Microsoft Warns About A DNS Vulnerability

Free Press Release
iPhone 3G SEO Local Dating Auto Insurance ...
 

Home | Submit Release | Features & Pricing | Success Stories | Blog | Journal | FAQ | Search | Members' Area

News Archive > 2007 > Apr > 16
Microsoft is investigating new public reports of a limited attack exploiting a vulnerability in the Domain Name System (DNS) Server Service.
For_Immediate_Release:

April 16, 2007 (Press Release) -- According to a security advisory posted on the company’s website, Microsoft is investigating new public reports of a limited attack exploiting a vulnerability in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server Service Pack 4, Windows Server 2003 Service Pack 1, and Windows Server 2003 Service Pack 2.

The Redmond company also said the Microsoft Windows 2000 Professional Service Pack 4, Windows XP Service Pack 2, and Windows Vista are not affected as these versions do not contain the vulnerable code.

Microsoft’s initial investigation reveals that the attempts to exploit this vulnerability could allow an attacker to run code in the security context of the Domain Name System Server Service, which by default runs as Local SYSTEM. This can be exploited to cause a stack-based buffer overflow via a specially crafted RPC request.

Upon completion of this investigation, Microsoft will take appropriate action to help protect its customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.

According to SANS, Microsoft has a few suggested actions that can mitigate the risk with the caveat that some tools may break.

1. Disable remote management over RPC for the DNS server via a registry key setting.
2. Block unsolicited inbound traffic on ports 1024-5000 using IPsec or other firewall.
3. Enable the advanced TCP/IP Filtering options on the appropriate interfaces of the server.

Also SANS said that there are two confirmed sources that were attacked on April 4th and 5th. Both were universities in the US.

The Danish security vendor Secunia rated the vulnerability as highly critical and also recommended disabling the remote management over RPC capability for DNS servers.

Author: Alex Radulescu
Source: http://www.playfuls.com/


Email Print SPAM Submit to RestNews.COM

LEAVE A COMMENT
Title:


Message:
You can use following font styles to enhance your article. (No HTML tags.)
[large]sample[/large] sample
[b]sample[/b]sample
[i]sample[/i]sample
[color=#ff0000]sample[/color]sample
Your name:
Your email: (Please provide a valid email.)
Please read the number in the image:
Publisher: zyk06




Submit Press Release
IndustriesCountriesTags

Top Headlines More>>
Hackers Claim to Revive 'Bricked' iPhones
It's unclear, however, how permanent any "unbrick" fix will be, or whether changes to the hacks that allow modifications will survive the next Apple iPhone update. Hackers have come up with at least one way to "unbrick" iPhones disabled by a firmware update Apple Inc. issued two weeks ago, developers of both paid and free unlock software said Thursday.
Palm's Centro is a Smart Phone With a Great Price
The Palm Centro from Sprint announced today the exceptional price of only $99. This is great news for consumers who want a smart phone, but don't want to shell out mega-prices for one. Of course, like most phones, you will need to sign a 2-year contract to get the new device. "Palm Centro has the power of a broadband smartphone at the price of a standard 12-key phone," said Ed...
IBM to offer free office software, targeting Microsoft
BEIJING, Sept. 19 (Xinhuanet) -- IBM Corp. is to start offering free programs for word processing, spreadsheets and presentations, in another bid to upset the dominance of Microsoft's Office suite, media reported Tuesday. The company was scheduled to announce the desktop software, called IBM Lotus Symphony, at an event Tuesday. The name for the suite is the same name IBM used...
Google prize aims to spur corporate race to moon
Search engine Google is offering more than $35 million prize money for companies to land a robot camera on the moon and send back high-resolution photos and data. It has launched a new site called Google Moon and hopes the prize will encourage what it calls a 'global private race to the moon'. Google hopes private companies can develop simpler technology than the equipment used by...
Google phone
The Google Phone is like the Roswell UFO: Few outsiders know if it really exists, but it's got a cult following. Just months after iPhone mania gripped Silicon Valley gadget heads, suspense is building over reports that Google Inc. plans to release its own cellphone. Color us skeptics on this one, but we've got a tipster claiming to have the scoop on Google Switch. This version of the...
Yahoo! Mail for mobile phone
Global Internet specialist Yahoo! Inc. has this week announced a widening to the range and draw of its existing e-mail service by granting online account holders the ability to stay in touch with their on-the-go friends via the dispatch and receipt of text messages to and from mobile phone handsets.
Easily Dominate Niche of the online Markets
If you're struggling desperately to make money online while your boss isn't watching, this will solve your 5 biggest problems... Discover The Magic Formula To Create “Set-it-and-Forget-it” Websites Using Wordpress & Make Your First Adsense Dollar in The Next 7 Days.
About PSP (PlayStation® Portable)
The PSP® (PlayStation® Portable) system is the first truly integrated portable entertainment system designed to handle multiple applications – music, video, photo, internet, and wireless connectivity, with games as its key feature. The PSP® system features an unmatched library of entertainment content, combining more than 135 games and more than 430 feature films, TV...
iPod Derivant
iPod is a brand of portable media players designed and marketed by Apple and launched in October 2001. Devices in the iPod range are primarily digital audio players, designed around a central click wheel — with the exception of the iPod shuffle, which uses buttons because of its small size. As of September 2006, the line-up consists of the video-capable fifth generation iPod, the smaller...

Sitemap | All News | Daily | Weekly | Monthly | Tags | Industries | Countries | RSS | Add URL | Contact Us

Free Press Release All press release information on this site, including free press release and premier press release, is solely based on what our users submit. Free-Press-Release.com disclaims that any right and responsibility for the information goes to the user who submit the press release. Some press release may be confusing without additional explanation. You should contact the provider with any questions about the information presented. In case some press release damages your benefits or violate your rights in any way, please contact us and we'll remove it immediately.
  • Press Release
  • Pub Gratuite