Security problems

Published: 28 August 1999 y., Saturday
Microsoft has acknowledged a serious security flaw in NT when used with Service Pack 4 (SP4) -- probably the most commonly deployed version of its operating system. The flaw enables hackers to masquerade as trusted hosts to get access to secure systems, using so-called Predictable IP Sequence Numbering - something that was identified and fixed in Unix systems several years ago, according to Richard Thomas, head of Winterfold Datacomm (Guildford, UK), a networking consultancy. Security problems had been found in earlier versions of NT, but the bundle of patches and fixes in SP4 were supposed to have made everything watertight. That_s proved not to be the case, according to NTA Monitor (Rochester, UK), a consultancy that conducts security audits on corporate systems by simulating hacker attacks over the Internet. When conducting such an audit, it came across Predictable IP Sequence Numbering at a customer site using NT with SP4. After doing bench tests to establish that the problem was generic to NT and SP4, NTA-Monitor contacted Microsoft. After nearly three weeks of deliberations, Microsoft has come clean. Sunil Gopal, a technical specialist at Microsoft, acknowledged the problem on Tuesday in a memo to Roy Hills, NTA-Monitor_s testing development director. His memo says fault has been eliminated in Windows 2000 and "will be back-ported to NT 4.0 in a future SP release."
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

LINUXWORLD - True believers still see Linux on desktop

Linux evangelists are keeping the faith, even when it comes to the elusive Holy Grail of the open-source operating system: taking a significant chunk of the desktop market. more »

Does Official Taliban Site Exist?

Afghanistan's Taliban government, which declared the Internet unholy and banned its use for millions of Afghan citizens last June, maintained a website until shortly after the Sept. 11 terrorist attacks more »

Web Welcome From Korea

This big Korea tourism site is designed to be the first port of call for providing information to overseas visitors to Korea. more »

FTC opens antifraud Web site

In court and on the Internet, the FTC and several states are cracking down on the practice with a Web site and lawsuits to help consumers "ditch the pitch." more »

Pentagon Denies GPS to Taliban

The Pentagon said on Friday that it won't limit the accuracy of positioning information that's beamed to civilian global positioning system (GPS) receivers. more »

Microsoft Lobbies For Strict New Zealand Copyright Rules

Microsoft has asked the New Zealand government to implement strict regulations to protect online intellectual property more »

Nokia Unveils Roaming Solution Using GSM, WLANs

Nokia Communications and Finnish operator Sonera reported today that they conducted wireless LAN roaming using the GSM core network and roaming infrastructure. more »

Surprise: E-Biz is Doing Fine

On Wednesday morning, the mass media abounded with pseudo-apocalyptic horrors. Dozens are "exposed" to anthrax. more »

Intertainer, Microsoft launch online film, video service

The market for watching movies over the Internet is uncertain, so few people have the necessary high-speed connections. more »

Hacking for the Cause

Group Claims Bank Hack Attacks; Others Not So Sure more »