ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Windows attack code released

Joris Evers CNET News.com

Published: 17 Nov 2006 10:29 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Computer code that exploits a "critical" Windows 2000 vulnerability has been released on the internet, increasing the likelihood of attacks, experts warned on Thursday.

The code takes advantage of a security hole in a key operating system component that routes file system and print requests called the "Workstation Service". On Windows 2000 systems, the flaw could be exploited via the net by an anonymous attacker without any user interaction, raising the possibility of the arrival of a Zotob-like worm.

"Somebody could write a piece of code that targets Windows 2000, and that replicates itself, and then you would have a worm go around the internet," said Monty IJzerman, senior manager in McAfee's Global Threat Group.

The public release of the exploit code comes only two days after Microsoft provided a fix for the flaw. That means that many vulnerable systems might still be unpatched. While Windows 2000 is an older operating system, it is still broadly used, primarily in businesses, said vulnerability management company Qualys.

"We scan about 10 million hosts every month, and at least 25 percent of those still run Windows 2000," said Amol Sarwate, a research manager at Qualys. Typically, it takes IT departments between five and eight days to apply a critical patch because of compatibility testing, he said.

Worm risk
Both McAfee and Qualys say a Zotob-like worm attack is probable. In August last year, Zotob slithered into Windows 2000 systems through a hole in the plug-and-play feature in the operating system. Zotob surfaced only days after Microsoft offered a fix for the "critical" bug as part of its monthly patching cycle.

Microsoft is aware of the "detailed exploit code" for the Workstation Service vulnerability, which was addressed by security bulletin MS06-070, a company representative said. The software maker is studying the code and plans to publish a security advisory to inform customers, the representative said.

The Workstation Service is a key part of Windows that can't be turned off or easily protected by a firewall, Sarwate noted. "Really, the only solution is to apply the patch as soon as possible," he said. Microsoft does offer some workarounds for the flaw in its security bulletin.

Also on Thursday, security vendor Immunity said it has created exploit code for two other Windows flaws. However, these blueprints are private, meaning they are supplied to users of its penetration-testing tool and are not publicly available.

The two flaws are covered by Microsoft alert MS06-066, which deals with issues that could put Windows 2000 and Windows XP systems at risk from worms. The bugs affect Microsoft's Client Service for NetWare and the NetWare Driver, which let Windows systems access network services on servers running Novell NetWare.

Microsoft also provided fixes for these vulnerabilities on Tuesday, its monthly patch release day. It rated the issues as "important" — one step below its most severe "critical" rating — because the vulnerable components are not installed by default.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
433 out of 515 people found this useful


Full Talkback thread

1 comment

  1. Risk of scaremongering robpow

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Applications Support, FIX, Tibco RV, SQL, Wombat, Equities

Applications Support, FIX, Tibco RV, SQL, Wombat, Equities A top Investment Bank requires a candidate with strong experience in Application Support ...

Infrastructure Engineer

Experience of Windows and some UNIX patch building Experience of dealing with security lockdowns Experience of configuration of Operating System ...

Hardware Break/Fix Engineer

ESG provides hardware support in the form of COTS Integration and Installation, and Break/Fix services to EDS Defence Projects based mainly in Hook. ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment