Security problems

Published: 28 August 1999 y., Saturday
Microsoft has acknowledged a serious security flaw in NT when used with Service Pack 4 (SP4) -- probably the most commonly deployed version of its operating system. The flaw enables hackers to masquerade as trusted hosts to get access to secure systems, using so-called Predictable IP Sequence Numbering - something that was identified and fixed in Unix systems several years ago, according to Richard Thomas, head of Winterfold Datacomm (Guildford, UK), a networking consultancy. Security problems had been found in earlier versions of NT, but the bundle of patches and fixes in SP4 were supposed to have made everything watertight. That_s proved not to be the case, according to NTA Monitor (Rochester, UK), a consultancy that conducts security audits on corporate systems by simulating hacker attacks over the Internet. When conducting such an audit, it came across Predictable IP Sequence Numbering at a customer site using NT with SP4. After doing bench tests to establish that the problem was generic to NT and SP4, NTA-Monitor contacted Microsoft. After nearly three weeks of deliberations, Microsoft has come clean. Sunil Gopal, a technical specialist at Microsoft, acknowledged the problem on Tuesday in a memo to Roy Hills, NTA-Monitor_s testing development director. His memo says fault has been eliminated in Windows 2000 and "will be back-ported to NT 4.0 in a future SP release."
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

DEA awards e-commerce contract

The Drug Enforcement Administration announced Nov. 26 that it has awarded a $6 million, two-year contract to PEC Solutions Inc. more »

Small victory

Via takes early round in graphics dispute with Intel more »

A trial date

Russian programmer gets April court date more »

Hardcore About Blocking Porn

The most people agree that work is the worst place for it to arrive. more »

Hardware vendors seek Web services opportunities

A host of IT vendors are jumping on the Web-based services bandwagon as hardware vendors realize the additional margins available from helping companies manage hardware from PCs to printers. more »

FBI software cracks encryption wall

‘Magic Lantern’ part of new ‘Enhanced Carnivore Project’ more »

E-Commerce Getting Ready for a Lean, Mean 2002

E-businesses are putting tech spending and other elements of their organizations on a much shorter leash in an effort to get ready for 2002, analysts say. more »

search.lt news

search.lt presents newest links more »

The report

Internet An Ideal Tool For Extremists - FBI more »

IT spend up 1% in 2001 - IDC

The "perfect storm" of the 11 September terrorist attacks, slowing global economy, and the telecommunications supply-demand mismatch, means that worldwide IT spending will only increase one per cent in 2001. more »