On TechRepublic: Why Linux will triumph over Windows
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Feb 10, 2004 8:29:00 PM

Microsoft has a message for Windows users: Patch your computers quickly.

On Tuesday, the software giant released a fix for a networking flaw that affects every computer running Windows NT, Windows 2000, Windows XP or Windows Server 2003. If left unpatched, the security hole could allow a worm to spread quickly throughout the Internet, causing an incident similar to the MSBlast attack last summer.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


"There are more attack vectors and more people that could be affected by this," said Marc Maiffret, chief hacking officer for eEye Digital Security, the software firm that warned Microsoft of the vulnerability more than six months ago.

This is the second time this month that Microsoft has warned users of a security flaw. The company has a new policy of announcing vulnerabilities and releasing patches on the second Tuesday of each month, unless a critical flaw needs to be released immediately.

Last week, the software maker revealed a security flaw in Internet Explorer and issued a patch. On Tuesday, Microsoft announced three more vulnerabilities: the critical flaw and two other issues of lesser severity. One security hole affects computers running the Windows Internet Naming Service, and the other affects Microsoft's Virtual PC for the Mac platform.

The latest flaw exists in Microsoft's implementation of a basic networking protocol known as Abstract Syntax Notation One, or ASN.1. The code is shared by many Windows applications, and if left unpatched, it causes each program that uses the code to be an entry point into the operating system for an attacker.

Such widespread vulnerabilities are most tempting for the underground coders who create worms such as MSBlast--also known as Blaster--and Slammer, both of which took advantage of widespread Windows flaws.

The vulnerability could allow a remote user to take control of a computer running a version of the Windows operating system that hasn't been patched, according to the advisory posted on Microsoft's Web site. Exploiting the flaw is much easier if the attacker can access a local network, the advisory noted.

"This means a high number of vulnerable systems out on the Internet," said Brian Dunphy, director of managed security services for security software company Symantec. "It's a good candidate for an Internet worm."


Special coverage
MSBlast echoes across Net
Fast-moving worm exploits a
widespread weakness in Windows.


The flaw bears a resemblance to the one that allowed MSBlast to spread in August 2003, said Stephen Toulouse, security program manager at Microsoft's security response center.

"It is relatively similar in terms of the number of computers it could affect," he said, adding that the flaw "is in all versions of Windows."

Created by Xerox and standardized in 1984, ASN.1 is a way to describe networking data and protocols, said Bancroft Scott, president of OSS Nokalva, an ASN.1 tools developer.

"Twenty years ago, people frequently reinvented the wheel when they wanted to pass data," he said in a January interview on the subject of ASN.1. "There was no standard way to describe the data that you were going to send."

ASN.1 changed that, allowing developers to describe data in an abstract language. However, developers of tools for creating network protocols and software from those descriptions frequently didn't consider that Internet attackers would use the channel as a way to break into computers, Scott said.

The widespread use of ASN.1 has led many security researchers to label it a possible "monoculture"--a population so homogeneous that a single threat could destroy it. A recent trend in the computer security world is the recognition that vulnerabilities in common technologies can have widespread effects. A flaw in the Simple Network Management Protocol, a widely used way to communicate between network hardware, was due to an ASN.1 implementation error.

eEye's Maiffret was critical of Microsoft for taking so long to issue the patch.

"Two hundred days to fix this," Maiffret said. "It is obviously ridiculous."

Microsoft's Toulouse said the fix took so long to create because of the difficulties posed by such a pervasive technology.

"ASN.1 is really an extremely deep...technology in Windows itself," he said. "This investigation required us to evaluate several different aspects. This is an instance where we really had to do our due diligence."

