Attackers prey on Windows DNS server flaw

Powered by SC Magazine
 

Vulnerability in Windows Server 2000 and 2003 being used for malware attacks.

Microsoft is warning users of a new attack targeting a vulnerability in Windows Server 2000 and 2003. 

Users of Windows XP and Vista are not vulnerable to the attack, which targets the domain name system (DNS) server component by using a specially-crafted remote procedure call (RPC).

DNS servers are used to link a server's IP address to its domain name. When executed, the exploit allows an attacker to remotely execute code on the target machine.

The vulnerability was first reported by Microsoft on 13 April as a proof-of-concept. By 16 April, two variants of attacks on the vulnerability were reported.

Security firm Secunia rated the vulnerability as 'highly critical', the company's second-highest alert level. 

Microsoft has listed a number of methods for administrators to mitigate the vulnerability, including disabling certain ports on a firewall and editing the machine's DNS registry.

All these moves, however, will disable the ability to remotely manage a machine's DNS server component via RPC commands.

Microsoft said that the number of reported attacks is very limited, and the company plans to have the vulnerability patched by next month's Patch Tuesday release, although it has not ruled out an earlier patch if attacks persist.

"Because DNS is a critical part of the networking infrastructure, they also have to be tested to ensure that changes introduced by the updates do not pose a greater risk than the security issue we are addressing," said Microsoft Security Response Center researcher Christopher Budd.

Copyright ©v3.co.uk


Attackers prey on Windows DNS server flaw
 
 
 
Top Stories
Beyond ACORN: Cracking the infosec skills nut
[Blog post] Could the Government's cybercrime focus be a catalyst for change?
 
The iTnews Benchmark Awards
Meet the best of the best.
 
Telstra hands over copper, HFC in new $11bn NBN deal
Value of 2011 deal remains intact.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  39%
 
Your insurance company
  3%
 
A technology company (Google, Facebook et al)
  8%
 
Your telco, ISP or utility
  7%
 
A retailer (Coles, Woolworths et al)
  2%
 
A Federal Government agency (ATO, Centrelink etc)
  20%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  6%
TOTAL VOTES: 1778

Vote
Do you support the abolition of the Office of the Information Commissioner?