ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Microsoft investigates Exchange security hole

Matthew Broersma ZDNet.co.uk

Published: 24 Nov 2003 15:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft is investigating what may be a serious flaw in Exchange Server 2003, only a month after the software's launch as part of Office System 2003.

The bug appears to affect an Exchange component called Outlook Web Access (OWA), which allows users to access their inboxes and folders via a Web browser.

Users logging into their Web-based mailbox sometimes find themselves accessing another user's account, with full privileges, according to Matthew Johnson, a network administrator with a US company that sells tools for investors and fund managers. Johnson reported the bug earlier this month on the NTBugtraq security mailing list.

"This seems to be a major security flaw and we have had to shut off OWA indefinitely because of the issue," Johnson wrote.

Microsoft has said it is investigating the issue, and said the flaw appears to occur only when Kerberos authentication is disabled. Kerberos is the method, developed at the Massachusetts Institute of Technology, that Microsoft uses for authenticating requests for services. For the moment, the company is advising users to keep Kerberos authentication enabled -- as it is by default -- and may issue a patch or more information when its investigation is complete.

However, Johnson told ZDNet UK that Microsoft's initial analysis doesn't seem to be correct, since his company did not alter Exchange Server's default configuration, and thus should have been using Kerberos. He initially reported the bug to Microsoft two months ago, and said Microsoft is in the process of testing patches.

Microsoft did not respond to requests for additional comment.

Earlier editions of OWA have suffered their share of security problems. In 2001, Microsoft released a patch for the OWA feature in Exchange 5.5 and 2000, but the patch itself notoriously caused many servers to overload and hang, and was pulled offline; a second patch also contained a catastrophic bug.

Last week Aaron Greenspan, a Harvard University junior and president of consulting company Think Computer, published a white paper concluding that Exchange 5.5 and 2000 can be used by spammers to send anonymous email.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
53 out of 108 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Facebook Bans Firefox 3

Ok this is the issue. Because I dared to try and access facebook with firefox 3, and all the cookies disabled, it won't let me back on there with firefox ever again, even though... More

1 comment

GoDaddy suspends travel-getaways.com d...

I'm very pleased to say that GoDaddy has suspended the travel-getaways.com domain. I blogged in June that to my surprise I had found I was the site administrator for travel-getaways.com,... More

1 comment

Hello, I知 a PC. I知 a Handheld.

Hello, I知 a PC. I知 a Handheld. Author: Eric Everson, Founder MyMobiSafe.com I have said it before and I am sure I値l say it again, mobile devices are simply replacing computers.... More

Post a comment