Microsoft admits critical flaw in Server 2003

mancombseepgood

Executive Member
Joined
Jun 1, 2004
Messages
9,351
Reaction score
2
Location
.
http://WindowsSecrets.com/comp/080131
In a change from its earlier statements, Microsoft now reports that some versions of Windows Server 2003 have a security flaw rated "critical" rather than merely "important."

If you didn't install security bulletin MS08-001 after its release on Jan. 8 — because you didn't feel you really needed it when it first came out — you should make time now to test your box and install the patch.

In my opinion, all versions of Windows Server 2003, including Microsoft's Small Business Server 2003, should be considered potentially vulnerable. According to Microsoft, some versions of Windows 2000, XP, Vista, and the new Windows Home Server are also affected, but those machines should already have been notified of the patch by Automatic Updates, which would have installed MS08-001 if authorized to auto-update.

If your company uses Microsoft server software, I'll describe how you can tell whether your machine is at risk from Internet attacks — and how you can close the hole.

The vulnerability occurs if an "IP multicast group," which listens for IGMP (Internet Control Message Protocol) queries, is enabled.

Windows Server 2003 ordinarily enables only multicast group 244.0.0.1, which represents all the machines on your local subnet. ICMP queries to that group are ignored. As a result, such a server would be safe from this particular attack.

Various applications, however, can enable other ICMP queries, meaning that a machine is vulnerable to exploitation. For example, Small Business Server 2003, Microsoft's more-affordable version of Windows Server, includes Exchange Server 2003, which runs WINS (Windows Internet Naming Service). That, in turn, enables the kind of ICMP queries that are open to hackers.

To test whether a server is currently vulnerable, open a command prompt and enter the following command:

netsh int ip show joins

If any multicast group other than 244.0.0.1 is listed in the output of the command, the server is open to attack. (See Figure 1.) This vulnerability is eliminated by installing MS08-001.

Output of the netsh command
Figure 1. In this example, multicast groups other than 224.0.0.1 are running, making the affected server vulnerable to attack (if unpatched).

For more information, read the blog entry by Microsoft SVRD (Security Vulnerability Research & Defense) regarding the differences in multicast groups.

To download the patch, see security bulletin MS08-001. Microsoft modified this bulletin on Jan. 23 to acknowledge that SBS 2003 is vulnerable and then again on Jan. 25 to add Windows Home Server to the documentation. If you haven't applied the patch, do so now.
 
I think theres a mess up with the article its in fact a IGMP Vulnerability for the patch

IGMP = Internet Group Management Protocol

As far as i know its used for IP Multicasting
 
I think theres a mess up with the article its in fact a IGMP Vulnerability for the patch

IGMP = Internet Group Management Protocol

As far as i know its used for IP Multicasting

Yup, for managing multicast groups. IGMP would be correct.
 
Top
Sign up to the MyBroadband newsletter
X