ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Microsoft discloses denial of service bugs

Will Knight ZDNet.co.uk

Published: 06 Mar 2001 15:44 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A flaw found in two major Microsoft business applications could allow a malicious computer hacker to crash a company's Web site or disable its email system.

The same bug is found in Microsoft's Internet Information Server (IIS) 5.0, which is used to power many commercial Web sites and in Exchange 2000, Microsoft's flagship corporate email product.

The bug means that a specially formulated message can be used to crash these applications and render them inoperative. Although Windows 2000 is designed to restart itself whenever a service is disrupted, it is possible using a target server's URL or IP address to design a script that will repeatedly send the same malicious URL request and cause the server to black out.

David Litchfield, a security expert with @Stake and an experienced bug finder in Microsoft products, said the flaw is not as significant as one that could allow a hacker to break into a computer network, but still merits an alert.

"You can't execute arbitrary code, which would be a problem," he said. "The worst you could do is a denial of service attack. It's worth getting patched though."

Another security expert said this problem is just waiting to be exploited. "There are undoubtedly crackers and security enthusiasts trying to recreate this problem," said Paul Rogers, network security analyst with MIS corporate defence solutions. "It is quite serious that you can [do this to] Windows 2000 machines, given the number of people using it."

Rogers also noted that this latest bug is just another in a long line of exploits affecting IIS. These have been used recently to deface a number of Web sites running the Web serving application, he said.

Denial of service (DOS) attacks, which involve bombarding a target, are a relatively simple method of causing disruption to an enemy. Earlier this year, the technique was used by a Romanian hacker to crash the Undernet Internet Relay Chat servers. Last year a technique for distributing a DoS attack between a number of unwitting hosts was used to bring down some of the Internet's biggest players, including Yahoo! and eBay.

Microsoft has issued a security bulletin about the problem along a fix for both IIS 5.0 here and one for Exchange 2000 here.

Take me to Hackers

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
33 out of 69 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:














Related Jobs

Sharepoint Expert Required - Development Lead - Contract - Tier 1 Bank

One of the world's leading international investment banks is currently looking to hire a Sharepoint development expert on a contract basis. They ...

Expert Java Developer - Front Office - Greenfield - 700

My top-tier investment bank client is looking for an expert Java Developer to work within a Front Office derivatives team on a Greenfield project ...

SAP Manufacturing Expert required - cambridgeshire - 50,000!

A Blue Chip Manufacturing organisation based in the Cambridgeshire area are urgently seeking an SAP Manufacturing expert with in depth experience of ...

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains