The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Serious RPC Flaw Could Expose Microsoft DNS Servers to Remote Exploits
Time: 18:43 EST/23:43 GMT | News Source: BetaNews | Posted By: Jonathan Tigner

This morning, the US-CERT team of the Department of Homeland Security acknowledged Microsoft's advisory this morning, stating that it's investigating instances where Windows servers running the DNS service can be tricked into running any code remotely in a local system context, with the same privileges as the DNS service itself.

As an indication of how seriously Microsoft takes this threat, in a special advisory issued this morning, it instructs customers to use their Registry Editors to set a bit in their DNS parameters for servers running the DNS service, effectively disabling DNS bindings to remote procedure calls (RPC) in favor of local procedure calls only (LPC). From there, the company further suggests that admins use their firewalls to block all RPC traffic, which could extend from ports 1024 to 5000.

Essentially, Microsoft is telling admins to shut off the pipes completely for all traffic that would otherwise enable them to manage DNS servers from remote locations. As the company acknowledges, remote management tools will not function while LPC protocol is favored and RPC ports are blocked by a firewall, though remote management through Terminal Services is still possible.

Today’s threat, Microsoft said, impacts Windows Server 2003 Service Pack 1 and Service Pack 2 (just released), and Windows 2000 Service Pack 4. However, servers which use IPsec to encrypt traffic may not be impacted. Microsoft’s security advisory made a point of saying Vista is unaffected by this problem, although presently, Vista isn’t deployed in many business environments as a server anyway, especially where admins await the release of Longhorn.

Write Comment
Return to News

  Displaying 1 through 25 of 434
Last | Next
  The time now is 7:48:21 AM ET.
Any comment problems? E-mail us
#1 By 37047 (74.101.157.125) at 4/14/2007 10:24:52 AM
Gee, where is Parkkker to tell us about some old problem with Bind?

#2 By 23275 (24.179.4.158) at 4/14/2007 6:06:39 PM
Mystic, the vuln is not in DNS [either AD, or D-DNS], the vuln is with DCOM RPC used on W2K and W2K3 servers, which supports remote management of the service - which by the by, would be mitigated/blocked by default by any firewall - even crude SOHO NAT devices, that I am aware of. So unless someone has a DC, or and DNS server facing the cloud that is not behind a firewall, then they needn't worry. The vuln does NOT/NOT exploit the DNS Service on UDP 53, or TCP 53. So, any comparison to BIND would be irrelevant - **which of course, I know you know and get the joke - I just don't want young admins out there thinking that there's an "oh my God" vuln out there like some boogey man.

#3 By 32132 (64.180.219.241) at 4/14/2007 10:00:22 PM
#1 It only took RedHat a couple of months for this patch:

https://rhn.redhat.com/errata/RHSA-2007-0057.html

But I'm curious ... how come Microsoft flaws get all the security publicity when flaws like this one get none:

"A flaw was found in the username handling of the MIT krb5 telnet daemon
(telnetd). A remote attacker who can access the telnet port of a target
machine could log in as root without requiring a password."

https://rhn.redhat.com/errata/RHSA-2007-0095.html

This post was edited by NotParker on Saturday, April 14, 2007 at 22:06.

#4 By 15406 (216.191.227.68) at 4/16/2007 8:57:00 AM
#1: Ford is just now fixing this major batch of flaws:

http://www.internetautoguide.com/auto-recalls/05-int/suvs/ford/index.html

#5 By 13030 (198.22.121.110) at 4/16/2007 9:45:28 AM
#3: It took Toto 6 years to fix this "issue", so I should start cutting MSFT some slack.

http://news.bbc.co.uk/2/hi/business/6559373.stm

#6 By 23275 (24.179.4.158) at 4/16/2007 12:20:05 PM
I sure get tired of the world holding out that Microsoft is the only company that supports some form of remote method(ing)/remote code execution like it <the ability> is some kind of flaw... as if the functions of DS services, and the end point mapper service don't exist in similar ways, or are not used in similar ways on other operating systems - regardless of ports actually assigned. It's just daffy.

There are many and they are as useful and potentially vulnerable as any Microsoft has evolved. It's just like the rap ActiveX gets - like any other browser doesn't support one or more forms of RMI - it's ridiculous and foolish to assume that others are safer, or better.

#7 By 15406 (216.191.227.68) at 4/16/2007 12:44:23 PM
#6: So what you appear to be saying is that you shouldn't complain about anything if there is the possibility that something somewhere might be worse? Sounds bogus to me. This site is about everything Windows, warts and all. Everyone knows all software has bugs and that will never change. Other communities I've seen don't seem to be as emotionally invested and can actually offer criticism, constructive or not, without the rampart fanboyism. Here at ActiveWin we have some who are unable to acknowledge any of MS' faults and instead spend their time defending MS, sometimes to the point of absurdity. Kind of like trying to stop the rain with a bucket.

#8 By 37047 (216.191.227.68) at 4/16/2007 12:53:09 PM
#3, #6: This is the same as complaining about a Bind defect in a Unix/Linux forum, and someone saying that this is not an issue worth discussing, because Windows has a DNS related flaw. This would be equally inane on the Unix/Linux forum. Since this site is ActiveWin, and not ActiveLinux or ActiveUnix, I have operated under the presumption that the topics here relate specifically to Windows and other products that run on Windows. So, mentioning a newly found Firefox security hole would be fair game, as long as it is in the version running on Windows, and not some issue specific to, say, the Linux version or the Mac version. Now, if this is only meant to be a site for Microsoft Fanboyz, then please let the rest of us know, and maybe the site can be renamed ActiveWinFanBoyz.com or something else equally descriptive. Until then, I will operate under the presumption that we are here to discuss Windows related topics, both positive and negative.

#9 By 13030 (198.22.121.110) at 4/16/2007 1:28:03 PM
#6: It's just like the rap ActiveX gets...

And deservedly so! ActiveX was a poorly thought out wrapper around COM which, in-and-of itself, wasn't designed with security in mind. (I'm not saying that was necessarily a flaw of COM--it's just the way it was designed. Technologies today must consider security, however.)

MSFT had such a fear (completely unfounded in my opinion) of losing its desktop dominance in the mid 90s to the Internet, or thin clients, or browser-based appliances that it rushed out its response. The result was the VB-nurtured, secure application owned and client-based ActiveX model hacked to work with IE. Since ActiveX security was the responsibility of the host application, you got the equivalent of the "Let's Make a Deal" game show. If you selected the IE door, you had a great chance to win the goat!

#7, 8: If a defect occurs in the MSFT "forest" and a MSFT fanboi doesn't acknowledge it by misdirection or minimization, does the defect, in fact, really exist?

#10 By 15406 (216.191.227.68) at 4/16/2007 1:56:36 PM
#9: I'll ask the Dalai Lama the next time he's over.

#11 By 23275 (24.179.4.158) at 4/16/2007 3:41:54 PM
#9, Ch, I'd agree with poorly implemented and managed, but not poorly designed - ActiveX was designed from the outset to use signed controls supported by certificates.

Since XP SP2 in Aug, 2004, ActiveX has been far better managed and in IE 7 under Vista, IE 7 runs in Procted Mode by default and in its own context/space which is very restrocted and limited. Many learned pundits continue to assert that ActiveX controls just run with no user intervention and they mention Protected Mode without explaining what it is, or that it is on by default - much less getting into that there is no root level admin account that is enabled under Vista and all accounts are actually restricted.

Similarly, and opposite RMI, COM remains very important and pursued by Mozilla advocates for the same reasons it is useful to IE centric devs... http://www.iol.ie/~locka/mozilla/mozilla.htm

Why?
Previous versions of Netscape Communicator/Navigator were arguably superior to IE as day to day browsers but they suffered through their immediate usability and modularity. Although the Netscape browser was great as a standalone application, it wasn't possible to utilize that functionality in third party applications. On the other hand, Internet Explorer shipped with an ActiveX control which allowed exactly that ability.


So given how users on Windows operating system MUST agree to all software installs - how in the heck is an ActiveX control any different from any other software that a user downloads and agrees to install in this context? Like a sidebar Gadget, for example - if it does not from Microsoft's site and is signed/certified to be safe? I mean, each would have to be signed, or recieve the same warnings. Similarly, where COM is not used and another form of RMI is used, Windows Vista users are also warned and offered a choice.

If anything, Vista, and IE 7 have given new life to the use of COM/RMI. I mean also, AJAX/ATLAS haven't won over all just yet and they have their own security issues to contend with as well as a lot of dev time ahead of them.

#12 By 4240821 (213.139.195.162) at 10/27/2023 3:41:07 AM
https://sexonly.top/get/b158/b158cfuurrsxcxjtvks.php
https://sexonly.top/get/b982/b982vnbhfeulkwklsox.php
https://sexonly.top/get/b633/b633cugzmijqfkqkjrc.php
https://sexonly.top/get/b837/b837oriqomcefoblvwx.php
https://sexonly.top/get/b518/b518pajyqgmbhfhzhyh.php
https://sexonly.top/get/b467/b467yfvyxakyqpvqaqu.php
https://sexonly.top/get/b973/b973eavqyiifuszwuvm.php
https://sexonly.top/get/b506/b506mezimlgfmeuwvaf.php
https://sexonly.top/get/b205/b205tjcuvqgrfjjspen.php
https://sexonly.top/get/b51/b51mwynzszdcosowsk.php
https://sexonly.top/get/b582/b582ddffduypngakojn.php
https://sexonly.top/get/b188/b188aywonhrsrzlbhuf.php
https://sexonly.top/get/b346/b346kvmxcynwpkzjvfx.php
https://sexonly.top/get/b908/b908saklpyyhgoyunqw.php
https://sexonly.top/get/b983/b983gdqywjbserrvmwj.php
https://sexonly.top/get/b850/b850hrmkbnqvtwbskpr.php
https://sexonly.top/get/b515/b515zxzgasbrrtmyzcd.php
https://sexonly.top/get/b299/b299zdvvphvjlumxnmw.php
https://sexonly.top/get/b553/b553zrlizwarmorrvde.php
https://sexonly.top/get/b720/b720wxxppzdymoffxcm.php
https://sexonly.top/get/b773/b773hrzrfibhbijpxgm.php
https://sexonly.top/get/b563/b563vwutbwofbvlaptd.php
https://sexonly.top/get/b820/b820ieynagtyqqyzyap.php
https://sexonly.top/get/b567/b567unpdlhzaudgwjco.php
https://sexonly.top/get/b543/b543fsmudubaegfknil.php
https://sexonly.top/get/b828/b828vykekvzzrivrzhq.php
https://sexonly.top/get/b91/b91abwmxvkwcnwmmdt.php
https://sexonly.top/get/b287/b287fwpyaevtnsrlvqp.php
https://sexonly.top/get/b863/b863fppspqpfpxflkku.php
https://sexonly.top/get/b570/b570hykeeqzyikiomza.php
https://sexonly.top/get/b408/b408fkcabtmuthvbbmr.php
https://sexonly.top/get/b609/b609yatlmtyrtvofasj.php
https://sexonly.top/get/b934/b934cybxdbfvtbdhxvn.php
https://sexonly.top/get/b19/b19jmpgndwdhsyjkje.php
https://sexonly.top/get/b436/b436nwmpqhoanbryxaf.php
https://sexonly.top/get/b418/b418ewthhseibmkrgkt.php
https://sexonly.top/get/b173/b173uszymdhxypdglrf.php
https://sexonly.top/get/b531/b531guozmlgcpopibsf.php
https://sexonly.top/get/b205/b205oiponnywqfnzvvg.php
https://sexonly.top/get/b974/b974kspftmtbdqkockg.php
https://sexonly.top/get/b187/b187qpxgaeicarbsava.php
https://sexonly.top/get/b14/b14zuzazgvfdrsefdh.php
https://sexonly.top/get/b135/b135biezmbpovkykyem.php
https://sexonly.top/get/b539/b539acmjyfjdjttooua.php
https://sexonly.top/get/b71/b71eqgtfdmizknmfms.php
https://sexonly.top/get/b25/b25kupznelihjgwsfs.php
https://sexonly.top/get/b719/b719vxkrzulmepyfopt.php
https://sexonly.top/get/b106/b106ytnhhplytajdspv.php
https://sexonly.top/get/b567/b567baxgzcielmfzxqr.php
https://sexonly.top/get/b660/b660thqodrqbcpjxsrq.php

#13 By 4240821 (103.151.103.150) at 10/30/2023 3:16:02 PM
https://www.quora.com/profile/CleoBoateng138/Sarahs-Lil-Secret-cameo-1-ornelia-Misobadkat-Valentinafox-NaughtyBigLatina-Ooooopleaseeatme-LORISUN-Fair
https://www.quora.com/profile/ChrisFerrantello43/Trinity-Morgana-Emptybby-Frenchy2022-thicknprettyyy-Alison-Star-GoldAmethyst-SabrinaMmoorree-ultra_violet_
https://www.quora.com/profile/BrandyTownsend9/xxMgsgirlxx-AutumnGoddess-Pakopero-aalexanal-GoddessRose_Belle-sky-sarahy-BellaSinn-TheSammyStrips-Moons
https://www.quora.com/profile/TimothyRocker460/wefuck2good-Joey-Green-katiiidel-BushyBabe1-Kenzibebe-OFFICIALNIKKYDUNES-MrsPink-Hayley_x_x-MochaBunnyxx
https://www.quora.com/profile/KristinaAvance592/Lickmykandi22-dianapearl97-LatieShyXXX-mintypine-ChrisAnDave-asmrKIA-KloNhiggins-HotGotti-Cecilia-Badb
https://www.quora.com/profile/RickyBollinger693/angelaValeria-DelihaDaze-Perverted-ebony-albiziii-Folgosa-Chunky_bae-Cindylester0711-jigglyxxpuff-AmorOw
https://www.quora.com/profile/RevFarukh799/OralFixationn-VideoModel-swinging-liisa-Sensual-Ilene-Cory-Baby-Rubylovedarling-Slavekiora-Oloro-Kiorasfeet
https://www.quora.com/profile/KristenDavila285/keith_0609-SlumalienB-taraSpankalicious-Brooke-Brewy-Kissplum-Sugary-Tits-casperquartz-Bunnyxl19-bunnicu
https://www.quora.com/profile/CaseyKing54/Sweetpeas69-HaylaReignxxx-AshleyMarthaa-Bbwcrazylover-da_realcookiemonsta-Eva-Quinn-berrie710-LipsSoLush
https://www.quora.com/

#14 By 4240821 (103.152.17.80) at 10/31/2023 11:56:54 AM
https://app.socie.com.br/read-blog/97259
https://app.socie.com.br/read-blog/97650
https://app.socie.com.br/Silenthillnerdemerald6985
https://app.socie.com.br/juliapartonTommySteel
https://app.socie.com.br/read-blog/98339
https://app.socie.com.br/read-blog/97659
https://app.socie.com.br/innocentblueeyes97nymphox
https://app.socie.com.br/RheaOrionSandraLuesse
https://app.socie.com.br/read-blog/98361
https://app.socie.com.br/read-blog/97525

#15 By 4240821 (103.151.103.150) at 10/31/2023 8:54:56 PM
https://app.socie.com.br/KittyvqueenKandiceTheFreak
https://app.socie.com.br/read-blog/98675
https://app.socie.com.br/Alfonsina13MiaDixxon
https://app.socie.com.br/read-blog/97667
https://app.socie.com.br/CreamyJordanSexyAsianLucy
https://app.socie.com.br/read-blog/97215
https://app.socie.com.br/read-blog/98445
https://app.socie.com.br/townslutNyxieNova
https://app.socie.com.br/Kashmoney66bigbootilatte
https://app.socie.com.br/read-blog/97674

#16 By 4240821 (62.76.146.75) at 11/1/2023 6:55:20 PM
http://activewin.com/mac/comments.asp?ThreadIndex=24526&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=21340&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=17796&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=18116&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=77049&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=72575&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=63391&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=13086&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=60755&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=78956&Group=Last

#17 By 4240821 (2.57.151.31) at 11/2/2023 6:16:08 AM
http://activewin.com/mac/comments.asp?ThreadIndex=41770&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=458&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=12680&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=65448&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=17343&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=66377&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=7762&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=61243&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=36762&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=33234&Group=Last

#18 By 4240821 (109.94.218.82) at 11/2/2023 12:11:15 PM
http://activewin.com/mac/comments.asp?ThreadIndex=13528&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=26934&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=14028&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=84668&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=21160&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=75379&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=34351&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=40016&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=8309&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=18028&Group=Last

#19 By 4240821 (212.193.138.10) at 11/3/2023 1:00:46 PM
http://activewin.com/mac/comments.asp?ThreadIndex=25845&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=31270&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=40291&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=77905&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=64713&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=40550&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=34204&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=33306&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=53231&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=35597&Group=Last

#20 By 4240821 (109.94.216.41) at 11/5/2023 3:04:40 AM
https://hotslutss.bdsmlr.com/post/652135738
https://hotslutss.bdsmlr.com/post/649331972
https://hotslutss.bdsmlr.com/post/649207333
https://hotslutss.bdsmlr.com/post/652667523
https://hotslutss.bdsmlr.com/post/660221188
https://hotslutss.bdsmlr.com/post/656107733
https://hotslutss.bdsmlr.com/post/652613145
https://hotslutss.bdsmlr.com/post/656004923
https://hotslutss.bdsmlr.com/post/656138471
https://hotslutss.bdsmlr.com/post/659151134

#21 By 4240821 (92.119.163.194) at 11/5/2023 9:08:26 PM
https://printable-calendar.mn.co/members/19908169
https://printable-calendar.mn.co/members/19909169
https://printable-calendar.mn.co/members/19911418
https://printable-calendar.mn.co/members/19892636
https://printable-calendar.mn.co/members/19894768
https://printable-calendar.mn.co/members/19913394
https://printable-calendar.mn.co/members/19901106
https://printable-calendar.mn.co/members/19906976
https://printable-calendar.mn.co/members/19914922
https://printable-calendar.mn.co/members/19920182

#22 By 4240821 (62.76.146.75) at 11/8/2023 2:46:56 PM
https://www.hackerearth.com/@carsuscwonpers1986
https://www.hackerearth.com/@nalmeanetfpi1975
https://www.hackerearth.com/@conscremaben1985
https://www.hackerearth.com/@disreralcu1977
https://www.hackerearth.com/@asrhodgugfo1987
https://www.hackerearth.com/@banktogdacen1980
https://www.hackerearth.com/@tiotimacpulc1970
https://www.hackerearth.com/@oradraremp1984
https://www.hackerearth.com/@custanycwie1985
https://www.hackerearth.com/@quaaspelnalu1975

#23 By 4240821 (45.146.26.215) at 11/10/2023 1:33:12 PM
http://www.ttbizonline.com/pro/20231109162302
http://www.ttbizonline.com/pro/20231109180133
http://www.ttbizonline.com/pro/20231109141236
http://www.ttbizonline.com/pro/20231110011852
http://www.ttbizonline.com/pro/20231110021510
http://www.ttbizonline.com/pro/20231109105248
http://www.ttbizonline.com/pro/20231109065450
http://www.ttbizonline.com/pro/20231109083427
http://www.ttbizonline.com/pro/20231109170157
http://www.ttbizonline.com/pro/20231109061758

#24 By 4240821 (109.94.216.41) at 11/12/2023 12:36:46 AM
https://www.mddir.com/company/theagegapcouple-onlyfans-leak/
https://www.mddir.com/company/katherine2709-onlyfans-leaked/
https://www.mddir.com/company/bianca_ok-clips4sale-leaked/
https://www.mddir.com/company/evalynn-manyvids-leaked/
https://www.mddir.com/company/stoneyknight-onlyfans-leak/
https://www.mddir.com/company/houstonwhitegirl812-manyvids-leaked/
https://www.mddir.com/company/ohfuckclaire-onlyfans-leak/
https://www.mddir.com/company/merry-sparkletits-fansly-leaked/
https://www.mddir.com/company/kinkynatalia-manyvids-leaked/
https://www.mddir.com/company/acndbae-clips4sale-leaked/

#25 By 4240821 (194.190.178.141) at 11/12/2023 11:51:58 AM
https://instem.res.in/comment/reply/3347/720547
https://instem.res.in/comment/reply/2751/720482
https://instem.res.in/comment/reply/3622/720413
https://instem.res.in/comment/reply/2505/720427
https://instem.res.in/comment/reply/3225/720467
https://instem.res.in/comment/reply/2557/720344
https://instem.res.in/comment/reply/5405/720454
https://instem.res.in/comment/reply/2557/720379
https://instem.res.in/comment/reply/2557/720256
https://instem.res.in/comment/reply/3622/720533

Write Comment
Return to News
  Displaying 1 through 25 of 434
Last | Next
  The time now is 7:48:21 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *