ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Network management Toolkit

VoIP holes remain open

Patrick Gray ZDNet Australia

Published: 16 Jan 2004 10:00 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft is still investigating which of its products are vulnerable to a bug in its implementation of the H.323 voice over IP (VoIP) standard.

While the company has patched its Internet Security and Acceleration server software against the glitch, it has conceded that users of the company's NetMeeting software are probably vulnerable to buffer overflow bugs found in implementations of the protocol that could allow a remote attacker to take control of affected systems.

Microsoft's security program manager at the company's security response centre, Stephen Toulouse, told ZDNet Australia that "it's hard to say" how many of its users are still using NetMeeting -- however, the company is currently looking at the software to assess its potential vulnerability to the H.323 bug.

"Because NetMeeting implements H.323, the likelihood is yes, it's vulnerable," he said by phone from the US.

NetMeeting, which still ships with Windows XP -- albeit without a short-cut to the program installed by default -- serves primarily as communication software that allows users to hold audio and video conferencing sessions over the Internet. However, some system administrators have been known to use NetMeeting's remote administration capabilities to manage and configure systems over networks.

"It has been supplanted by a number of technologies," Tolouse said. "[But] I'm sure there are people still out there using it... we'll do whatever we need to do to protect those customers."

The H.323 flaw has affected a large number of vendors. The security bug, which was found by researchers at the University of Oulu in Finland, was discovered in a widely replicated implementation of the H.323 protocol, which meant the bug was effectively replicated in most incarnations of the protocol.

"It's one of those cases where security researchers found a flaw in the implementation of a protocol, and then anyone who had picked up on it or was adhering to that protocol was impacted by it," Tolouse said.

When asked if the case was similar to that of the discovery of flaws in a commonly used SNMP implementation in March, 2002, which affected a seemingly endless list of vendors, Tolouse said the "cases aren't that dissimilar at all," and pointed out that the University of Oulu also found that bug.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
41 out of 109 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Business Analyst - London City EC1

Experience of formal testing methodologies - Use Cases and UML Modelling. We build close relationships with key Vendors which gives us access to ...

Backbone Network Engineer

Help design data centre installations and build-outs - Capacity planning - Troubleshoot a wide range of issues - Escalation point for network related ...

SOFTWARE ENGINEER (PERL)- Cambridge, South East

SOFTWARE ENGINEER (PERL)- Cambridge, South East The EBI is Europe's leading provider of information services to biological researchers in academia ...

Featured Talkback

Could it be that ISP’s are making this out to be a bigger problem than it actually is? We’re a small country with an internet penetration of less than 60%, for every Youtuber there’s someone who only uses the internet to check their emails, more people surf on their mobile handsets than a few years ago. Surely things should even themselves up.

By: harpless

Read full story:
Unlimited-broadband offers to go 'within a year'

On The Road Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Eee 1000 + iPhone 3G = the ultimate mo...

Having left the comforting bosom of ZDNet.co.uk to strike out on my own as a freelance journalist recently, I found myself contemplating a shocking truth – I was going to have to shell... More

Post a comment

Think Your Skype Call is Secure? Read...

There is growing, and credible, speculation that Skype has built in a back door to allow monitoring of SKype calls. Heise Online has a good article about it. So, what we have now... More

1 comment