Welcome Guest ( Log In | Register )

  Recent Software News
Gmail Notifier 0.5.0 released
Coding misstep forces new Firefox r...
SmartSync Software Announces OEM Ag...
novaPDF 1.2 released
Google Toolbar for Firefox Coming S...
  Recent Gaming News
Playstation 3 Secrets Revealed
Microsoft Mulling HD-DVD in Future ...
Microsoft takes Marvel heroes
Microsoft Developing For Nintendo D...
The Sims 2: Nightlife
  Recent Reviews
 · Laserpod
 · Vantec Nexus Fan & Light ...
 · CoolerMaster Aerogate 3 A...
 · CoolerMaster AquaGate Wat...
 · OCZ Copper BGA Ramsinks
  Recent Forum Posts
? about new HDDs with old data...
Certification Exams
PC Specs...
Windows XP Sp2 Problems
Post up your desktops!
  Announcement

Welcome to AusPCWorld - Australia's Leading PC Technology News & Reviews site.




> AusPCWorld > Tech News > XP At Risk From DoS







   
XP At Risk From DoS
Posted by mitchy_g on 19 Jul 2005 - 02:38 1 comment
Previous Post | Tech News | Next Post
 
Microsoft has issued a security advisory warning that XP users could be at risk from a DoS (define)due to a vulnerability in Remote Desktop Protocol (RDP).

The vulnerability was discovered by security researcher Tom Ferris of SP (security-protocols) Research Labs. In a post on the Security-Protocols site, "badpack3t" wrote that they notified Microsoft about the flaw in May and allegedly were told that a patch would be out for it by August. SP Research Labs did not disclose the details of how to exploit the flaw nor did they provide proof of concept code along with their website posting.

In the advisory, Microsoft said the vulnerability was responsibly reported to Microsoft originally, but the finder chose to publish the details of the vulnerability publicly before a fix was available.

The flaw, as described by SP Research, is a "remote kernel DoS flaw within Microsoft Windows XP SP2 fully patched, with the firewall on."


In its advisory Microsoft admitted that its own "initial" investigation showed that the DoS flaw could be triggered by an attacker using a specially crafted Remote Desktop Protocol(RDP) request. Microsoft noted that its investigation has shown that the vulnerability does not lead to a system takeover, only DoS.

Microsoft's RDP allows for the remote desktop management and is currently enabled by default on Windows XP Media Center Edition, and as an option on other versions of XP and Windows 2000 and Windows Server 2003.

Pending the completion of a full investigation Microsoft noted it would issue a patch if required during its monthly patch update or out of cycle if it was merited.

News source: InternetNews

There is 1 additional comment, Post a comment | View printable post | Open/Close All Comments



#1 Posted by Daniel at 16 Sep 2005 - 20:11 Reply To This Comment  
Realy good site!

Hidden
Add A new comment
Name: (Register)
Email: (optional)
Quick HTML: (help)
  Close current tag   Standard Mode
  Close all tags   Enhanced Mode
Comment:


Smilies
(help)
Parse URL's: (will automatically add [url] [/url] round the web addresses in your comment)


 

Google