Security problems

Published: 28 August 1999 y., Saturday
Microsoft has acknowledged a serious security flaw in NT when used with Service Pack 4 (SP4) -- probably the most commonly deployed version of its operating system. The flaw enables hackers to masquerade as trusted hosts to get access to secure systems, using so-called Predictable IP Sequence Numbering - something that was identified and fixed in Unix systems several years ago, according to Richard Thomas, head of Winterfold Datacomm (Guildford, UK), a networking consultancy. Security problems had been found in earlier versions of NT, but the bundle of patches and fixes in SP4 were supposed to have made everything watertight. That_s proved not to be the case, according to NTA Monitor (Rochester, UK), a consultancy that conducts security audits on corporate systems by simulating hacker attacks over the Internet. When conducting such an audit, it came across Predictable IP Sequence Numbering at a customer site using NT with SP4. After doing bench tests to establish that the problem was generic to NT and SP4, NTA-Monitor contacted Microsoft. After nearly three weeks of deliberations, Microsoft has come clean. Sunil Gopal, a technical specialist at Microsoft, acknowledged the problem on Tuesday in a memo to Roy Hills, NTA-Monitor_s testing development director. His memo says fault has been eliminated in Windows 2000 and "will be back-ported to NT 4.0 in a future SP release."
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

Experts: Don't dismiss cyberattack warning

Security experts and two former CIA officials said today that warnings of cyberattacks by al-Qaeda against western economic targets should not be taken lightly more »

Intel, AMD Air Chip Advancements

Intel hit the ground running Monday by unveiling a dozen new additions to its Intel Xeon processor lineup more »

search.lt news

search.lt presents newest links more »

Feds Want to Extradite British Hacker

In an unusual move in an international hacking case, the U.S. government wants to extradite Gary McKinnon, a 36-year-old unemployed British computer administrator more »

BrideX worm bites Kaspersky Labs

In a bold move, a group of hackers launched a successful attack on the Web server of Russian computer security firm Kaspersky Labs Ltd. on Friday more »

search.lt news

search.lt presents newest links more »

A rapidly growing sector

Lithuania - a Perfect Place to Start for U.S. Businessmen in CEE Countries more »

Internet sites harry debtors

Frustrated firms use Web to shame clients who fail to pay bills more »

IBM relaunches PC division

Computing giant IBM has a new name and a new strategy for capturing market share in the PC business more »

search.lt news

search.lt presents newest links more »