CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image Windows, Unix Hit By Critical Security Vulnerabilities image
Riot Act
By Mitch Wagner

Security administrators have been kept hopping this week with a series of vulnerabilities and patches for Microsoft and Unix systems.

In the latest events on Wednesday, Microsoft announced a vulnerability in Windows, the second Windows problem announced by Redmond this week that could allow attackers to take over a target system.

Earlier this week, Microsoft announced a vulnerability that could allow hackers to take over a Windows 2000 system. Unlike most of the regular procession of security vulnerabilities announced in enterprise software, the Windows 2000 hole had actually been exploited. Web servers run by the U.S. Army and others were attacked. Later in the week, Microsoft warned that its patch to fix the vulnerability could itself freeze up systems running Windows 2000 Service Pack 2. The company recommended users update their operating systems with later Windows 2000 patches.

Also on Wednesday, the Computer Emergency Response Team (CERT) advised of a security hole that could allow attackers to take over users of systems running Unix and Unix-like OSs including BSD, IBM AIX, and Sun Solaris, using network code written by Sun. Other vendors were investigating the flaw.

The latest Windows security problem is a buffer overrun vulnerability affecting Windows XP, Windows 2000, Windows NT 4.0 Terminal Server Edition, Windows NT 4.0, Windows Me, Windows 98 Second Edition, and Windows 98. The flaw affects the Windows Script Engine for JScript; an attacker could exploit the vulnerability by constructing a Web page that executes code of the attacker's choice with the user's privileges. The Web page could be hosted on a Web site or sent directly to the use in e-mail.

Microsoft recommends users immediately install its patch for the flaw, which Microsoft rates as critical. Users can also disable active scripting, install the current Outlook E-mail Security Update, and restrict Web visits only to trusted sites. Further information and the patch code is available from the Microsoft Web site.

The Unix problem, also a buffer overflow vulnerability, affects the Sun Microsystems XDR library, used in other vendors' operating systems as well. The eXternal Data Representation libraries allow systems to send data between systems processes, typically over a network connection, and commonly used in Remote Procedure Call (RPC) implementations. CERT recommends systems administrators apply patches from their vendors; more information, pointers, and patches are available from the CERT Web site.

The constant procession of security patches from enterprise vendors puts enterprise security managers in a Catch-22: it's impossible to keep up, and impossibly dangerous to fall behind. David Perry, global director of education at enterprise security vendor Trend Micro, said he expects security services -- such as the service introduced by his company earlier this year -- will step in to help users manage security. These services will replace and incorporate traditional standalone products like antivirus software, Perry said.

"We're transforming to a world where you're not just getting a pattern file from your antivirus companies, you're getting policies and advisories and leveraged expertise," Perry said. "You hire someone who does these things for you."

That's the solution for large enterprises. Small enterprises, Mom-and-Pop businesses, and home users will look to Internet service providers to offer security services, which is important to large enterprises because small-enterprise systems and home users generally have sloppier security policies, and become vectors for transmitting viruses. Users connect to corporate networks from personal systems, spreading viruses.

Perry also questioned the media's pattern of publicizing security holes as soon as they are discovered, which provides pointers to hackers on where to look for vulnerabilities, as well as an incentive to gain notoriety in the hacker community.

"It becomes a self-fulfilling prophecy of a sort," Perry said.

Source
Posted on Thursday, 20 March 2003 @ 08:08:15 UTC by Paul (1316 reads)
[ Trackback ]
image

"Windows, Unix Hit By Critical Security Vulnerabilities" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· IBM
· Microsoft
· Microsoft
· HotScripts
· W3 Consortium
· Sun Microsystems
· More about Riot Act
· News by Paul


Most read story about Riot Act:
Is Hacking Ethical

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer