ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Windows VPN software allows attacks

Matthew Broersma ZDNet.co.uk

Published: 31 Oct 2002 15:18 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Windows 2000 and Windows XP servers can be attacked through the software ordinarily used to create secure connections to remote workers, Microsoft said on Wednesday.

A buffer overflow in the implementation of Point to Point Tunnelling Protocol (PPTP) in the two operating systems allows attackers to cause any Windows 2000 or Windows XP servers to crash.

Microsoft also warned of a bug in Windows 2000 that could allow an attacker to sabotage the system via a Trojan horse.

The PPTP bug, which received a "critical" rating from Microsoft, affects both servers and clients, but the client attack is more difficult to carry out. Microsoft said that attackers could feed specially-formed control data to the part of the PPTP software that connects and disconnects PPTP sessions, which would corrupt the system core memory, causing the system to fail. Any server that offers PPTP, or a workstation manually configured to offer PPTP, is affected.

PPTP client systems can also be attacked using the exploit, but only during an active session, Microsoft said.

The standard is used to create secure connections over insecure environments such as the Internet. These connections, known as virtual private networks (VPNs), are commonly used by remote workers to connect to the company's network. Windows 2000 Internet servers are most likely to be affected by the bug, Microsoft said. It does not affect Windows 98, Windows 98SE, Windows ME or Windows NTŪ 4.0.

Users and administrators are recommended to install a patch, found with the security bulletin on Microsoft's TechNet Web site.

The other bug affects Windows 2000 workstations and a select few Windows XP workstations, and allows a malicious user on a multi-user system to implant a Trojan horse that could be automatically executed by another unsuspecting user on the same machine. The Trojan horse would execute with the privileges of the user who executed it, allowing it to alter files, erase hard drives and the like.

The Trojan bug is possible because of the way Windows 2000 searches for programs to execute. In some cases, when a program is invoked, the operating system looks first in the system root directory (typically C:\), which is by default open to all users. If an attacker created a Trojan horse with the same name as a frequently-used program, the user could invoke the Trojan instead of the legitimate program.

This attack could most easily be carried out if, at log on, Windows was set up to automatically invoke certain programs, and the attacker knew the names of those programs. Otherwise, the attacker would have to convince another user to invoke a program using Windows' Start/Run menu.

Workstations that aren't shared would not be vulnerable, because the attacker must have privileges to log onto the machine. Servers are at no risk and Remote Terminal server sessions are also set up in such a way that the attack would not work.

There is no patch for this bug, but Microsoft recommends that system administrators review the permissions for the system root directory.

With the two new warnings, Microsoft has issued 64 alerts this year. Microsoft earlier this year launched a drive to make its software more secure.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
33 out of 93 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Linux Systems Administrator - Linux Windows XP, Network Connectivity

Linux Administrator - Linux Redhat Systems Administrator Windows XP, Network Connectivity, Backup, DR, Market Data (not essential Reuters / Icap). ...

3rd Line Support (Windows Server 2003, Windows XP, MS Exchange, AD)

I am looking for a 3rd Line Support Engineer for a contract role in Southampton, Hampshire. To be considered for this opportunity you must be able to ...

Support Analyst - 2nd line - Windows XP - ITIL - 175-200/day

Windows XP / Blackberry / ITIL / Excel / Poweerpoint / Asset Mgmt. Urgent requirement - 2nd line support role. The client are a global asset ...

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal