Security problems

Published: 28 August 1999 y., Saturday
Microsoft has acknowledged a serious security flaw in NT when used with Service Pack 4 (SP4) -- probably the most commonly deployed version of its operating system. The flaw enables hackers to masquerade as trusted hosts to get access to secure systems, using so-called Predictable IP Sequence Numbering - something that was identified and fixed in Unix systems several years ago, according to Richard Thomas, head of Winterfold Datacomm (Guildford, UK), a networking consultancy. Security problems had been found in earlier versions of NT, but the bundle of patches and fixes in SP4 were supposed to have made everything watertight. That_s proved not to be the case, according to NTA Monitor (Rochester, UK), a consultancy that conducts security audits on corporate systems by simulating hacker attacks over the Internet. When conducting such an audit, it came across Predictable IP Sequence Numbering at a customer site using NT with SP4. After doing bench tests to establish that the problem was generic to NT and SP4, NTA-Monitor contacted Microsoft. After nearly three weeks of deliberations, Microsoft has come clean. Sunil Gopal, a technical specialist at Microsoft, acknowledged the problem on Tuesday in a memo to Roy Hills, NTA-Monitor_s testing development director. His memo says fault has been eliminated in Windows 2000 and "will be back-ported to NT 4.0 in a future SP release."
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

E-Mail Virus Slams Muslim Group

Executives at the American Muslim Council are mad as hell. more »

Intel's accidental revolution

The foundation of modern computing was something of an accident. more »

New Nokia Phone Takes AIM

America Online's popular AIM instant messaging application has found a home on cell phone service offered by VoiceStream Wireless. more »

ICANN: To Serve and Protect

The deadly attacks of September 11 didn't just give us tighter airport checkpoints, new wiretapping and surveillance laws, and countless metric tons of explosives air-lifted to Afghanistan. more »

Osama Family's Suspicious Site

For the price of registering a domain name, a 30-year-old Web designer from Los Angeles has bought a bizarre piece of Internet history. more »

NTT DoCoMo Steps Up War Against Wireless Spam

Japan's NTT DoCoMo has unveiled new weapons in its war against junk e-mail more »

Telephony Speech Recognition Coming Of Age - Datamonitor

The use of speech recognition technology in telephone call centers is about to enter the mainstream more »

University Error Exposes Kids' Psychological Info Online

The information breach exposed the names and diagnoses of children and teenagers being treated for such conditions as schizophrenia, retardation and depression. more »

Wearable Computers in Fashion

Smart shirts embedded with optic fibers can monitor wearer's condition and transmit data wirelessly. more »

Hacker 'Doctor Nuker' Claims FBI Fingered Wrong Person

A computer hacker who vandalized a pro-Israeli group's Web site said law enforcement officials have issued an arrest warrant for the wrong person. more »