Previous Posts


Parallels 4.0 Released

AVG Virus Scanner Removes Critical Windows File

Windows 2008 R2 Sneak Peak

5 new features of Windows 7

Remote Control 3.0 Released!

Reset your Office 2007 Serial number

SMB Vulnerablity Found - Emergency Patch

Remote Control RC6 - Public Beta

Enable file and printer sharing using group policy...

64 Bit VNC Server



Archives

May 2005

January 2006

April 2006

May 2006

June 2006

July 2006

September 2006

October 2006

November 2006

December 2006

January 2007

February 2007

March 2007

April 2007

May 2007

June 2007

July 2007

August 2007

September 2007

October 2007

November 2007

December 2007

January 2008

February 2008

March 2008

April 2008

May 2008

June 2008

July 2008

August 2008

September 2008

October 2008

November 2008



Subscribe to our Feed:






The security hole that took 7 years to patch

If you like this article, then sign up for our email newsletter to get more like it every day in your inbox

Microsoft has recently released patch MS08-068 - Another SMB remote code execution bug. It allows anyone who exploits the flaw to take control of that computer. If you have not gotten the patch yet - I would get it as soon as you can.

The disturbing part is that Microsoft knew about this flaw as far back as 2001. According to Microsoft, they held back on releasing a fix because it would immediately break many applications that require SMB signing. For example, on the MSRC blog, a Microsoft employee states:

...the impact would have been to render many (or nearly all) customers network-based applications then inoperable. For instance, an Outlook 2000 client wouldnt have been able to communicate with an Exchange 2000 server. We did say that customers who were concerned about this issue could use SMB signing as an effective mitigation...

I could buy that. IF IT ONLY AFFECTED WINDOWS XP. But the bug in question also affects Vista, 2008, and 64 bit releases. Many applications were simply broken with the release of Vista. Why not just allow them to break and keep them secure? And why does it take 7 years to figure out this application compatible work around?

In our remote programs, like remote reboot, or remote desktop enabler, we need to use 4 different methods to authenticate via SMB with a remote host...to cover all of the versions of Windows. Now I can understand why this is the case! Because the SMB server in windows is a spaghetti code mess that probably has 10 more security holes the hackers already know about, Microsoft knows about, but still has not found a fix for them yet!

Sorry for the rant, but if you do have an internet facing machine I suggest disabling file and printer sharing, and make double sure these ports are firewalled.


Posted By: Steve Wiseman on Thursday, November 13, 2008

Check out our utilities for windows

 



Copyright © IntelliAdmin, LLC, 2008. All Rights Reserved