systems . . . but Microsoft's XP will soon be changing that, to the delight of
malicious hackers everywhere:
[Link]
I got a personal chuckle out of the last paragraph on that page. It talks about
the trouble with the new personal firewalls and suggests that by renaming the
DDoS Trojan to the name of a common Internet application (like "[Link]")
— which presumably has firewall permissions — you may be able to get past
outbound blocking firewalls by "impersonating" a permitted application.
Those of you who have been following my work at [Link] will note that this
was exactly the personal security problem I anticipated when I created and
promoted my free LeakTest utility. Its goal was to bring market pressures to
bear, thereby inducing firewall vendors to prevent this trivial exploit. At the
time of LeakTest's release, all but one firewall was vulnerable to this. But
today, every reputable firewall has been updated as a direct consequence of
LeakTest's influence.
As you might imagine, the personal firewall vendors were as furious with me
then, as Microsoft appears to be now. But those vendors are happy today,
and their users are much safer.
(So as not to confuse people, I should mention that BlackICE defender still
fails the LeakTest, and would therefore presumably allow this Trojan to
operate. However, Network ICE has stated that, despite the declarations on
their web site, BlackICE is not a firewall. So it is exempt from the class of
products I refer to as "reputable firewalls".)
While you're at the megasecurity site, take just a moment to browse through
their catalog of the Trojans which will soon be competing for space on Windows
XP hard drives:
[Link]
[Link] 11.06.2001
Denial of Service with Windows XP Seite 11 von 18
Right.
This author is describing a classic SYN flooding attack using a spoofed Source IP.
NO PRIOR VERSION OF WINDOWS allows its applications to arbitrarily generate
Internet packets. As this example demonstrates, deliberately invalid — and
malicious — SYN packets can NOT be generated unless the application is running
on Windows 2000 . . . or, soon, Windows XP.
The typical teenage hacker has not had access to Windows 2000. He or she has
been limited to playing video games on Windows 95/98/ME. But this Christmas
will change all that: When "Junior" asks Mom and Dad if he can get an upgrade
to the new really cool Microsoft Windows XP for Christmas, Mom and Dad will
smile and nod. "What a GREAT idea!" they think to themselves.
Yeah. Great.
Proof #3:
One of the most well known and sophisticated remote control attack Zombies is
named: Trinoo. This remote control Bot was originally written to run on
compromised Unix- and Linux-style platforms which, as we all know by now,
have traditionally been unique in having the ability to generate spoofed source IP
flooding attacks.
Trinoo was such a successful attack tool over on the *NIX platforms, that it was
"ported" to the Windows environment under the name: WinTrinoo.
Next year, after "The XP Christmas of Death" has passed, tens of millions of
home PC's will be happily running Windows XP. How many minutes do you think
it will take for "WinTrinoo2" to arrive on the scene and for it to take full
advantage of XP's Unix-style full Raw Socket support?
[Link] 11.06.2001
Denial of Service with Windows XP Seite 12 von 18
Proof #3:
One of the most well known and sophisticated remote control attack Zombies is
named: Trinoo. This remote control Bot was originally written to run on
compromised Unix- and Linux-style platforms which, as we all know by now,
have traditionally been unique in having the ability to generate spoofed source IP
flooding attacks.
Trinoo was such a successful attack tool over on the *NIX platforms, that it was
"ported" to the Windows environment under the name: WinTrinoo.
Next year, after "The XP Christmas of Death" has passed, tens of millions of
home PC's will be happily running Windows XP. How many minutes do you think
it will take for "WinTrinoo2" to arrive on the scene and for it to take full
advantage of XP's Unix-style full Raw Socket support?
So now, in light of what you've just seen, reconsider the intent behind Microsoft's
summarized position, as documented above:
I hope it is clear to you, in light of this little bit of evidence (there's an endless amount
more), that the release of Windows XP, as currently planned, into the mass consumer
market, represents a crucial mistake. And given that Microsoft is fully aware of this, a
shocking example of corporate hubris.
NEXT
This quote is taken directly from Microsoft's TechNet page referenced above:
We have just examined the obfuscation that was apparently intended at the end
[Link] 11.06.2001
Denial of Service with Windows XP Seite 13 von 18
Perhaps Microsoft hasn't been reading about the rapid rise (explosion) in the
number of DDoS attacks which is already occurring. One must wonder how they
could be unaware of this since they have, themselves, been frequent targets of
those attacks. Furthermore, they must know, as I demonstrated above, that the
widespread availability of Linux and Unix, with their "system-level functions to
manipulate data packets" are clearly responsible and are a "critical factor" in
the number of DDoS attacks.
Assuming that this is what that quote was trying to say, it raises a good question
which is worth exploration:
As we have seen, it is indeed unfortunate that "everyone else" has full Raw
Socket support. The Internet has already been suffering the consequences. That
problem is certainly going to grow with time and needs to be dealt with as well.
The fact that Microsoft was not the first to make this crucial mistake on the
Internet in no way reduces their now-fully-informed responsibility to prevent
their deliberate compounding of the problem.
NEXT
[Link] 11.06.2001
Denial of Service with Windows XP Seite 14 von 18
Adding full Raw Socket support to the DEFAULT Windows XP consumer product
ABSOLUTELY GUARANTEES that, IN PRACTICE, the next-generation tools of mass
malicious exploitation will be far more powerful than any previously or currently
designed for the traditional Windows of today.
It's just that plain and simple. How could Microsoft NOT see that?
