Welcome | Sign In
ECommerceTimes.com
Security

Advisory: Windows Platform Widely Vulnerable to Attack

Print Version
E-Mail Article
Reprints
Advisory: Windows Platform Widely Vulnerable to Attack

Microsoft's latest security breach -- which affects all Windows servers and the Windows XP client -- is the result of relying on outdated protocols that were never meant to be deployed between machines or over networks.


How Much is 'Free' Costing You?
Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.

The U.S. Department of Homeland Security (DHS) issued an updated advisory Wednesday entitled "Potential for Significant Impact on Internet Operations Due to Vulnerability in Microsoft (Nasdaq: MSFT) Operating Systems."

The warning listed all the major iterations of Windows server platforms as well as client-side Windows XP. The advisory said that, while the department has not yet encountered any disruptions, several "working exploits" that would grant complete remote system access to affected computers are now being distributed across the Internet.

No Problems Reported as Yet

The DHS said that no worm codes have been reported; however, "an Internet-wide increase in scanning for vulnerable computers over the past several days reinforces the urgency for updating affected systems."

Eric Hemmendinger, research director for security and privacy at Aberdeen Group, told the E-Commerce Times that while he wasn't aware of any particular signs, he assumed the DHS has received some indication of activity.

"Otherwise, this would be the Net equivalent of duct tape and plastic sheeting," Hemmendinger said. "[The DHS] would be scaring people for no good reason."

The Latest Vulnerability

Windows computers have been found susceptible to a Remote Procedure Call (RPC) vulnerability. According to the DHS, hackers can take advantage of this flaw to install programs, change or delete data, create new accounts with full privileges or invoke a denial-of-service attack on at-risk computers.

Both the DHS and Microsoft have urged computer owners and systems administrators to patch their systems as soon as possible.

Problems with the Patch

But Richard Stiennon, research director for Internet security at Gartner (NYSE: IT), told the E-Commerce Times that patching computers is a problematic solution, particularly for large government agencies.

Stiennon said that, to patch a typical Windows machine, one would need to download and install an updated service pack before the user could download the appropriate patch, a task that could take up much of a day. The Employment and Training Administration (ETA), for example, has over 50,000 desktops. Stiennon said the agency simply does not have the time or resources to patch all those PCs.

"Microsoft has become very good at patching buffer overruns, but they have to go one layer deeper," Stiennon said. "They have to fix the way programs talk to each other."

Returning to Port

Stiennon said Microsoft's latest security breach is the result of relying on outdated protocols that were never meant to be deployed between machines or over networks.

According to Stiennon, port 135, one of the ports mentioned in the advisory, was designed to be used in non-Internet computing. Under those circumstances, it was an efficient protocol, but in today's Internet world, using it to enable computers to communicate and exchange code simply is not smart.

Stiennon recommended blocking 135 at the firewall level and, if possible, blocking it inside Windows-based networks. In addition, he advised administrators to take steps to get away from the parts of Windows architecture that uses this port, including Active Directory and the Active Directory Authentication Tool.


Print Version E-Mail Article Reprints More by Staff Writer


Talkback: Join the Discussion.
Re: Advisory: Windows Platform Widely Vulnerable to Attack
aergern
Posted 2003-08-02
Yep. And the week before the DHS sends out this alert they bought millions of dollars worth of ...
Re: Advisory: Windows Platform Widely Vulnerable to Attack
ctene
Posted 2004-10-31
LOL - Yeah, I'd feel really safe about my economy if I was a U.S. citizen - lucky I'm in Canada ...

More by Staff Writer

A Midsummer's Mac Death Match, Round Two: Enderle vs. Chaffin
July 13, 2004
MacNewsWorld presents round two of our three-round Midsummer Mac Death Match, in which Mac Observer editor-in-chief Bryan Chaffin and the always-controversial industry analyst Rob Enderle square off on one of today's key Mac issues. Today Enderle and Chaffin eachs kicks metaphorical mounds of sand on the arguments the other made in round one on the question of where Apple will be five years from now.
A Midsummer's Mac Death Match, Round One: Enderle vs. Chaffin
July 12, 2004
MacNewsWorld presents round one of our three-round Midsummer Mac Death Match. Today, Mac Observer editor-in-chief Bryan Chaffin and the always-controversial industry analyst Rob Enderle each offer their predictions of what sort of company Apple will be in five years. Will Apple rule the "Digital Life" -- or be the Atari of 2009?
PeopleSoft Blames Oracle for Share Price Free Fall
July 07, 2004
Forrester vice president and CRM analyst Erin Kinikin described PeopleSoft as being on a very narrow tightrope since Oracle first made its takeover offer. "To prove [it] can survive as an independent company, PeopleSoft has to make its numbers," Kinikin told CRM Buyer. "Any time PeopleSoft pre-announces lower earnings, people are going to wonder if [it is] falling off the tightrope."
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network