ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Network management Toolkit

Microsoft silent over IP vulnerability claims

Dan Ilet ZDNet.co.uk

Published: 15 Apr 2005 16:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft has refused to comment over allegations that computers running its Windows operating system are affected by a serious vulnerability in one of the Internet's underlying technologies.

The UK's National Infrastructure Security Co-ordination Centre (NISCC) published details of this denial-of-service vulnerability earlier this week that affects some routers, firewalls and voice-over-IP (VoIP) phones.

The vulnerability is in the way ICMP error messages are handled would allow hackers to reset connections between computers and stop activity, such as VoIP conversations, from working.

Cisco, Juniper and IBM have admitted that the vulnerabilities exist in their equipment, but the security researcher who claimed to have found the flaws has now claimed that Microsoft is also affected.

"All (or most) versions of Microsoft Windows are vulnerable," wrote Fernando Gont. "Keep in mind this is an important item, as Microsoft has the largest installed base."

Microsoft declined to comment on Gont's allegations.

In an email to ZDNet UK, Gont added that Cisco "refused to cooperate with NISCC" over the vulnerability.

Cisco's router operating system IOS, PIX firewalls and some VoIP phones are affected by the vulnerability. The company said it has released a fix and rebutted Gont's claims.

"We've provided the fix and notified our customers," said a Cisco spokesman. "We know that Fernando Gont brought details of the vulnerability to the attention of NISCC. We have been working closely [with NISCC] to address the issue, but this vulnerability is not specific to Cisco."

Network company Juniper issued a statement claiming to have fixed the problem: "Juniper Networks has identified the issue and has provided a software fix. Customers with service contracts can log into the restricted area on our Web site."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
71 out of 139 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Security Consultant Ethical Hacking / Penetration Testing - London

Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...

Network Systems Engineer

Hands-on knowledge of configuration and maintenance of Cisco devices; routers in the 7200 family, Switches in the 6500+ range and Pix Firewalls - ...

Firewalls Engineer Lead

Extensive working knowledge of logical and physical Firewalls across Cisco Pix (95%), Nokia Checkpoint, and Borderware including Operating systems - ...

Featured Talkback

Could it be that ISP’s are making this out to be a bigger problem than it actually is? We’re a small country with an internet penetration of less than 60%, for every Youtuber there’s someone who only uses the internet to check their emails, more people surf on their mobile handsets than a few years ago. Surely things should even themselves up.

By: harpless

Read full story:
Unlimited-broadband offers to go 'within a year'

On The Road Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Eee 1000 + iPhone 3G = the ultimate mo...

Having left the comforting bosom of ZDNet.co.uk to strike out on my own as a freelance journalist recently, I found myself contemplating a shocking truth – I was going to have to shell... More

Post a comment

Think Your Skype Call is Secure? Read...

There is growing, and credible, speculation that Skype has built in a back door to allow monitoring of SKype calls. Heise Online has a good article about it. So, what we have now... More

Post a comment