Feeds

Attacks exploit Windows DNS server flaw

Only workarounds for now

Top 5 reasons to deploy VMware with Tegile

Attackers are targeting a flaw in the DNS service for Windows server OSes that could hijack the computers that run them, Microsoft warns. The software behemoth advises admins to employ workarounds pending completion of its investigation.

The vulnerability affects Windows 2000 Server, Service Pack 4 and SP 1 and SP2 versions of Windows Server 2003, according to this Microsoft advisory. DNS functionality exposed over port 53 is not at risk. Nor are Windows 2000 Professional, Windows XP and Windows Vista.

An attack can be carried out by executing a stack-based buffer overrun in the DNS Server's remote procedure call (RPC) interface. A successful exploit, in which a specially crafted RPC packet is sent to a targeted machine, could allow an attacker to run code in the security context of the DNS, which by default runs full privileges.

Without elaborating, Microsoft said it is aware of "limited attacks" using the DNS flaw. Fortunately, the SANS Internet Storm Center was a bit more forthcoming, saying it has learned of two US universities that have been attacked, in each case in early April from a source located at 61.63.227.125.

According to SANS, the attack commences with a TCP scan of ports 1024-2048, followed by a TCP connection to the port running the vulnerable RPC service. A Shellcode binds to TCP port 1100 and a VBscript is uploaded, which downloads an executable DUP.EXE. Voila: the machine is pwnd.

It's been a busy few weeks for Microsoft's security peeps. Last week, the company rushed out an emergency update to patch a critical hole in the way Windows handles customized cursors. On Tuesday, the company released a host of fixes as part of its monthly patch cycle. But even before savvy users had a chance to install them, miscreants were already tinkering with several new exploits targeting Microsoft products.

Microsoft has yet to announce plans for a patch. In the meantime, it is providing instructions for workarounds, which include disabling remote access of DNS using RPC. Those who want to automate the disabling of RPC from a large number of domain controllers can find help here. ®

Intelligent flash storage arrays

More from The Register

next story
Knock Knock tool makes a joke of Mac AV
Yes, we know Macs 'don't get viruses', but when they do this code'll spot 'em
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
Shellshock over SMTP attacks mean you can now ignore your email
'But boss, the Internet Storm Centre says it's dangerous for me to reply to you'
Why weasel words might not work for Whisper
CEO suspends editor but privacy questions remain
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
BlackEnergy crimeware coursing through US control systems
US CERT says three flavours of control kit are under attack
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
New hybrid storage solutions
Tackling data challenges through emerging hybrid storage solutions that enable optimum database performance whilst managing costs and increasingly large data stores.
Website security in corporate America
Find out how you rank among other IT managers testing your website's vulnerabilities.