Advertisement
Promo

Security threats Toolkit

Weakness found in MS server shield

Stephen Shankland, CNET News.com CNet

Published: 18 Apr 2001 10:01 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A Microsoft Windows 2000 server software package can be crashed by sending it a comparatively simple request for a Web page, a security firm has discovered.

SecureXpert Labs reported the vulnerability in Microsoft's Internet Security and Accelerator (ISA) software, which is used to protect internal networks from outside attackers and to bridge internal networks with the public Internet.

Microsoft acknowledged the problem on Monday and issued a patch.

An attacker can take advantage of the vulnerability by sending the server a request to view a Web page with an unusually large address -- for example, one with the letter A repeated 3,000 times, SecureXpert Labs said. Sending such a request will prevent the ISA software from letting computers inside its network view outside Web pages or letting outside computers view internal pages.

While the vulnerability wouldn't permit an attacker to take over a company's server, it could be used to make a Web page inaccessible to the public, Microsoft said.

In the array of possible methods to attack a server, this type is very simple and easily launched.

Though analysts agree the newer Windows 2000 operating system is more secure than its predecessors, Microsoft still faces a host of security problems. For example, future versions of its Outlook email software will ban many file types in an effort to prevent the spread of viruses that can reproduce quickly because of tight integration between different Microsoft products.

The ISA software must be restarted to restore the service, but the server doesn't need to be rebooted, Microsoft said.

Take me to ZDNet Enterprise

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
19 out of 48 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters