ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Attack code raises risk for Windows

Joris Evers CNET News.com

Published: 17 Apr 2007 10:27 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The public release of computer code that exploits a yet-to-be-patched Windows security hole increases the possibility of widespread attacks, security experts have warned.

At least four exploits for the vulnerability in the Windows domain name system, or DNS, service were published on the internet over the weekend, Symantec said in an alert on Monday. In response, the company raised its ThreatCon to level 2, which means an increase in attacks is expected.

The security vulnerability affects Windows 2000 Server and Windows Server 2003. Microsoft last week warned that it had already heard of a "limited attack" exploiting the flaw. However, exploit code wasn't yet publicly available. Exploits may help miscreants craft malicious code that uses the vulnerability to compromise Windows systems.

Microsoft continues to work on a fix for the problem, and attacks are still limited, Christopher Budd, a Microsoft Security Response Center staffer, wrote on a corporate blog on Sunday.

"Attacks are still limited. We are aware though of public disclosure of proof-of-concept code to exploit the vulnerability," Budd wrote. Microsoft urges users of the vulnerable systems to apply the workarounds it has suggested.

McAfee on Monday afternoon said it had spotted a variant of Nirbot that appears to exploit the DNS vulnerability. Nirbot is a typical botworm that gives an attacker full control over an infected computer via an internet relay chat channel.

"An attacker can gain control over the compromised computer and use it to send spam, install adware or launch a DDos attack on internet systems," according to McAfee's description of the pest. There are multiple versions of the Nirbot family, which is also known as Rinbot.

The attacks on the DNS service happen when someone sends rigged data to it. The service is meant to help map text-based internet addresses to numeric internet protocol addresses. The vulnerability affects the DNS RPC interface. RPC, or remote procedure call, is a protocol used by applications to send requests across a network.

The vulnerability is not exploitable over the standard DNS ports TCP/UDP 53, according to Microsoft. The RPC interface is typically bound to network ports between 1024 and 5000, Symantec said. This mitigates the risk, according to the SANS Internet Storm Center, which tracks network threats.

"Networks obliging to basic secure perimeter design would only allow port 53 UDP/TCP to the authoritative DNS servers, and definitely not the additional RPC ports required for exploitation," a SANS ISC staffer wrote on the organisation's blog on Monday.

Still, the issue is significant, according to SANS ISC. Web hosting companies may run various network services on a single server, and active directory servers often also run DNS and may be exposed, according to the blog post.

The DNS flaw does not affect Windows XP or Windows Vista. Windows 2000 Server Service Pack 4, Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 are vulnerable, Microsoft said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
6 out of 10 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Enterprise Systems Support Engineers (Fixed term for 3 years)

Benefits: 28 days annual leave (increasing up to 40 days with continuous service) choice of defined benefits pension scheme or defined ...

VOIP TCP/IP ARP Systems Test Engineer

VOIP Test engineer needed for a 6-month contract in South-East. You will be expected to have a strong background in Voice over IP (VOIP)/IP ...

Junior Level Desktop Support (Grad, Win XP, AD, TCP/IP) HEDGE FUND

Windows 2000/XP, MS Office 2003, Printer maintenance, basic networking TCP/IP, understanding what a subnet gateway is, PC Hardware One of Europes Top ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment