Feeds

Attacks exploit Windows DNS server flaw

Only workarounds for now

Using blade systems to cut costs and sharpen efficiencies

Attackers are targeting a flaw in the DNS service for Windows server OSes that could hijack the computers that run them, Microsoft warns. The software behemoth advises admins to employ workarounds pending completion of its investigation.

The vulnerability affects Windows 2000 Server, Service Pack 4 and SP 1 and SP2 versions of Windows Server 2003, according to this Microsoft advisory. DNS functionality exposed over port 53 is not at risk. Nor are Windows 2000 Professional, Windows XP and Windows Vista.

An attack can be carried out by executing a stack-based buffer overrun in the DNS Server's remote procedure call (RPC) interface. A successful exploit, in which a specially crafted RPC packet is sent to a targeted machine, could allow an attacker to run code in the security context of the DNS, which by default runs full privileges.

Without elaborating, Microsoft said it is aware of "limited attacks" using the DNS flaw. Fortunately, the SANS Internet Storm Center was a bit more forthcoming, saying it has learned of two US universities that have been attacked, in each case in early April from a source located at 61.63.227.125.

According to SANS, the attack commences with a TCP scan of ports 1024-2048, followed by a TCP connection to the port running the vulnerable RPC service. A Shellcode binds to TCP port 1100 and a VBscript is uploaded, which downloads an executable DUP.EXE. Voila: the machine is pwnd.

It's been a busy few weeks for Microsoft's security peeps. Last week, the company rushed out an emergency update to patch a critical hole in the way Windows handles customized cursors. On Tuesday, the company released a host of fixes as part of its monthly patch cycle. But even before savvy users had a chance to install them, miscreants were already tinkering with several new exploits targeting Microsoft products.

Microsoft has yet to announce plans for a patch. In the meantime, it is providing instructions for workarounds, which include disabling remote access of DNS using RPC. Those who want to automate the disabling of RPC from a large number of domain controllers can find help here. ®

The smart choice: opportunity from uncertainty

More from The Register

next story
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
NEW, SINISTER web tracking tech fingerprints your computer by making it draw
Have you been on YouPorn lately, perhaps? White House website?
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Black Hat anti-Tor talk smashed by lawyers' wrecking ball
Unmasking hidden users is too hot for Carnegie-Mellon
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Own a Cisco modem or wireless gateway? It might be owned by someone else, too
Remote code exec in HTTP server hands kit to bad guys
prev story

Whitepapers

Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.