Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
Microsoft details 'Windows on ARM' program
March debut of 'iPad 3' a sure bet, says analyst
FBI unbolts Steve Jobs 1991 investigation file
Cisco boosted profit, sales in Q2 while cutting costs
Macs take on the enterprise
Four crazy tech ideas from Google's Solve for X project
Obama 2012 campaign playlist revealed courtesy of Spotify
Oracle buying Taleo for US$1.9 billion in direct hit at SAP
Amazon attacks Apple: You get 3 Kindle products for price of iPad 2
Pre-rendered pages highlight latest Google Chrome release
Microsoft exec: Lync-Skype integration a 'compelling opportunity'
The future of hypervisors
/

Vulnerability in Netscape Servers Revealed

Today's breaking news
Send to a friendFeedback

InfoWorld, 08/26/99

A bug that allows hackers to gain illicit access to the Netscape Enterprise Server and Netscape FastTrack Server, has been discovered by Internet Security Systems Inc. (ISS) and its research team, the X-Force.

The vulnerability in both Netscape Communications Corp.'s servers uses a well-known hacker technique-called buffer overflow-to overload a server and then allows the hacker to overwrite the systems stack and gain access. The attack takes the form of an overly long HTTP GET request, according to ISS and X-Force.

"The fact that it's a remote buffer overflow attack means that an attacker can exploit the vulnerability and remotely upload and execute arbitrary assembly language. An attacker can write an exploit to get the computer to do what ever they want," said Chris Rouland, director of the X-Force, a intrusion-detection research team within ISS. "Users of Netscape (Enterprise and FastTrack Servers) have to patch those systems to protect themselves from this attack."

Netscape and ISS have collaborated to create a fix for the bug, in the form of the Enterprise 3.6 SP 2 SSL Handshake fix. It is available from Netscape at http://www.iplanet.com/downloads/patches/detail_12_86.html.

Separately, Netscape yesterday announced an encryption and security upgrade for Netscape Communicator 4.61 for use with Internet commerce sites, which is easier to download.

While previously Netscape users would be required to download a full version of the browser to upgrade their level of encryption, the SmartUpdate service-at http://home.netscape.com/smartupdate-requires only a 36KBps file to provide 56-bit U.S. internationally exportable encryption or 128-bit U.S.-grade encryption.

Currently, 128-bit encryption is believed to be unbreakable, and 56-bit is the maximum the U.S. government will allow to be exported internationally due to security concerns.

InfoWorld This story from Infoworld.com Copyright © 1999 InfoWorld Media Group, Inc.


RELATED LINKS


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.