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 196 Talkback(s)
us navy
im not sure what the navy uses on board ships but i can tell you that the usaf uses windows on b1b bombers navigation and weapons systems - they were tactical conventional in afghanistan however they ... (Read the rest)
Posted by: carl-mbsi Posted on: 03/11/04 You are currently: a Guest | | Terms of Use
why bother?  stephen732@... | 02/10/04
(NT) some advertisement happy  toomuchgreeatea@... | 02/10/04
UNTIL MICROSUCKS GETS SUED...  realitycheck101 | 02/10/04
Sorry, read the EULA....  Oscar_Goldman | 02/10/04
True but deception is rampant  michael-t | 02/10/04
Also Re the EULA  The Real Bitch | 02/11/04
eula's  NemesisNL | 02/11/04
Why not you then  rock06r | 02/10/04
HOME USERS APPLY THIS PATCH IMMEDIATELY!!!!  Heatlesssun | 02/10/04
UNTIL MICROSUCKS GETS SUED..  rwest@... | 02/11/04
Until MS Gets Sued ...  gary.douglas@... | 02/11/04
Bravo!  brasscap_z | 02/11/04
The pain at Microsoft has to be more than they can bear.  DonnieBoy | 02/10/04
Not the only ones with problems....  racka4279 | 02/10/04
Yeah...MS is doing good.  Cardinal_Bill | 02/10/04
Nobody claims perfection  zd-spam | 02/10/04
But Billy Gates comes close  IT_User | 02/10/04
I agree, security is relative  racka4279 | 02/10/04
flawed argument.  ryusen | 02/10/04
Let me see if I've got this straight.  Immanuel Tranz-Mischen | 02/10/04
um..  racka4279 | 02/10/04
sense of humor  broadway al | 02/11/04
Server exploits versus desktop exploits  Knorthern Knight | 02/10/04
Caught You  nikoli | 02/11/04
how does this affect xp lite  Hanover Phist | 02/11/04
how long to patch  scott.marlowe@... | 02/11/04
MS Flaw......again  B_HI | 02/10/04
Two hundred days to fix this...  Solid Water | 02/10/04
eEye is compromising another tool for Homeland Security  toomuchgreeatea@... | 02/10/04
Don't think we'll see No_Ax/Shadetree/usapride/southerpride/NoLife in here  Bobby Sskcat | 02/10/04
Don't think we'll see No_Ax/Shadetree/usapride/sout herpride/NoLife in here  FreeBSD | 02/10/04
Funny  fastech@... | 02/10/04
Bwahahahahahaha!! That was great!!  Bobby Sskcat | 02/10/04
Not really  zd-spam | 02/10/04
It's already happened...  surtur | 02/11/04
HEAR HEAR....  spinit | 02/10/04
Two mistakes:  CobraA1 | 02/10/04
What is MS?  zd-spam | 02/10/04
Rant Rant Flame Rant Flame Rant  Squawkbox | 02/10/04
MS has already started doing that  toomuchgreeatea@... | 02/10/04
Sorry I did not know I have been in my cave too long.  Squawkbox | 02/10/04
Xp is flawed as well  NemesisNL | 02/11/04
Firestone & Ford  B_HI | 02/11/04
Stock in Firestone?  ddollinger | 02/11/04
Top Secret?  WizWom_z | 02/11/04
It's not just Windows. Linux users must do the same.  No_Ax_to_Grind | 02/10/04
So? What does this have to do with the story? It's an M$ article!  Bobby Sskcat | 02/10/04
Just helping users that are unaware.  No_Ax_to_Grind | 02/10/04
yeah.. right..  Iain_Peters | 02/10/04
LaiM_Peters has no clue  jrbeaman | 02/11/04
Thanks for the tip  nucrash | 02/10/04
Nice try Bit.  Cardinal_Bill | 02/10/04
The point being...  No_Ax_to_Grind | 02/10/04
His point being  nucrash | 02/10/04
Not exactly  Suicida| | 02/10/04
The point being 4 months...  jrbeaman | 02/11/04
oh bother  optimaloptimusprime | 02/10/04
Do you have a spell checker?  No_Ax_to_Grind | 02/10/04
I think he called you his girlfriend. In Spanish amiga=female friend  Squawkbox | 02/10/04
would not be a bad add on for a browser (nt)  JWatson77 | 02/11/04
wow  JWatson77 | 02/11/04
Linux INVENTED on an AMIGA? HAH!  jrbeaman | 02/11/04
the Worm infection is just windows  Iain_Peters | 02/10/04
Do you have a browser on our Linux box?  No_Ax_to_Grind | 02/10/04
I patched most of this problem months ago  DanIelWalker_z | 02/10/04
Good on ya, now warn others to do the same.  No_Ax_to_Grind | 02/10/04
But you imply tyhe risk is the same in both cases. It's not.  DanIelWalker_z | 02/11/04
You Just Did The Stupidest Possible  nikoli | 02/11/04
Re: You Just Did The Stupidest Possible  B.O.F.H. | 02/12/04
A browser on a server??? Why??  Iain_Peters | 02/11/04
Odd you should say that.  zd-spam | 02/10/04
You also missed the point.  No_Ax_to_Grind | 02/10/04
Can you hit the point  michael-t | 02/10/04
Oh, come on...  brble | 02/10/04
a couple of points  ryusen | 02/10/04
Uh huh, whatever you say ZZ  No_Ax_to_Grind | 02/10/04
you want to look at the actual isues?  ryusen | 02/10/04
In the eye of the beholder...  No_Ax_to_Grind | 02/10/04
beholders are ugly...  ryusen | 02/11/04
Axe - point out ZZ'z misinterpretation  Iain_Peters | 02/11/04
Have you taken...  The Real Bitch | 02/11/04
I think that Dr. Phil could  michael-t | 02/12/04
Well for starters  bhanes@... | 02/11/04
re: a couple of points  brble | 02/10/04
NP  ryusen | 02/10/04
Yes... and no....  Zogg | 02/10/04
Design  Suicida| | 02/10/04
The loudest the noise  michael-t | 02/10/04
Small technical point...  Zogg | 02/11/04
The strength of modular design, eh?  Zogg | 02/11/04
I don't use SSL  FreeBSD | 02/10/04
For my mind the MS one appears much worst  Richard Flude | 02/10/04
Nonsense, as usual.  michael-t | 02/10/04
OpenSSL is from the OpenBSD project!  B.O.F.H. | 02/11/04
Nice try bub  Taz_z | 02/11/04
You are daft, aren't you?  WizWom_z | 02/11/04
Ah, I see now how this lowers the TCO ..  George Jay | 02/10/04
Windows Users Remind Me Of A Dog  Chad_z | 02/10/04
That's good writing.  Anton Philidor | 02/10/04
Glad you like it.  Cardinal_Bill | 02/10/04
Wrong way 'round  Anton Philidor | 02/10/04
Thanks for reminding me what I dislike most about Linux  jfrankcarr | 02/10/04
both sides  ryusen | 02/10/04
The day the twin towers fell...  civilised | 02/10/04
after that day....  NemesisNL | 02/11/04
And you point is?  FreeBSD | 02/10/04
The point is the Linux attitude  jfrankcarr | 02/10/04
RE: The point is the Linux attitude  Iain_Peters | 02/11/04
There are just as many, if not more...  The Real Bitch | 02/11/04
i resent that...  ryusen | 02/11/04
It really wasn't meant to offend anyone  The Real Bitch | 02/11/04
Gloaty Gras!  Chad_z | 02/10/04
actually  bhanes@... | 02/11/04
Not a minute too soon  michael-t | 02/10/04
STFU  Suicida| | 02/10/04
off point  michael-t | 02/10/04
Technical Arguments?  brble | 02/11/04
Too much effort for nothing  michael-t | 02/11/04
Ditto  brble | 02/11/04
Too many words; too little essence.  michael-t | 02/11/04
24 years?  D_Larsen | 02/11/04
Myth-buster  MarcB_z | 02/11/04
In addition  TWRX | 02/11/04
Don't you mean 1983?  voska | 02/11/04
Some inaccurate info there.  jfrankcarr | 02/11/04
At last someone with memory ....  michael-t | 02/11/04
