New York Web Design News September 10 2003, the latest breaking New York Web design news brought to you by,
Web Designs Now,Website Designs Now,New York Web Design Homepage,Web Design Services for New York, Connecticut, Long Island,New York Web Design Client Testimonials,Website Portfolio of New York Web Design, About this New York Web Design Firm,Contact this New York Web Design Firm

More Holes in MSFT Windows
Web Design & Technology News, September 10, 2003

New Adobe Creative Suites
Google Ads Milestone
VeriSign Settles w/ FTC
OpenSSH Patches 2nd Flaw
Google's Local Search
Yahoo! Product-compare
VeriSign Defies ICANN
ICANN Responds to VeriSign
ISPs Limit Transfer Volume
Open-souce Security Flaws
VeriSign's SiteFinder Sued
DB2 Linux Security Flaw
MSFT Adopts Wi-Fi 802.11g

VeriSign's 404 Handling
Sun SW Intros@Confab
Symantec Security Servers
VCs Get More for Their $
Bright Outlook for HDDs
More Holes in MSFT Windows
New Macromedia Web Tools
IE Patch Doesn't Work
Scaled-down Intel Itanium-IIs
Lycos E-mail Troubles
IBM+Borland Challenge MSFT
Verizon Puts $1B into 3G
DOJ OKs Yahoo+Overture

More Web Design News:
2008 Current News
2008 June
2007 June
2007 May
2007 March
2006 November
2006 September
2006 August
2006 July
2006 June
2006 May
2006 April
2006 March
2006 February
2006 January
2005 December
2005 November
2005 October
2005 September
2005 August
2005 July
2005 June
2005 May
2005 April
2005 March
2005 February
2004 March
2004 February
2004 January
2003 December
2003 November
2003 October
2003 September
2003 August
2003 July
2003 June
2003 March - May



September 10, 2003

MSFT identified three vulnerabilities in Windows on Wednesday that could have a similar effect to that of the dreaded MSBlast worm of August.
By Michael Kanellos

The flaws, which affect Windows NT 4.0, Windows 2000, Windows XP and the 64-bit versions of Windows XP, are the latest in a string of critical weaknesses identified in Windows recently. The company has issued a patch that can be downloaded from its Web site.

The first two flaws are buffer overruns, which allow a hacker to take over a computer by swamping it with data.

The third is a denial-of-service flaw that affects a component known as the remote procedure call (RPC) process. The RPC process facilitates activities such as sharing files and allowing others to use a computer's printer. By sending too much data to the RPC process, an attacker can cause the system to grant full access to its resources. By using the flaws in tandem, a hacker could load unwanted programs onto computers through the buffer overrun flaws and then use the infected computers to launch a denial-of-service attack.

The MSBlast worm, also known as W32/Blaster and W32.Lovsan, exploited a similar vulnerability that allowed a group of unknown hackers to load data on computers worldwide in an attempt to knock out servers that run MSFT's update services.

"An attacker who successfully exploited either of the buffer overrun vulnerabilities could gain complete control over a remote computer," MSFT stated in a bulletin released Wednesday. "This would give the attacker the ability to take any action that they wanted on the system, including changing Web pages, reformatting the hard disk or adding new users to the local administrators group."

The bulletin released Wednesday, MS03-039, supersedes bulletin MS03-026, which in July first warned of the vulnerability MSBlast exploited. The vulnerability revealed Wednesday is similar in nature and in its potential for damage, but it affects the RPC function differently.

"It is a different vulnerability, but they have the same impact, and they affect the same ports," said Stephen Toulouse, security program manager at MSFT's Security Response Center. "In terms of impact, it is the same."

Ports are standardized software addresses that allow applications to exchange data. Firewalls routinely prevent illicit access to such services from the Internet by blocking the specific port used by a computer to offer those services.

MSFT is urging customers to apply the patch immediately. The company is also revisiting its overall security patching policy, Toulouse said. Now, patching is mostly left up to customers, a problem that has helped viruses spread.

Although the flaws were announced Wednesday, researchers at the CERT Coordination Center, a clearinghouse for information on Internet threats, said in August that they had detected the potential for a second denial-of-service flaw with the RPC process.

The actual flaw was first discovered by eEye security, NSFocus and Tenable Network Security.

Web Designs Now
Back to the Top


 © Copyright 2007, All rights reserved  |  Privacy Web Design Forums  |  Web Design News  |  Advertise  |  About Us  |  Contact Us  |  W3C HTML 
 Related Websites: New-York-WebDesign.com