ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

US Report: MS, Netscape scramble to fix security holes

Michael Moeller ZDNet.co.uk

Published: 29 Jul 1998 14:38 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Separate security loopholes recently uncovered in Windows NT and in Internet-based e-mail clients from Microsoft and Netscape Communications could provide hackers with access to users' computers and resources.

The Window NT loophole -- known as a "privilege elevation attack" -- is enabled via a program called sechole.exe, written by Prasdad Dabak, Sandeep Phadke and Milind Borate, a group of programmers based in India.

Posted to the Internet last week, the program enables non-administrative users who are logged on to the network locally to gain debug-level access on a system process. With such access, they are then able to run arbitrary code in the system security context and grant themselves local administrative privileges. The program does not work over a remote connection, thereby limiting attacks to users who have internal access privileges.

Microsoft posted a fix on Monday for Windows NT 4.0 Server and Workstation, both on X86 and Alpha platforms, on its Web site. A fix for Windows NT 4.0 Terminal Server Edition as well as fixes for 3.51 versions of NT will be posted "shortly," according to company officials. According to Dabak, the program also works on the beta version of NT 5.0. Microsoft officials were unavailable for comment about NT 5.0 On the e-mail front, researchers at Oulu University's Secure Programming Group in Finland have discovered a hole in Microsoft's and Netscape's (Nasdaq:NSCP) Internet-based mail applications through which malicious code can be launched. The breach affects users of Microsoft's Outlook Express 4.x and Outlook 98 as well as Netscape Mail Versions 4.05 and 4.5b1.

The malicious code needn't be contained in an e-mail attachment; rather, the tags that identify the attachment contain the code, according to Russ Cooper, owner and moderator of the NTBugtraq mailing list, which is dedicated to security breaches and bugs in NT and is operated out of Lindsay, Ontario. Outlook Express users and Outlook 98 users who are installed with an Internet Mail Only configuration or with an Internet Mail service in a corporate/workgroup configuration are at risk. They can be affected when malicious code is sent in a message and they highlight the name of an attachment, right mouse click on it and then move the mouse over the attachment, Cooper explained.

For Netscape Mail users, malicious code can be launched by simply highlighting the message -- without launching the attachment or opening the message -- and then accessing the File menu, Cooper said. "This is very dangerous. Any person sending you an e-mail could send a program and have it run on your computer. They could run code on your machine, and it would do anything you normally could do," said Cooper, who added that the code is not detected by a corporate firewall or gateway because "it's not abnormal ... it's not trying to do something that is not allowed by this protocol."

The solution: patches from Microsoft and Netscape.

A patch for Microsoft Outlook 98 is available here. The patch for Outlook Express is at here.

For Netscape Mail users, a fix will be included in Communicator Version 4.06, which is due on August 7, according to officials. In the interim, Cooper said, Netscape Mail users should be wary of messages with attachments from unknown users. He recommends that users delete such messages and close the program directly with the "X" button rather than exiting the program through the File menu.

The Microsoft and Netscape e-mail holes were discovered in June by researchers at the Finland university

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
47 out of 108 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



















Related Jobs

IT Support Engineer (Terminal Services 2003,Wins Server,AD,VMWare)

Successful candidates will be working in a Windows Server team, administering, installing and troubleshooting for Windows NT, 2000/2003 server ...

IMMEDIATE DESKTOP SUPPORT OPPORTUNITY WEST LONDON 25-30K

MS Administration, data Recovery and Antivirus Procedures, Telephony Systems, MS 2003 & NT, MS Active Directory 2000/2003 and MS Exchange messaging ...

Application Developer Middleware

Application Developer Middleware Job ID GBS-0162239 Job type Full-time Regular Work country United Kingdom Posted 09-Jun-2008 Work city - Any Job ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment