IT Masala

A Tech Curry with a Pinch of Indian Spice

14th April 2007

Cybercrooks exploiting new Windows DNS flaw

posted in Microsoft, Windows, Xclusive |

Cybercrooks are using a yet-to-be-patched security flaw in certain Windows versions tomicrosoft_dns_bug.jpg attack computers running the operating systems, Microsoft warned late Thursday.

The attacks target Windows 2000 Server and Windows Server 2003 systems through a bug in the domain name system, or DNS, service, Microsoft said in a security advisory.

What is the vulnerability: 

The vulnerability is believed to be caused by a stack overflow error in the Windows DNS Server's RPC interface implementation when processing malformed requests sent to a port between 1024 and 5000.

This means that remote unauthenticated attackers can execute arbitrary code with SYSTEM privileges by sending specially crafted requests to vulnerable systems. 

"An anonymous attacker could try to exploit the vulnerability by sending a specially crafted RPC packet to an affected system," Microsoft said in the advisory.

What is RPC?

RPC, or Remote Procedure Call, is a protocol that applications use to request services from programs on another computer in a network.

Red Alert : The French Security Incident Response Team deems the Windows DNS vulnerability "critical," its highest rating.

Which OS's are Affected : 

Windows 2000 Server Service Pack 4, Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2 are vulnerable, Microsoft said.

Caution to be taken : 

Security experts are advising that users for the time being disable remote management over RPC capability for DNS Servers or block unsolicited inbound traffic on ports 1024 to 5000.

via [ Microsoft security advisory ]

Leave a Reply

*
To prove you're a person (not a spam script), type the security text shown in the picture. Click here to regenerate some new text.
Click to hear an audio file of the anti-spam word


Call India for only 6.9ยข - 90 Free Minutes
Spread the Word
delicious
digg
technorati
reddit
magnolia
stumbleupon
yahoo
google