main

DoS attack warning for Windows 2000/XP

Sleeper   on 16 October 2003 - 08:21 · 31 comments & 3572 views

Advertisement (Why?)
Last RPC patch does not protect systems, say researchers

Security experts are warning of a flaw that could allow hackers to launch a denial of service (DoS) attack against PCs running Windows 2000 and XP. The vulnerability, in the Microsoft Remote Procedure Call (RPC) service, was discovered by security firm Internet Security Systems (ISS).

ISS warned that the flaw affects PCs even with the most current Windows patches installed, including computers patched against the devastating RPC flaw described in Microsoft Security Bulletin MS03-039 According to ISS, the DoS vulnerability exists by exploiting the race condition, allowing attackers to crash the Microsoft RPC service and/or force vulnerable systems to reboot.

News source: vnunet.com


But the firm added that "significant barriers exist" which may prevent reliable exploitation outside controlled lab conditions.

ISS said that Microsoft has not yet released a patch for the vulnerability, and urged network administrators to assess external exposure to vulnerabilities associated with Microsoft services running on ports 135, 137, 138, 139, 445 and 593 on both the network perimeter and VPN connections.

Speaking at Microsoft's Partner Summit in New Orleans last week, chief executive Steve Ballmer criticised security researchers and their methods of disclosing vulnerabilities early.

"These are people who discover vulnerabilities, and it's part of their job to go public with them," he said.

"What we have done over the last six months is intersect with them to make sure disclosure is done in a more responsible way. I wish these people would just be quiet, but that's not going to happen."

ISS countered that it had speeded up disclosure of the vulnerability because tools are in circulation to demonstrate the DoS condition.

Post a comment · Send to friend Comments · There are 31 additional comments
(1 reply) #1 philmcneal on 16 Oct 2003 - 08:40
jesus the nightmare isn't over
#1.1 gigsvoo on 16 Oct 2003 - 09:00
Emm... the worst nightmare is coming and we are sitting here do nothing.
#2 YaZoR on 16 Oct 2003 - 08:47
oh ffs, come on microsoft. release patches that god damn work please!!!!
(6 replies) #3 Jasco on 16 Oct 2003 - 09:02
Yeah, for once: release a patch before something bad happens.
#3.1 eSouL on 16 Oct 2003 - 09:21
FYI, the RPC vulnerability patch was released way before the blaster attack..
#3.2 werejag on 16 Oct 2003 - 12:44
read this article
#3.3 Fowen on 16 Oct 2003 - 15:06
QUOTE (#1.2)
read this article

He is talking about the patch for the Blaster virus. It was released almost 3 weeks before the virus was released, and Microsoft went out of their way to get the news out. I got a email from them on a email address that I had no idea that they had (kind of scary). They are also STILL releasing patches for Windows NT4, which they don’t HAVE to do, since support was discontinued in June for the OS.

I get tired of all the people that bash Microsoft. If it wasn’t about these patches, it would be about something else. If you don’t like their products…. Get Linux. “They are the worst software company out there, but they are better then the rest”
#3.4 Sawyer12 on 16 Oct 2003 - 17:28
I thought there was something out a while back never to accept a patch that came through e mail from microsoft. it was dodgy or something
#3.5 Caelamia on 16 Oct 2003 - 18:40
Yeah, Microsoft say on their Windows Update site that they never send out e-mails to users like that, I believe.

I'm currently getting a load of these e-mails from numerous addresses at "charter.net" and I'm sick of them. Not entirely sure how people know my private home e-mail address, must be a friend of mine who has it in their address book and it virus-ridden. *sigh*
#3.6 King_John on 16 Oct 2003 - 22:20
MS won't send you a patch in the mail although they will, if you are signed up to the service, notify you of their patches and link you to it.
#4 psychoge3k on 16 Oct 2003 - 09:47
I had my network patched the day after the pach came out... Same as when the newer patch came out. You can never be to careful The same for any future patches too.
(2 replies) #5 MR_Candyman on 16 Oct 2003 - 10:27
ok, seriously, their LAST 4 patches HAVE NOT WORKED. What is wrong with you microsoft?
#5.1 Sub on 16 Oct 2003 - 12:16
They worked. There is more then one way to skin a cat.
#5.2 werejag on 16 Oct 2003 - 12:45
sure they worked now we will have the same problems
(2 replies) #6 kiddingguy on 16 Oct 2003 - 12:45
aha.

you'll have to check DAILY the Windows Update page to keep your system up-to-date.

