Microsoft has released a patch for the hole in 2000 and Windows Server 2003 and 2008 that could allow an attacker to redirect network traffic to a malicious site that has been set to act as a proxy.
Vulnerability, the value of critical by Microsoft, allows IT managers to set the Windows Proxy Auto-Discovery, or WPAD, entry in DNS. If IE or Firefox is configured to automatically detect settings, "the browser will be connected to a computer proxy.
This is a useful feature for companies that want to set their own proxy servers and to monitor employees' Web use for security purposes. But also can be used for a man-in-the-middle type of attack if the outside is able to set the WPAD entry through dynamic DNS update so that traffic is diverted to the IP address dangerous.
The patch solves the problem for systems without a WPAD entry in DNS, by request to block the WPAD for the future. But for the WPAD entry system, the patch did not do anything.
IT managers who install the patch can provide a false sense of security that compromised the system has been set, "said Tyler Reguly, the security research engineer at nCircle, who contacted Microsoft and write a blog post about his concerns with the same night that Microsoft released the update.
In a blog post the next day, Reguly said a Microsoft representative to select him to leave the companies that have touched the WPAD entry is not possible to distinguish legitimate WPAD entries from that taken by an attacker.
But at least Microsoft could have included a pop-up message in the example, the user has a warning that the WPAD DNS entry, and even ask if they want to save or block it, Reguly said.
"I understand the need to maintain the function, but not at the cost of sweeping security issues under the rug," he wrote.
Answers to this problem, Microsoft issued a more detailed technical note on the update on Friday said that the company will not interfere with the function and choose not to violate any risk administrator configuration on the likelihood that the WPAD is not valid, even if it means that an attack will continue to apply.
"This scenario is not a security update, or security update released by Microsoft aims to address," said Microsoft notes. "Security update is intended to help protect the system against the exploitation of the future, and does not aim to cancel any of the attacks have occurred in the past."
Notes and then give instructions for how an administrator can validate the IP address assigned to the WPAD entry in DNS.
In an interview on Friday, Reguly still disappointed with Microsoft and implemented to correct the problem.
"They can be done to reduce the things the fact that they prefer the security function," he said. "They can also change DNS so that you can not update the WPAD dynamic."
Saturday, March 14, 2009
Microsoft, researcher spar over security patch
Related Posts:
Intel chip flaw--but what of it?Intel chip bug? Or simply much more than you need to know? Researchers claim Intel has a serious chip bug. But that all depends.Security experts who are into the arcana of chip security may find "CPU cache poisoning" riveting… Read More
Smoking hazardsMaybe you already know that cigarette smoke suck other people near you more dangerous for you than for the smokers themselves. Home is smoke smoke that cigarette terhisap directly into the lungs in smokers hembuskan again. Si… Read More
the most secure browser "GOOGLE CRHOME"Race to see which browser is most secure in the case of securities that have not yet ended. But it seems Google Chrome already on winning positions.Last week, the hackers are invited to attend the CanSecWest security conferen… Read More
Facebook mulling a branded smartphoneFacebook denied a story published this weekend that says the company is "building a mobile phone," but mehas confirmed that the social-networking giant has reached out to hardware manufacturers and carriers seeking input o… Read More
Internet sales tax proposalAmazon.com has said that Jeremy Bray To affiliate program to provide small payments to refer customers, for all people in the state of Colorado. The reason? A state law, which Democratic Gov. Bill Ritter signed last week, sla… Read More
0 comments:
Post a Comment