Microsoft scrambles to address widespread ASP.NET bug

Powered by SC Magazine
 

Bug impacts entire .Net framework.

Microsoft has warned of an unpatched but publicly known vulnerability affecting ASP.NET, a web application framework that allows developers to build enterprise-grade web applications.

The flaw affects all versions of the .NET Framework, but so far Microsoft is not aware of any in-the-wild attacks, Dave Forstrom, director of Microsoft Trustworthy Computing, said in a blog post. However, the software giant anticipates exploit code to quickly be developed, and security experts said an emergency fix could come as early as this week.

What makes the bug particularly worrisome is that it enables attackers to use limited means to launch a devastating denial-of-service (DoS) attack against web servers. According to Microsoft, "a single, specially crafted ~100kb HTTP request can consume 100 percent of one CPU core for between 90 to 110 seconds."

"The vulnerability could allow an anonymous attacker to efficiently consume all CPU resources on a web server, or even a cluster of web servers [rendering ASP.NET pages]," Microsoft engineers Suha Can and Jonathan Ness wrote in a blog post. "An attacker could potentially repeatedly issue such requests, causing performance to degrade significantly enough to cause a denial-of-service condition for even multi-core servers or clusters of servers."

Andrew Storms, director of security operations at vulnerability management firm nCircle, said this type of DoS attack is highly unusual.

"This isn't your average DoS attack because it doesn't take a botnet or a lot of coordination to take a web server down," he said. "Most DoS attacks rely on a huge number of small requests targeted at a specific web server to overwhelm it."

The vulnerability is caused by an error in the way ASP.NET handles values in an ASP.NET form post to cause a "hash collision," which happens when two unique pieces of data have the same hash values.

In an advisory, Microsoft has released workaround details. In addition, the company has provided its Active Protections Program (MAPP) partners with detection guidance.

Storms said the issue is not unique to ASP.NET.

"It's highly likely that this attack isn't (Microsoft) specific and probably affects a number of vendors, and we can expect other vendors to make similar zero-day announcements," he said. "Everybody will be scrambling to come up with mitigation advice and patch strategies."

This article originally appeared at scmagazineus.com

Copyright © SC Magazine, US edition


Microsoft scrambles to address widespread ASP.NET bug
 
 
 
Top Stories
Innovating in the sleepy super industry
There’s little incentive to be on the bleeding edge, so why is Andrew Todd fighting so hard?
 
How technology will unify Toll
The systems headache formed through 15 years of acquisitions.
 
Immigration breached Privacy Act with data leak
Pilgrim slams "copy and paste" of asylum seeker data.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Optus steps up regional 4G coverage
Nov 20, 2014
Once 700Mhz services are working, Optus claims regional users will have a "faster and more ...
This Huawei 4G phone costs $99
Nov 12, 2014
The $99 Huawei Ascend Y550, available through Vodafone, enters the budget market as one of the ...
4G smartphones: Microsoft's Lumia 830
Nov 7, 2014
Microsoft has announced its flagship Windows Phone, the Nokia Lumia 830 4G, will be available in ...
Do you direct debit customers? Read this
Oct 10, 2014
Authorities have been targeting direct debit practices with iiNet and Dodo receiving formal ...
Optus expands 4G coverage
Oct 10, 2014
If you rely on an Optus phone for work you might be interested to know that there are now 200 ...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  39%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  7%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  20%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  6%
TOTAL VOTES: 811

Vote