Streaming media giant RealNetworks Friday morning posted a patch for a flaw in its video servers that leaves them vulnerable to crippling attacks.
Published:
29 April 2000 y., Saturday
The flaw permits what is known as a "denial- of-service"
attack against specific RealServers. A denial-of- service attack is one that floods a server with a volume of bogus requests or that exploits a vulnerability so that it can't respond to legitimate demands for information. A Buenos Aires-based security firm called Underground Security Systems Research (USSR) posted a demonstration exploiting the flaw and a notification to the Bugtraq security mailing list. RealNetworks learned of the vulnerability and the demonstration exploit, dubbed "realdie.exe," through the Bugtraq
post Thursday and finished work on its remedy last night.
"As soon as we found out about it, we deployed a tiger team to analyze it, created a fix, put it through quality assurance testing, and posted it," a RealNetworks representative said. "We had a group of developers focused on it for the day. We treat all of these things very seriously." The denial-of-service attack and its cousin, the distributed denial-of-service attack, gained notoriety this year after attacks brought down major Web sites including Yahoo, eBay and Amazon.com.
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.
The most popular articles
Software company announced new structure_ of it_s business.
more »
High-profile telecom and networking companies are banding together to crack down on hackers
more »
End-of-show report for CeBIT 2005 (10 to 16 March) in Hannover/Germany
more »
Sony Ericsson announces at CeBIT the Bluetooth Motion Cam ROB-1
more »
German video streaming service company TV1 is launching at CeBit 2005 an online personal video recording service called shift.tv
more »
search.lt presents newest links
more »
China retailers are just starting to adopt electronic point-of-sale terminals, as the number of shipments is expected to surpass those to Germany, Europe's largest POS market, this year
more »
On January 27, 2005 JSC “Skaitmeninio sertifikavimo centras” (Digital Certification Centre) presented an application for IVPC to register a company providing qualified certification services. The director of the company Mudrikas Dadasovas tells about the future plans.
more »
GuruNet's stock fell back to Earth on Tuesday after the company revealed the extent of its tightening relationship with Google
more »
Photos of a "dead" Saddam Hussein are the lure for a new mass-mailing worm, Sophos warned on Thursday
more »
Picking up where it left off in 2004 with its distributed computing plans, IBM introduced a new service to help companies build and deploy service-oriented architectures
more »