June 13, 2002 (IDG News Service) --
Microsoft Corp. issued three security bulletins late yesterday offering patches for four recently discovered security vulnerabilities in several of its products. One hole, found in Windows NT, Windows 2000 and Windows XP, was rated "critical" by the vendor. That hole is a buffer overrun flaw in the phone book of the Remote Access Service (RAS), a standard part of Windows NT 4.0, 2000 and XP. By exploiting it, an attacker could gain full control over a machine or cause it to fail, Microsoft said in its advisory. To carry out an attack, an attacker would first have to change a RAS setting on the affected system before connecting to the system using RAS. If the target system's settings restrict user access, it won't be at risk, Microsoft said. RAS is used for dial-up connections. Another bulletin addresses a flaw in Internet Information Server (IIS) versions 4.0 and 5.0, the Web server components of Windows NT 4.0 and 2000. An attacker could run arbitrary code on the system by exploiting a flaw in software that supports HTR scripting, an older and largely obsolete scripting language, Microsoft said. HTR has been part of IIS since Version 2.0. It was never widely adopted because Active Server Pages, introduced in IIS 4.0, became popular before HTR use could take off. Virtually the only use for HTR today is a Web-based NT password managed service, Microsoft said, adding that it has long recommended customers disable HTR functionality and convert scripts that are needed to Active Server Pages. The IIS Lockdown Tool offered by Microsoft disables HTR by default. A third security bulletin addresses two vulnerabilities in the SQLXML part of SQL Server 2000. SQLXML enables the transfer of XML data to and from SQL Server 2000. The most serious of the flaws could allow an attacker to take over the machine running the database, Microsoft said.
Reprinted with permission from IDG.net Story copyright 2008 International Data Group. All rights reserved.
"Welcome to a special IT Blogwatch EXTRA: as Richi Jennings watches bloggers' reactions to the Russian hackers who claim to..."
Read more...
"As if taxpayers needed another reason to scorn the IRS. I read yesterday that the inspector general review of several..."
Read more... Read more Security posts or See all Blogs
One positive development stemming from the collapse of Wall Street may be a boost in interest in computer science and IT careers among students who were previously interested in financial services jobs.
Virtualization: Simplify. Automate. Lower Costs. Watch this complimentary webcast today! Go to the webcast
Managing Mobile Data with Endpoint Security for Laptops
Download this white paper now, compliments of Computerworld and Absolute Software. (Source: Absolute Software) A NetworkWorld survey of IT professionals found that only 1 in 100 employees consistently follow data security policy. This paper outlines endpoint security for laptops that restricts data access beyond encryption to safeguard against insider threats and user error.Read this whitepaper to learn lessons from recent data breaches, limitations of traditional data security, and how to remotely wipe out data and monitor computers that go off the network. Download this executive briefing
Top 10 Reasons to Upgrade
Get this white paper now! (Source: Symantec) Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery. Download this white paper
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
XenServer FREE trial
Citrix XenServer is the simplest and most effective way to virtualize and provision servers. XenServer combines comprehensive server virtualization capabilities with unparalleled scalability, performance, economics, and ease-of-use. Based on the open source Xen hypervisor, XenServer delivers fast performance, easy management, and advanced features such as live migration.
Go Green with Webroot® Perimeter Security SaaS! Webroot Perimeter Security SaaS is a powerful alternative to obsolete on-premise hardware based security solutions. SaaS allows businesses to obtain flexible protection through an expert security provider, solving the problems caused by software, hardware and appliance solutions. Benefits include easier manageability, better protection and guaranteed performance all at a lower cost. Register for your free copy of the "Why Security SaaS Makes Sense" whitepaper and Go Green with Webroot! Download this white paper now!