What is the BigBlueNetwork?

Go Back   BigBlueBall Forums > Computer Support > Computer Support Discussion

Join today and you won't have to look at these ads any more. Learn more.
Reply
 
LinkBack Topic Tools
  #1 (permalink)  
Old 07-19-2005, 08:49 AM
MiamiGuy
 
Posts: n/a
Windows Flaw Reaches Beyond XP

A security flaw that could let an attacker remotely crash computers running Windows exists in several versions of the operating system, not just Windows XP.

Windows 2000, Windows XP and Windows Server 2003 are vulnerable to a denial-of-service attack that exploits a problem in the Remote Desktop Protocol, Microsoft said in an advisory on Saturday.

RDP is a protocol that enables remote access to Windows systems. Because of a flaw in the way Windows handles remote desktop requests, an attacker could crash a PC by sending a malformed remote request, Microsoft said.

The advisory was released after the security researcher who discovered the flaw last week flagged Windows XP as vulnerable. Microsoft confirmed the issue on Friday and published the advisory over the weekend.

<!-- STORY TEASE --><!-- END STORY TEASE -->Microsoft said it is working on a patch, but noted that it is not aware of any attacks that try to exploit the vulnerability. However, security experts at The SANS Institute on Saturday did notice an increase in port scanning activity on the network port used by RDP. That could be a sign that hackers are trying to look for targets.

While most Windows versions ship with RDP services disabled, Remote Desktop is turned on out-of-the-box in Windows XP Media Center Edition. Only computers using services that have RDP enabled are vulnerable, Microsoft said in its advisory.

Services with RDP include Terminal Services in Windows 2000 and Windows Server 2003, and Remote Desktop Sharing and Remote Assistance in Windows XP.

-----

<!--StartFragment -->Remote Desktop is enabled by default on Windows XP Media Center Edition, putting those users at higher risk.
In addition to remote desktop sharing in Windows XP, Microsoft has also implemented the RDP protocol in Terminal Services in Windows 2000 and Windows Server 2003.

WORKAROUNDS

In the advisory, Microsoft recommends the following workarounds to help block known attack vectors:



- Block TCP port 3389 at the firewall. This port is used to initiate a connection with the affected component. Blocking it at the network perimeter firewall will help protect systems that are behind that firewall from attempts to exploit this vulnerability. On Windows XP and Windows Server 2003, the Windows Firewall can help protect individual machines. By default, the Windows Firewall does not allow connections to this port. Information on how to disable the Windows Firewall exception for Remote Desktop on these platforms can be found here.


- Disable Terminal Services or the Remote Desktop feature if they are not required. As a security best practice, if these services are no longer required on a system, users should consider disabling them. Disabling unused and unneeded services helps to reduce your exposure to security vulnerabilities. Information on disabling Remote Desktop via Group Policy can be found in this Knowledge Base article.

- Secure Remote Desktop Connections by using an IP Security policy. Specific configurations would be dependent upon the individual environment. For more information on IPSec, visit this Web site.

- Secure Remote Desktop Connections by employing a VPN. Again, configurations would be dependent upon the individual environment. See this Web site for more information about VPN connections.


Sources:

http://news.zdnet.com/2100-1009_22-5793344.html

http://www.eweek.com/article2/0,1895,1838174,00.asp
Reply With Quote
Reply



Currently Active Users Viewing This Topic: 1 (0 members and 1 guests)
 
Topic Tools

Posting Rules
You may not post new topics
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Topics
Topic Topic Starter Forum Replies Last Post
Windows 2000 and NT source leaked! EvilSeph Computer Support Discussion 15 04-23-2005 11:16 AM
Clean up! (Windows Program) LittleShorty The BigBlueBall Lounge 7 08-30-2004 06:04 PM
If Operating Systems were beer detn8r The BigBlueBall Lounge 0 06-24-2004 01:06 AM
Messenger Plus! 3 Feature List BigBlueBall News Windows Live Messenger News 0 05-21-2004 12:00 AM
freezing =( babycandy MSN / WLM Archive 43 06-28-2003 02:32 PM

All times are GMT -5. The time now is 06:57 AM.
Return to the BigBlueBall.com homepageHome | Contact Us | Privacy Statement | Advertise | Top
Powered by vBulletin® Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 RC6
Content Relevant URLs by vBSEO 3.0.0 RC6
©1999 - 2008 BigBlueBall.com All rights reserved.