Friday February 10, 2012 4:49 PM AEST

Windows 7, Vista vulnerable to BSOD attack

By Justin Robinson
10:46 Sep 9, 2009 | 7 Comments
Tags: Windows | 7 | Vista | vulnerable | security | BSOD | attack | SMB | SRV2.SYS
Windows 7, Vista vulnerable to BSOD attack

A faulty driver leaves the system wide open.

Operating systems are incredibly complicated bundles of code, so entangled around each other and manipulated to form some kind of working beast that it's a surprise they manage to work at all. With so many variables introduced by the many humans working on code under a strict deadline (and keeping in mind just how reliable humans are under pressure), there are frequent system-threatening errors.

The latest one, discovered by security researcher Laurent Gaffie, involves a driver called SRV2.SYS that is buried inside the networking stack of both operating systems. Its function is to allow printers and scanners be used remotely from other users on the network, but adding a simple ampersand (& for those who don't know) to the "Process Id High" field and sending it through the wide-open port 445, it causes the entire stack to crash and force a reboot.

While it's pretty amusing that a simple printer exception in the firewall can crash a system, it means that anyone who is wily enough to know what they're doing could crash your PC in the middle of pretty much anything. Gaffie recommends turning off the printing features until a patch is released, just in case. This bug affects both Windows 7 and Vista equally, while XP and earlier are not affected.

Head to the H Security to check out an explanation of how to use this naughty resetting bug.

 

 
 
Behind the scenes with Mass Effect 3! GTX 560 VGA round-up! Essential Skyrim tweaks to improve your game! Plus reviews, news, hardware, more games, and easy to following modding guides for PC builders. ON SALE NOW!
7 Comments
thesorehead
Sep 9, 2009 11:44 AM
lulz. I guess something like that is bound to happen. I wouldn't have expected that having the stack crash (whatever that means) would force a reboot. Also, wouldn't it only be activated if you have a network-shared printer?


*shrug* such is life.
SyKRyD
Sep 9, 2009 12:43 PM
can someone post up instructions? i would like to play a joke on enemi... uh, i mean, "colleagues", in my company. lol
Hoonbernator
Sep 9, 2009 1:17 PM
interesting that this affects Vista too... meaning it's been around for quite a while.

I'm with you SyKRyD, I want a little application to do this :)
N3M3SiS
Sep 9, 2009 4:16 PM
Woot, its WinNuke all over again! ;)

Those interested in "testing" follow the link at the end of the article.
.:Cyb3rGlitch:.
Sep 9, 2009 5:13 PM
*waits for patch Tuesday*
hazarama
Sep 9, 2009 9:50 PM
That is an awesome bug. Great post.
Xen
Sep 17, 2009 9:26 AM
it's strange to think that a couple of years ago security vulnerabilities like this would have been ignored for year (teardrop/ping of death..etc).

Now its found and the window to use the exploit is reduced to a week at the most.

Glad to see security is becoming more and more of a priority.
Comments have been disabled on this article.
 
Latest Competitions
 
Atomic Magazine

Issue: 133 | February, 2012

Atomic is a magazine aimed squarely at computer enthusiasts, gamers, and serious PC upgraders.

Every month we bring you the latest reviews of new technology and PC components, in depth features on everything from overclocking to console hacking, and gaming previews and interviews.
 
Latest Comments
 
Latest User Reviews
Battlefield 3 is the new benchmark online FPS
90%
A very fun and realistic multiplayer ride.
 
Antec Kuhler 920 - liquid cool
90%
Antec Kuhler 920 silent but effientive out of the box no maintence water cooling kit
 
Antec's Lanboy Air - our new favourite case
90%
Antec Lan boy Air in red a very cool design
 
Antec's Lanboy Air - our new favourite case
90%
This product overall is awesome.
 
MSI's GT780 laptop as fast as it gets
90%
Nice laptop
 
 
Close Get the February, 2012 issue of Atomic mailed to you for $8.95, including postage.

SubscribeBuy nowDigital Version