At last someone with memory ....  michael-t | 02/11/04
Windows 1.0 1991  mrlinux | 02/11/04
MS ASN dll FLAW????  michael-t | 02/11/04
good point!  ryusen | 02/11/04
My theory on why it took so long.  jfrankcarr | 02/10/04
The people who  michael-t | 02/10/04
Corroborates mine  IT_User | 02/11/04
good, meaningful post  michael-t | 02/11/04
Common Sense??  stormaz@... | 02/11/04
Sadly you are right  michael-t | 02/11/04
Believe it or not  brble | 02/11/04
us navy  carl-mbsi | 03/11/04
Accuracy  brble | 02/11/04
A small pesky detail  michael-t | 02/11/04
Probably a Misunderstanding  brble | 02/11/04
But there is such GREAT job security in fixing the flaws at MS!  jrbeaman | 02/11/04
Why this is especially bad news for Microsoft  George Mitchell | 02/10/04
Windows 3.1.1  jhimes | 02/11/04
Um... "Deep" doesn't mean what you think  WizWom_z | 02/11/04
(NT) ZDNET, You need a new story - - - Read this one 18 times in last year.  Plain Logic | 02/10/04
(NT) No_Ax, HOW MANY SERVERS DID YOU NEED TO PATCH TODAY ???  Plain Logic | 02/10/04
If he is smart  Suicida| | 02/10/04
Is it safe to auto-update a MS patch  Iain_Peters | 02/11/04
NO NO NO!  jrbeaman | 02/11/04
All MS and Linux boxes, automatically.  No_Ax_to_Grind | 02/10/04
I would never  brble | 02/11/04
re: All MS and Linux boxes, automatically -NOT  Iain_Peters | 02/11/04
huh?  CobraA1 | 02/16/04
big deal  JWatson77 | 02/11/04
Think  mn210@... | 02/11/04
You Think  ITGuy04 | 02/11/04
I pray the patch won't break my system  doctormoriarty | 02/11/04
I think it did mine  jhimes | 02/11/04
Better after removing patch  jhimes | 02/11/04
Do you want some cheese to go with that whine?  rwest@... | 02/11/04
Linux has the same "holes"?  middle of nowhere | 02/11/04
Linux has the same "holes"?  rwest@... | 02/11/04
so you're saying  ryusen | 02/11/04
Another FUDder  WizWom_z | 02/11/04
If your Windows computer were a car  mau4@... | 02/11/04
Parked Car? Bad Analogy  mycoal5 | 02/11/04
Car analogy  mrlinux | 02/11/04
Car Analogy  stormaz@... | 02/12/04
If your Windows computer were a car  rwest@... | 02/11/04
look at this case specifically...  ryusen | 02/11/04
First thing to do.....  chiishen | 02/11/04
Throw out all MS software & prgmrs & start over again  IT-professional | 02/11/04
Start all the way over  Bit Bucketteer | 02/11/04
Market Share  TWRX | 02/11/04
Almost a really good post  nikoli | 02/11/04
Microsoft  aschwabjr@... | 02/11/04
A small pesky detail  michael-t | 02/11/04
This Is Just Stupid  nikoli | 02/11/04
AHMEN.  jrbeaman | 02/11/04
ahmen ???  nikoli | 02/11/04
Windows Flaw  dercp94@... | 02/11/04
What?  nikoli | 02/11/04
I should add  nikoli | 02/11/04
Another Timed Moved by M$  dgpeter@... | 02/11/04
EULA spyware / ownership issues  Laura Newman | 02/11/04
Not An Apologist But...  nikoli | 02/11/04
I couldn't imagine  michael-t | 02/11/04
You're too funny  nikoli | 02/11/04
Microsoft Flaws  TheWizard_z | 02/12/04
Mac OS X  slylabs13 | 02/13/04
Mine Either  nikoli | 02/15/04
Windows ME vulnerabilty and security support  jonkopp | 02/16/04
Window Flaw  redhead4855 | 02/16/04
Here We Go Again...  TANSTAAFL! | 02/17/04
Hmm. Isn't this software from India?  mike.pennington@... | 02/17/04

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

advertisement
Click Here