NEWS

Microsoft VPN flaw may open intranets to attack
By David Legard
September 27, 2002 5:25 am PT
A FLAW IN Microsoft's Point-to-Point Tunneling Protocol (PPTP) used to secure VPN (virtual private networks) leaves corporate intranets open to attack from outside, according to German IT
security company Phion Information Technologies.
In a
security advisory Thursday, Phion said that the Microsoft PPTP service shipping with
Windows 2000 and
Windows XP contains a remotely exploitable pre-authentication buffer overflow. This enables a specially crafted PPTP packet to overwrite kernel memory, such that a denial-of-service attack can lock up the
server. This has been verified on
Windows 2000 SP3 and
Windows XP, Phion said in the advisory.
Microsoft has not yet confirmed the flaw.
Phion said that VPN clients are also vulnerable as the PPTP service continually listens on an I/O port, making always-on DSL clients particularly vulnerable, Phion said.
Phion said that
Windows XP clients can be temporarily protected by firewalling the PPTP port in the Internet Connection Firewall. The company said it didn't know of any solution for
Windows 2000 and
Windows XP PPTP
servers.
David Legard is a Singapore correspondent for the IDG News Service, an InfoWorld affiliate.
SPONSORED WHITE PAPERS
EMC
- Lower costs and improve reliability-Get the EMC CLARiiON white paper!
Ciphertrust
- Are you ready for Sobig.G? Learn how to protect your email systems.
CDW
- Personal attention. CDW. The Right Technology. Right Away.
EMC
- Explore key performance features and capabilities of EMC ControlCenter 5.1.1.
Intel
- Free Intel white paper shows you how to deploy a secure wireless LAN
Cisco
- FREE WHITE PAPER: BLUEPRINT to design and implement secure VPNs
Verity, Inc.
- "Mass Consolidation Hits the Web-Search Market"
McDATA
- Download a FREE storage consolidation white paper from McDATA(R).
Lucent Technologies
- Overcoming Common Firewall Limitations
Lucent Technologies
- Leverage Your Mobile High Speed Data Access. Download Free White Paper!
Nokia
- Get the scoop! Mobilizing business white papers & case studies.
BMC Software
- Maximize the Potential of Enterprise Data: Free white paper!
Network Associates
- Free white paper - Strategies for Optimizing Network Costs and Benefits
Entrust
- Manage identities across applications. Improve productivity.
Stalker Software
- CommuniGate Pro - Transform your Email and Calendaring
Remedy
- A NEW Gartner Research Note:Producing Quality IT Services
Search the IDG White Paper Library:
|
SPONSORED LINKS
|