IT Management Begins With Security
SecurityProNews > News > IT News > A BB Hole In Windows
Search:
[ news_it_news ]

A BB Hole In Windows



John Stith
Staff Writer
2005-07-19

SecurityProNews: News RSS Feed Security News RSS Feed


Microsoft announced the a vulnerability in some of their products in the Remote Desktop Services (RDS). The vulnerability comes in Windows 2000, 2003, and XP. The RDS is only enabled on the Windows XP Media Center Edition but it's present in the all the other versions.

The vulnerability takes the form of denial service that could allow an attacker to send a crafted Remote Desktop Protocol (RDP) request to a system. Microsoft determined that hackers couldn't take control of one's system, they'd just annoy the devil out of you. The most that could happen would be that the hackers could force your system to reboot.
A BB Hole In Windows


Tom Ferris over at Security Protocols discovered the problem back in early May. He advised Microsoft of the vulnerability and their procedure is to test it out thorougly. Then they issue an alert.

RDP allows users to access Windows remotely but because of the way Windows runs the remote desktop, an attacker could punch through and pop your computer a black eye.

Not to worry too much though because it would only work in very specific circumstances though. First, it would have to be enabled, which it's not unless you have the XP Media Center Edition. Then the port would have to be accessible for folks who also want to crash your computer for some reason. Finally, if you have up a firewall, then this isn't even going to be an issue really because in most cases, firewalls will block it completely.

Microsoft is working on a patch but in the meantime, they recommend blocking TCP port 3389 on their firewall, disable terminal services or the remote desktop feature, secure remote desktop connections by using IPsec policy and by employing a virtual private network connection.







About the Author:
John is a staff writer for SecurityProNews covering cyber security.

More news_it_news Articles

SecurityProNews: News RSS Feed Security News RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds