search technology reviews, news, features, group tests
Popular Searches:   video , free , windows
 |  Register
 |  Newsletters  | 
Sitemap  |  RSS
RSS
Friday November 27, 2009 6:23 AM AEST
Skip Navigation LinksPC Authority > News > Windows exposed to DOS attacks
NEWS

Windows exposed to DOS attacks

by Paul Thurrott  on Mar 28, 2003
Tags: Windows | exposed | to | DOS | attacks

A recently discovered vulnerability in the Remote Procedure Call (RPC) subsystem in Windows NT, 2000, and XP threatens to provide hackers with a means to perform Denial of Service (DoS) attacks, Microsoft said yesterday.

And while the company has already created a patch for Win2K and XP users, Microsoft says that major changes in RPC since the release of NT 4.0 prevent it from creating a patch for that OS. Instead, NT 4.0 users can use a workaround, described on the Microsoft Web site.

The RPC service allows applications on a local computer to call functions in applications residing on a remote computer in a network. Taking advantage of a vulnerability in this service, it's possible to create an application that can send malformed requests to RPC, Microsoft notes in its advisory, causing the RPC service to fail.

This week's RPC vulnerability follows a serious Windows 2000 flaw announced a week earlier involving ntdll.dll, one of the core system library files in that system. According to the CERT Coordination Center, this library file has a buffer overflow vulnerability that is being actively exploited on WebDAV-enabled IIS 5.0 servers, which could allow remote attackers to execute arbitrary code on unpatched systems. The organization recommends that sites running Win2K apply a patch or disable the WebDAV services as soon as possible. The patch download URL is available below.
Patch for ntdll.dll Vulnerability
Microsoft Security Bulletin - RPC Vulnerability
NT 4.0 Workaround to RPC Vulnerability

Email a Friend Email this
Print Page Print this
Tweet This Tweet this
Feedback Send us your tips


Ads by Google

Comments

Be the first to comment on this article.
Thoughts on this article? Add a comment below.
Login or register to submit a comment.
 

Top Stories

Top 10 technology also-rans
From Betamax to Amiga, here's a list of those IT innovations that fell under the bulldozer. Some were cruelly robbed of their advantage, others threw it away with bad management
 
Movie tech: Latest Avatar trailer serves up more on Amp Suits, Aliens style army gear and much more
The latest Avatar trailer takes a closer look at the battle tech behind the film - but we can't help compare it to James Cameron's Aliens in tone and style.
 
Whatever happened to...Video Phones?
Videophones, in one form or another, have been around since the 1920's, with some major attempts to create public videophone booths in the 1930's and 1950's. But why didn't they take off in the modern era?
 


 
Intel
 
Apple Black Friday sale - one day only
 
 
LogMeIn
 
 
Amazing Dell Coupons now available