New York Web Design News July 16 2003, the latest breaking New York Web design news brought to you by,
Web Designs Now,Website Designs Now,New York Web Design Homepage,Web Design Services for New York, Connecticut, Long Island,New York Web Design Client Testimonials,Website Portfolio of New York Web Design, About this New York Web Design Firm,Contact this New York Web Design Firm

Critical Windows Flaw
Web Design & Technology News, July 16, 2003

NetSol's DNS Glitch
Netgear's $98M IPO
Overseas Outsourcing
Can Google Save AOL?
Google Refines News Search
Yahoo's New SiteBuilder
ISPs Fix Cisco Flaw
Critical Windows Flaw
Google's WMD Not Found
MS Secures Web Services
Overture Yahoo'd for $1.63B

A New Tech Order
Verity's Ultraseek Engine
Windows Flaw Remains
Yahoo's Q2 Revenues Soar
MS versus Google
Neighborhood Mini-ISPs
McDonald's McWeb
Overture vs Google in U.K.
e-Services to Change Business
Hacker Contest Weekend

More Web Design News:
2008 Current News
2008 June
2007 June
2007 May
2007 March
2006 November
2006 September
2006 August
2006 July
2006 June
2006 May
2006 April
2006 March
2006 February
2006 January
2005 December
2005 November
2005 October
2005 September
2005 August
2005 July
2005 June
2005 May
2005 April
2005 March
2005 February
2004 March
2004 February
2004 January
2003 December
2003 November
2003 October
2003 September
2003 August
2003 July
2003 June
2003 March - May



July 16, 2003

Windows users should expect to have another update from Microsoft waiting for them on their computers.
By Robert Lemos

The software giant issued a patch Wednesday morning to plug a critical security hole that could allow an attacker to take control of computers running any version of Windows except for Windows ME.

A group of Polish hackers and independent security consultants, known as the Last Stage of Delirium, discovered the flaw and worked with Microsoft to fix it.

"It should be emphasized that this vulnerability poses an enormous threat, and appropriate patches provided by Microsoft should be immediately applied," the group said in an advisory posted to its Web site. The group said that programs designed to exploit the vulnerability will likely be available on the Internet soon.

The flaw is in a component of the operating system that allows other computers to request the Windows system perform an action or service. The component, known as the remote procedure call (RPC) process, facilitates such activities such as sharing files and allowing others to use the computer's printer.

By sending too much data to the RPC process, an attacker can cause the system to grant full access to the system.

"This would give the attacker the ability to take any action on the server that they want," Microsoft stated in its advisory. "For example, an attacker could change Web pages, reformat the hard disk, or add new users to the local administrators group."

Jeff Jones, senior director for Microsoft's Trustworthy Computing effort, said that, in addition to applying the patch, users and systems administrator should close down any unused communications channels, or ports.

"Customers should protect their network with a firewall," he said. "Individual users should use the Internet Connection Firewall or some other personal firewall." The Internet Connection Firewall is a feature of Windows XP and Windows 2003 that limits the ways that a potential intruder could attack from the network.

Ports are standardized software addresses that allow applications to exchange data. Firewalls routinely prevent access to such services from the Internet by blocking the specific port used by a computer to offer those services.

Internet Security Systems, a network protection company based in Atlanta, warned its customers of the flaw on Wednesday. The company said in an advisory that it had raised its measure of the danger posed by threats on the Internet because of the vulnerability's seriousness.

Microsoft is well into the second year of its Trustworthy Computing initiative. Aimed at boosting customers' trust in the company's products, the initiative has been both praised as a bold move to become a leader in security and criticized as largely ineffectual.

Jones says the company is learning from its mistakes. In this case, Microsoft analyzed where the flaw crept in, and it developed plans to build in the expertise to detect it in the company's in-house development tools.

"It was primarily a process issue," he said. "We will be updating our automated scanning tool to make sure this type of issue is detected in the future."

Web Designs Now
Back to the Top


 © Copyright 2007, All rights reserved  |  Privacy Web Design Forums  |  Web Design News  |  Advertise  |  About Us  |  Contact Us  |  W3C HTML 
 Related Websites: New-York-WebDesign.com