Keeps getting annoying, to be quite honest with ya.

Why doesn't MS makes programs/OS's that work! That's what they're hired for, right?
#6.1 Tews on 16 Oct 2003 - 14:33
If you're refering to the OS it works fine... If you're too laxidasical about your security, then switch on automatic updates and you wont have to be annoyed.
The programs that MS work fine... I'd like to see security over eyecandy, but as long as they're script kiddies out there, you're going to have to be vigilant about patching yer system...
#6.2 Fowen on 16 Oct 2003 - 15:01
I agree 100%. It doesn't matter how much time they spend on their OS, there will always be someone who finds someway to get around the security. I am just happy that they aree doing a much better job then they used to with security patching.
#7 King_John on 16 Oct 2003 - 13:06
There is this magical thing that MS made, it's called AutoUpdate. Learn how to use it if you're so worried about patches.
(1 reply) #8 xp1ode on 16 Oct 2003 - 13:22
Everyone complains about how MS's OS' dont work and this and that, damn shut up
is always the same bullsh*t. If you dont like it so much just go to Linux or get a Mac or something. I've had windows for quiet sometime and i've never been affected by one of these vulnurabilties, neither have other two computers running XPHE and win2k. I've always kept up to date with these things, and have never had a problem, and if i do have a problem then oh well, i'l just try my best and fix it. You people somethng better to do than just sit there and complain, i bet some of you didn't even pay for the OS your using and are still complaining about it.
#8.1 BonkedProducer on 16 Oct 2003 - 21:05
yeah - my linux box doesn't play this or that game all that well - OH sorry thought the thread was about us that didn't pay for our OS whining - LOL

Just a weak shot of humor for the thread
(3 replies) #9 kiddingguy on 16 Oct 2003 - 13:45
i'm not complaining....

just making a remark. and that's different.

i also have not been affected anyhow from ms vulnerabilities. however, like i said, it's getting on my nerves to daily visit the windows update site.

that's all.
#9.1 cork1958 on 16 Oct 2003 - 14:21
Get's on your nerves? Are you one of the minority that is still on dialup? If not, how long does it take check the update site? 3 secs. max? Even on dial up. What does it take to check it out. 1 minute? Sheesh!!
#9.2 JaggedFlame on 16 Oct 2003 - 14:35
They release patches every Wednesday. What are you talking about, daily?
#9.3 Tews on 16 Oct 2003 - 14:38
No.. As a matter of fact you WERE complaining..... You claim that you weren't affected by any of the vulnerabilities... gee.. I wonder why??? Now kwitcherbitchin, turn on auto update and STFU!
(5 replies) #10 TheDeputy on 16 Oct 2003 - 19:18
As if me as the Security Administrator does not have enough on my fricken plate. geese
#10.1 King_John on 16 Oct 2003 - 22:18
Hey Mr Security Admin, learn how to use AutoUpdate. I don't know who is hiring you.
#10.2 KiwiNZ on 17 Oct 2003 - 07:48
If an Admin released a patch or an update on my network with out testing , in other words autoupdate I would fire them.
Auto update is fine for home PC's . On a network not a chance in hell.
That is why TheDeputy has a valid grumble . This is is costing a lot time and money .
#10.3 rbanksy on 17 Oct 2003 - 13:19
Which is why Microsoft developed MSUS for company's to use with the AutoUpdate Client. You can approve what you want.
#10.4 JaggedFlame on 17 Oct 2003 - 14:01
A valid grumble? That's his job! He sits around with nothing other to do than manage these computers!
#10.5 KiwiNZ on 17 Oct 2003 - 19:16
Like I said NOTHING goes on my Network without testing in the Labs. When you manage 5200 Desktops, 270 F&P Servers and 23 App Servers you dont trust vendor testing period.
#11 Tews on 17 Oct 2003 - 10:16
Well just what in the hell do you want??! I AM a sysadmin and I can gaurentee you that I patch my systems as soon as it becomes available... Do you remember MSBlaster??? The patch was available 6WEEKS before the worm hit and still MILIONS of systems were affected... Wait to patch one of my systems and your out the door!!

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)