Advertisement
Promo

Online business Toolkit

Microsoft discloses denial of service bugs

Will Knight ZDNet.co.uk

Published: 06 Mar 2001 15:44 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A flaw found in two major Microsoft business applications could allow a malicious computer hacker to crash a company's Web site or disable its email system.

The same bug is found in Microsoft's Internet Information Server (IIS) 5.0, which is used to power many commercial Web sites and in Exchange 2000, Microsoft's flagship corporate email product.

The bug means that a specially formulated message can be used to crash these applications and render them inoperative. Although Windows 2000 is designed to restart itself whenever a service is disrupted, it is possible using a target server's URL or IP address to design a script that will repeatedly send the same malicious URL request and cause the server to black out.

David Litchfield, a security expert with @Stake and an experienced bug finder in Microsoft products, said the flaw is not as significant as one that could allow a hacker to break into a computer network, but still merits an alert.

"You can't execute arbitrary code, which would be a problem," he said. "The worst you could do is a denial of service attack. It's worth getting patched though."

Another security expert said this problem is just waiting to be exploited. "There are undoubtedly crackers and security enthusiasts trying to recreate this problem," said Paul Rogers, network security analyst with MIS corporate defence solutions. "It is quite serious that you can [do this to] Windows 2000 machines, given the number of people using it."

Rogers also noted that this latest bug is just another in a long line of exploits affecting IIS. These have been used recently to deface a number of Web sites running the Web serving application, he said.

Denial of service (DOS) attacks, which involve bombarding a target, are a relatively simple method of causing disruption to an enemy. Earlier this year, the technique was used by a Romanian hacker to crash the Undernet Internet Relay Chat servers. Last year a technique for distributing a DoS attack between a number of unwitting hosts was used to bring down some of the Internet's biggest players, including Yahoo! and eBay.

Microsoft has issued a security bulletin about the problem along a fix for both IIS 5.0 here and one for Exchange 2000 here.

Take me to Hackers

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
33 out of 69 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:














Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters