ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Attackers target Windows DNS flaw

Joris Evers CNET News.com

Published: 13 Apr 2007 09:13 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Cybercrooks are using a yet-to-be-patched security flaw in certain Windows versions to attack computers running the operating systems, Microsoft warned late on Thursday.

The attacks target Windows 2000 Server and Windows Server 2003 systems through a hole in the Domain Name System (DNS) service, Microsoft said in a security advisory. The attacks happen by sending rigged data to the service, which by design is meant to help map text-based internet addresses to numeric internet protocol (IP) addresses.

"An anonymous attacker could try to exploit the vulnerability by sending a specially crafted RPC packet to an affected system," Microsoft said in the advisory. RPC (Remote Procedure Call) is a protocol that applications use to request services from programs on another computer in a network. RPC has been involved in several security bugs before, including in the vulnerability that let the Blaster worm spread.

The French Security Incident Response Team deems the Windows DNS vulnerability "critical", its highest rating.

The DNS and RPC warning comes days after Microsoft issued its April security patches. At the same time security experts have issued warnings on multiple zero-day flaws in Office and another one in Windows.

The latest vulnerability is a stack-based buffer overrun, Microsoft said. This is a common type of coding problem that has caused many headaches for Microsoft and Windows users. A successful attack will give full control over a vulnerable machine without any user interaction, Microsoft said.

There are "limited attacks" that exploit the issue, Microsoft said. The software maker is finishing a security update for Windows to repair the problem, it said. Microsoft did not say when it plans to release the update. The company's next "Patch Tuesday" is on 8 May, although if attacks increase a patch could be released out of that cycle.

While it works on the fix, Microsoft suggests several workarounds for users of affected Windows versions. These include disabling remote management over RPC capability for DNS servers, blocking specific data ports using a firewall and enabling advanced filtering. Security firm Symantec on Thursday urged users to apply the workarounds.

"Customers are advised to… apply the appropriate workarounds as soon as possible, in the event that the attacks become more widespread," Symantec said in an alert sent to subscribers of its DeepSight security intelligence service.

Windows XP and Windows Vista are not impacted by the DNS flaw. Windows 2000 Server Service Pack 4, Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 are vulnerable, Microsoft said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
15 out of 16 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Windows engineer Investment banking city based

Directory infrastructures involving tens of thousands of users, covering multiple domains and business units.knowledge of DNS, Kerberos, LDAP and ...

Senior Systems Support Analyst - Southampton

You will also be developing and supporting major infrastructure services such as Portal, Email, VLE, directory services, proxy, DNS, DHCP and ...

Senior 2nd Line Support Engineer Manchester 26,000

Networks: LAN / WAN / VPN / SSL environments Support: Domain Management / Active Directory / Group polices / DHCP & DNS Security: Firewalls / AV We ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Biometric devices. Do you need one?

When saying “biometrics” I am not thinking about law enforcement, AFIS systems, national ID and visa projects. I first think about personal solutions that will make my life easier.... More

1 comment

Barracuda launches counter-suit agains...

Court cases are never pleasant or simple. The ongoing battle between security companies Trend Micro and Barracuda Networks took a new twist on Wednesday, when Barracuda launched a counter-suit... More

Post a comment

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment