Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
iPhone 5 rumor rollup for the week ending Feb. 10
Forget Public Cloud or Private Cloud, It's All About Hyper-Hybrid
Apple passes HP as largest tech company
How to get the IRS' attention: Forge nearly $8 million in tax returns, steal identities
Much of Western U.S. is a 3G wasteland, says FCC
How the Phoenix Suns basketball team takes on social media attacks
Microsoft details Windows 8 for ARM devices
Resume Makeover: How an Information Security Professional Can Target CSO Jobs
Blogger exposes major Google Wallet security flaw
Web app lets enterprise set security, sharing for Google Apps users
Cloudscaling to offer OpenStack private cloud platform
Macs take on the enterprise
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
/

Bug delays next Win 2000 service pack

Today's breaking news
Send to a friendFeedback


REDMOND,WASH.- Despite a serious security vulnerability found last week in Windows 2000 Server, IT executives will have to wait for the second service pack for a fix.

Microsoft was set to ship the service pack nearly two weeks ago when researchers reported a major vulnerability in Internet Information Server (IIS) 5.0, which is built into Win 2000. Microsoft immediately canceled shipment of the service pack so it could include a patch that corrects the problem. It is unclear when the service pack will be ready. A Microsoft spokesman would only say it will ship in the first half of this year.

The vulnerability discovered last week is known as a buffer overrun, one of the most well-known and common avenues for security attacks. In IIS, the flaw is exploited through an Internet Services Application Programming Interface (ISAPI) and can provide an attacker with system-level access to the server. That means an attacker would have full control of Win 2000 Server. The vulnerability is present in the Server, Advanced Server and DataCenter editions.

"I expect this exploit to be as bad as [Remote Data Services]," says Russ Cooper, editor of the NT BugTraq Web site and the surgeon general for TruSecure. RDS was introduced three years ago in IIS 4.0 and hackers have been using it ever since to deface Web sites and collect credit card numbers.

"We estimate 26% of IIS servers today are still vulnerable to it," because IT administrators have not plugged the hole, Cooper says. "I expect this most recent bug to be with us for a long time and in about six months we'll see an exploit."

With that in mind, Microsoft last week scrambled to issue a patch, but the company also began work on incorporating it into Service Pack 2 for Win 2000.

"We have to redo all the system testing and all the final testing before we can release the service pack," says Scott Culp, security program manager at the Microsoft Security Response Center.

Culp says the bug is serious enough to mandate that enterprise users get a fix in a service pack, which is likely to get more attention than a patch. But he says users should get the patch as soon as possible.

Service Pack 2, which is already off the every-six-months release cycle for service packs Microsoft announced when it shipped Win 2000, features a number of fixes for Win 2000 and Active Directory. Microsoft has not publicly discussed what specifically is included.

The newest fix, however, is for the ISAPI extension in IIS that supports the Internet Printing Protocol, which allows printing over the Web. To exploit the flaw, a hacker sends a cleverly crafted URL to the server that contains the malicious code. The string of characters overruns a buffer and then adds executable code to the server. Once the code is run, the hacker gains access to the entire machine. The exploit works only with IIS 5.0.

RELATED LINKS


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.