NEXT
Remember "Junior" whom we met awhile back when he asked his parents for a
Windows XP upgrade for Christmas? Let's take a look at what "Junior" is up to
after he returns to school from Christmas vacation . . .
[Link] 11.06.2001
Denial of Service with Windows XP Seite 15 von 18
If you imagine that this little story about "Junior" and his XP Gang is pure
Science-Fiction, you don't know teenagers. This is what Windows XP will be
making all too easily possible.
It is worth noting that since TCP "SYN" packets are extremely small (60 bytes)
compared with data-carrying packets (1500 bytes), many more SYN packets can
be sent per second than data packets. This gives a SYN flooding machine more
"packet potency" than one which is attempting to transfer valid data. The
consequence of this, is that a single SYN-flooding machine can completely
knock out any other machine connected at the same or lesser speed. Coupled
with Windows XP, and a breed of cyber-war toys like the still-hypothetical
"[Link]" described above, we can expect "one-on-one" cyber-battles
between individuals. If someone doesn't like what you've said or done, you're
easily blown off the Internet.
[Link] 11.06.2001
Denial of Service with Windows XP Seite 16 von 18
applications have ANY need for full Raw Socket support. No VALID use exists
outside of an Internet research setting. Raw Sockets were only included by the
original Berkeley designers for Internet protocol research. In a consumer
computer system, they will only be exploited for malicious purposes.
So, as we see, the "real issue" (to quote Microsoft) is NOT whether the attacker
can run hostile code on another user's computer. I submit that the "real issue" is
whether a personal computer can be much too easily programmed to generate
untraceable and maliciously damaging Internet traffic. Until now, for Windows,
that answer was no, and as a direct consequence it was never done.
"Microsoft Security"
It takes every last bit of strength I have, not to label those two words "The
Oxymoron that Keeps on Giving". I have tried on this page, often without
success, to keep to the facts, since my feelings are already well known. You don't
need to read them over and over again.
Ask any real security expert, like Bruce Schneier of Counterpane Internet
Security. They will tell you flat out that it's an impossible task to secure a
personal, consumer, computer. Why does Microsoft continually insist otherwise?
Because it is what people desperately want to hear, and desperately want to
believe. Well, it's not possible.
Microsoft's OWN software has NEVER been secure, and NEVER will be. Why?
Because with each generation of featurerama upgrade, it becomes more and
more complex, and less and less understandable. There can not possibly be
anyone left at Microsoft whose mind encompasses the entire system. They gave
that up with MS-DOS. Microsoft single-handedly created the eMail virus. Their
consumer operating systems — and the high-end server platforms — are a
security joke.
You MUST KNOW that not long after its release the world will begin finding huge
security holes in Windows XP. Oh sure, Microsoft will issue patches. Then the
users will be blamed for not installing them in a timely fashion. What's WRONG
with those damn users anyway?
And even if, against all logic and our wealth of experience, you're on the fence
with this question . . . WHAT IF they are wrong? There is just too much riding on
the issue of the security of this completely unproven new system.
[Link] 11.06.2001
Denial of Service with Windows XP Seite 17 von 18
How many people complain that the annoying "Comet Cursor" keeps getting
installed into their computer whenever they visit certain web sites? Guess what
folks, that's Comet Cursor's CODE being downloaded and run without your
knowledge or permission. What happens when a Windows XP user innocently
surfs to a site that was set up to take over those machines?
As any of you who run a personal firewall with "noisy logging" know, routine
scans for the PC Anywhere remote control utility are STILL occurring on the
Internet. Why? Because people installed PC Anywhere in their machines to give
them remote access across the Internet. The only problem was, a great many of
these people never bothered with a password. Thus, anyone could scan the
Internet to find a machine running the "PC Anywhere" Trojan and "own it". So
much for the "security" of that machine.
As you can see from these examples, the goal of an "absolutely" secure personal
computer for the masses is impossible to achieve. It's true that exercising
extreme care and caution can result in "a more secure PC". But that can only be
achieved in degree, never absolutely. For example, even Windows 95 could be
quite secure if the user were careful about its configuration and diligent about its
use. But the average consumer can not be expected to appreciate the subtle and
complex nuances of Internet security — especially when being stalked, tricked,
and seduced by malicious hackers. Typical consumer computer users will tend to
do insecure things. There's no practical means to prevent that, since that's what
they want to do.
Windows NT and 2000 are supposedly "secure" operating systems, yet malicious
Russian hackers have been breaking into those machines left and right, then
stealing consumer credit card data. Has anyone ever supported the contention
that WinNT and Win2000 are immune to viral infection? Has anyone ever
contended that? I've never heard any such thing because we all know it's
ridiculous.
We all know that no Windows system is inherently safe or secure. The truth is,
that can NEVER change due to the customer-base these systems have been built
to satisfy.
[Link] 11.06.2001
Denial of Service with Windows XP Seite 18 von 18
While Microsoft "spins" the reality of what happened with Windows XP — just as
they spun my initial concerns in their bogus response — they would find
somewhere else to place the blame. Let's NOT let it be our fault too.
Purchasing Info GRC Mail System To GRC's Home Tech Support Discussions
The contents of this page are Copyright (c) 2001 by Gibson Research Corporation.
SpinRite, ChromaZone, ShieldsUP, NanoProbe, the character 'Moe' (shown above),
and the slogan "It's MY Computer" are registered trademarks of Gibson Research
Corporation (GRC), Laguna Hills, CA, USA. GRC's web and customer privacy policy.
~~~
[Link] 11.06.2001