Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Android, Apple Own 80% of Global Smartphone Market; Microsoft's Share, 2.2%
Proposed New York Legislation Would Ban Anonymous Online Comments
Supercomputer to connect to 400PB of storage via Ethernet
Sales of unused IPv4 addresses gathering steam
Customizable cloud SLAs on the way, researchers predict
Google chairman pledges to fund Raspberry Pi availability in U.K. schools
Obama orders agencies to optimize Web content for mobile
Are CEOs getting the social media thing?
Managing Mobile Mania
Google's Android did not infringe Oracle patents, jury finds
HP to trim 27,000 jobs as part of restructuring program
VMware acquires desktop management company Wanova
Privacy advocates fear CISPA
Groups launch gigabit-per-second broadband project
Windows 8 touchscreen devices to be priced higher, Dell says
/

Microsoft issues fixes for Win 2000 security holes

Today's breaking news
Send to a friendFeedback


Microsoft Corp. managed to beat itself to the punch last week, issuing the first patches to fix security holes in the much delayed Windows 2000 operating system-several weeks before its official release date.

Two security bugs were detected in Microsoft Index Server, search engine software found in both Windows NT and Windows 2000. The first could allow a malicious user to view, but not change, add or delete, files from a Web server, while the second could reveal the physical location of Web directories on the server, according to a security bulletin issued by Microsoft last week. The bulletin also said that the two glitches were unrelated except for the fact that they both were found in the Index Server.

Windows 2000, Microsoft's new operating system for corporate users, is scheduled to be officially released on Feb. 17. Index Server is a tool designed to allow users to perform full-text, online searches via a Web browser. It was designed to search Word, PowerPoint and Excel documents as well as standard HTML (hypertext markup language) documents, according to information from Microsoft's Web site.

The first bug, or the Malformed Hit-Highlighting Argument "vulnerability," as Microsoft calls it, allows users to request information beyond their security access via a specific type of malformed request.

"It's highly possible that someone could take advantage of the vulnerability," said David Litchfield [CQ], security analyst at U.K.-based Cerberus Information Security Ltd., who originally spotted the bug. "But it depends on what the ultimate end of the attacker is," he noted. "If he's trying to look for sensitive files on the Web server. . . or view the source of active server pages, he can do that."

Microsoft's patch, which he has installed on his system, does eliminate the problem, Litchfield said.

More information regarding both security bugs, including the patches, can be found here.

Microsoft, in Redmond, Washington, can be reached at 425-882-8080, or on the Web at www.microsoft.com/. Cerberus Information Security, in Surrey, U.K., is at 44 181 661 7405, or at www.cerberus-infosec.co.uk/.

RELATED LINKS

Some Windows 2000 systems shipping already
IDG News Service, 01/25/00.

King of the NOS hill
NetWare holds the performance reins, but Windows 2000 reigns supreme for features overall.
Network World Test Alliance, 01/24/00.

More ways to get Windows 2000 upgrade for free
Network World Windows NT Newsletter, 01/24/00.

Microsoft vows security committment on Windows 2000
InfoWorld, 01/19/00.

Rolling out Windows 2000
Network World Fusion, 08/30/99.

RELATED LINKS


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.