On The Insider: John Mayer Equates Dating with Shame
BNET Business Network:
BNET
TechRepublic
ZDNet

By Matthew Broersma
Posted on ZDNet News: Nov 24, 2003 8:27:00 PM

Microsoft is investigating what may be a serious flaw in Exchange Server 2003, only a month after the software's launch as part of Office System 2003.

The bug appears to affect an Exchange component called Outlook Web Access (OWA), which allows users to access their in-boxes and folders via a Web browser.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


Consumers logging into their Web-based mailbox sometimes find themselves accessing another user's account, with full privileges, according to Matthew Johnson, a network administrator with a U.S. company that sells tools for investors and fund managers. Johnson reported the bug earlier this month on the NTBugtraq security mailing list.

"This seems to be a major security flaw, and we have had to shut off OWA indefinitely because of the issue," Johnson wrote.

Microsoft has said it is investigating the issue and that the flaw appears to occur only when Kerberos authentication is disabled. Kerberos is the method--developed at the Massachusetts Institute of Technology--that Microsoft uses for authenticating requests for services. For the moment, the company is advising customers to keep Kerberos authentication enabled, as it is by default, and may issue a patch or more information when its investigation is complete.

However, Johnson said that Microsoft's initial analysis doesn't seem to be correct, because his company did not alter Exchange Server's default configuration and thus should have been using Kerberos. He initially reported the bug to the software giant two months ago, and said Microsoft is in the process of testing patches.

Microsoft did not respond to requests for additional comment.

Earlier editions of OWA have suffered their share of security problems. In 2001, Microsoft released a patch for the OWA feature in Exchange 5.5 and 2000, but the patch itself notoriously caused many servers to overload and hang and was pulled offline; a second patch also contained a catastrophic bug.

A week and a half ago, Aaron Greenspan, a Harvard University junior and president of consulting company Think Computer, published a white paper concluding that Exchange 5.5 and 2000 can be used by spammers to send anonymous e-mail.

ZDNet UK's Matthew Broersma reported from London.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 26 Talkback(s)
put it behind a secure OWA proxy !!!!!!!!!!!
So know I pay through the nose for exchange and you tell me in order to get it secure I will have to pay yet again?????

Well I now understand why it's important to keep using MS stuff.... it ge... (Read the rest)
Posted by: NemesisNL Posted on: 11/26/03 You are currently: a Guest | | Terms of Use
This is a real shame  ChrisHenderson | 11/24/03
is there any reason  ryusen | 11/24/03
OWA and mobility  AbsolutelyNot | 11/24/03
Kerberos  FirstNLastN | 11/24/03
or...  Dave P. | 11/24/03
There might be.  Cardinal_Bill | 11/24/03
Re: There might be.  FirstNLastN | 11/24/03
Nope - it won't  Dave P. | 11/24/03
Re: Is there any reason  issthatso | 11/24/03
It's a sad fact  Fred Fredrickson | 11/24/03
RTA  Fred Fredrickson | 11/24/03
This is a non-issue.  DonnieBoy | 11/24/03
are you screaming silence?  JoeMama_z | 11/24/03
Let's compare then...  Dave P. | 11/24/03
jesus do you people even care  JoeMama_z | 11/25/03
Kicks but on bugs and vulnerabilities, I agree there.  DonnieBoy | 11/24/03
Lotus Notes?  master of illusion | 11/24/03
(NT) More of an issue, is that the Notes client is a bloated peeeg :o)  Jack-Booted EULA | 11/25/03
used?  James Schroer | 11/25/03
Microsoft is getting better at this security thing...  Dave P. | 11/24/03
OK, Show of hands.........  middle of nowhere | 11/24/03
A Security Flaw In A Microsoft Product???  The Real Bitch | 11/25/03
ME!!!  James Schroer | 11/25/03
Yes, shocked AND surprised!  Jack-Booted EULA | 11/25/03
OWA Security  robert.campbell | 11/25/03
put it behind a secure OWA proxy !!!!!!!!!!!  NemesisNL | 11/26/03

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline