Advertisement
Promo

Industry watch Toolkit

Windows VPN software allows attacks

Matthew Broersma ZDNet.co.uk

Published: 31 Oct 2002 15:18 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Windows 2000 and Windows XP servers can be attacked through the software ordinarily used to create secure connections to remote workers, Microsoft said on Wednesday.

A buffer overflow in the implementation of Point to Point Tunnelling Protocol (PPTP) in the two operating systems allows attackers to cause any Windows 2000 or Windows XP servers to crash.

Microsoft also warned of a bug in Windows 2000 that could allow an attacker to sabotage the system via a Trojan horse.

The PPTP bug, which received a "critical" rating from Microsoft, affects both servers and clients, but the client attack is more difficult to carry out. Microsoft said that attackers could feed specially-formed control data to the part of the PPTP software that connects and disconnects PPTP sessions, which would corrupt the system core memory, causing the system to fail. Any server that offers PPTP, or a workstation manually configured to offer PPTP, is affected.

PPTP client systems can also be attacked using the exploit, but only during an active session, Microsoft said.

The standard is used to create secure connections over insecure environments such as the Internet. These connections, known as virtual private networks (VPNs), are commonly used by remote workers to connect to the company's network. Windows 2000 Internet servers are most likely to be affected by the bug, Microsoft said. It does not affect Windows 98, Windows 98SE, Windows ME or Windows NT® 4.0.

Users and administrators are recommended to install a patch, found with the security bulletin on Microsoft's TechNet Web site.

The other bug affects Windows 2000 workstations and a select few Windows XP workstations, and allows a malicious user on a multi-user system to implant a Trojan horse that could be automatically executed by another unsuspecting user on the same machine. The Trojan horse would execute with the privileges of the user who executed it, allowing it to alter files, erase hard drives and the like.

The Trojan bug is possible because of the way Windows 2000 searches for programs to execute. In some cases, when a program is invoked, the operating system looks first in the system root directory (typically C:\), which is by default open to all users. If an attacker created a Trojan horse with the same name as a frequently-used program, the user could invoke the Trojan instead of the legitimate program.

This attack could most easily be carried out if, at log on, Windows was set up to automatically invoke certain programs, and the attacker knew the names of those programs. Otherwise, the attacker would have to convince another user to invoke a program using Windows' Start/Run menu.

Workstations that aren't shared would not be vulnerable, because the attacker must have privileges to log onto the machine. Servers are at no risk and Remote Terminal server sessions are also set up in such a way that the attack would not work.

There is no patch for this bug, but Microsoft recommends that system administrators review the permissions for the system root directory.

With the two new warnings, Microsoft has issued 64 alerts this year. Microsoft earlier this year launched a drive to make its software more secure.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
33 out of 93 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Discussions

Fat Pop Do Wop Fat Pop Do Wop

How far will it all go?

Sunday 29 November 2009, 12:04 AM

3 comments
siarad siarad

Maybe, similarly,

Saturday 28 November 2009, 8:42 AM

3 comments
smpcs smpcs

Does 10x faster development dumb down...

Saturday 28 November 2009, 7:31 AM

28 comments
Video icon

Video

Featured Talkback

In association with Network Liberation Movement
When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters