Computerworld
Microsoft plugs nine holes in Windows, DNS, SQL
It's among the vendors patching a multiplatform DNS vulnerability
Gregg Keizer  09 July, 2008 08:07

Microsoft Tuesday patched nine vulnerabilities in Windows, Exchange, SQL Server and the company's Domain Name System (DNS) server and client software.

All nine flaws were rated "important" by Microsoft, the second-highest threat rating in the company's four-step scoring system.

One of the Microsoft fixes for Windows DNS was part of a group of patches issued Tuesday by software vendors to plug a multi-platform hole. The researcher who uncovered the vulnerability called the group patch effort the "largest synchronized security update in the history of the Internet."

Microsoft patched its iterations of DNS in MS08-037, the security bulletin that called out two DNS bugs in every supported version of Windows except Vista.

"We've had four updates to Microsoft's DNS since 2007 -- and one led to a bot, Rinbot, in April 2007," noted Andrew Storms, director of security operations at nCircle Network Security.

Storms was referring to the episode last year when researchers spotted then-new variants of Rinbot exploiting a zero-day flaw in Windows DNS Server Service. The most recent patch for Windows DNS was released as MS08-020 in April, part of that month's eight-update, 10-fix batch of updates.

The fix for the DNS cache poisoning vulnerability, which Dan Kaminsky, a noted researcher and director of penetration testing with US-based IOActive, reported to Microsoft, is part of a larger, coordinated rollout Tuesday. Internet Software Consortium (ISC) has also updated its popular open-source BIND DNS software, which vendors like Red Hat and Sun Microsystems will be pushing to their users Tuesday.

"This is pretty bad, pretty bad," said Kaminsky. "I wish I could go into full detail, but ..."

Kaminsky, who held a news conference Tuesday with Jerry Dixon, former director of the national Cyber Security Division at the US Department of Homeland Security, to discuss the DNS cache poisoning bug, said he would withhold specifics of the vulnerability for about a month. He plans to present his findings at the Black Hat security conference, which runs August 2-7 in Las Vegas.

"But look at how many people have worked this entire year to make this happen," Kaminsky hinted. "This is not your every-day vulnerability. There are vulnerabilities and then there are vulnerabilities. But that doesn't mean you panic."

He predicted that exploits will be crafted for the DNS flaw. "I don't think this will survive reverse engineering."

Storms of nCircle put it into perspective. "A reliable DNS cache exploit means that the probability of redirecting an unsuspecting user to a malicious website has just increased dramatically," he said, urging users -- enterprise administrators in particular -- to install the patch pronto. "Every network administrator in the world needs to drop that iPhone, get off their BlackBerry and patch their DNS now."

Computerworld Buyer's Guide - Vendors Matched to this Article

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Newsletter Subscription
Sign up for our Computerworld newsletters!
Syndicate content
 

Computerworld Webinar

Thursday, June 11th, 2009
10:30am EST (Sydney, Australia)
Screening at your PC

Computerworld is hosting a 30 minute live webinar to help you to learn how unified communications can save you money, foster innovation and business agility by making it easier for people to find, reach and collaborate with one another.

Register Now

Computerworld Community Comments
Whitepaper

Customer Experience Management: Improving the Consistency and Quality of Customer Interactions

Don't let your customers have a bad experience. Customer experience management (CEM) research from Ventana highlights the failures of traditional CRM and indicates many companies are hearing the message, but few have implemented the processes and technology to make it a reality. Download the report today!

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links
 
Send Us E-mail | Privacy Policy
Features List | Media Kit | Advertising | Contact Us

Copyright 2009 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.