posted by steve | Category: Current Projects |
Need more proof that security is simply not a priority at Microsoft? Today it came out that both Windows XP Professional with SP2 and Windows Server 2003 are vulnerable to an old, old, old,, and incredibly enough, previously-patched flaw in their TCP stack. The attack, called a LAND attack, causes a DoS condition against the operating systems.
Of course, it’s only applicable if XP SP2 isn’t running the Windows firewall but that’s the case within many (most?) corporate networks today. In addition, Windows Server 2003 is certainly not running with its own firewall, though is probably hidden behind an external firewall. However, if that server happens to be running a public web server, it’s vulnerable to this attack.
Microsoft was notified 10 days ago about this vulnerability and has done nothing about it, no fix, not even an announcement. Meanwhile, you can bet that folks everywhere are working on simple scripts to do this across entire subnets. To mitigate the risk, the only option would be to stop running Windows.
Leave a Reply
Archives
- March 2012
- February 2012
- January 2012
- December 2011
- November 2011
- July 2011
- June 2011
- February 2011
- September 2010
- December 2009
- November 2009
- September 2008
- August 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- October 2007
- September 2007
- August 2007
- July 2007
- June 2007
- May 2007
- March 2007
- December 2006
- August 2006
- July 2006
- December 2005
- September 2005
- August 2005
- July 2005
- June 2005
- May 2005
- March 2005
- February 2005
- December 2004
- October 2004
- September 2004
- July 2004
Categories