Serious Windows security hole + Microsoft unable to distribute patches

"Bjorn Stabell" <[email protected]>
Newsgroups gmane.org.user-groups.linux.beijing
Message-ID <[email protected]>
First of all there a very serious security hole in Windows' SSL that
makes it possible for people to take control over the machine remotely;
this affects all secure Windows 2000 and NT4 sites (45% of all SSL
servers!), including banking sites!  Talk about critcial!
 
Secondly, it seems Digital Island's content distribution network is not
up to the task to distribute the patches quickly enough.  Microsoft
picked them because Akamai, who it used successfully before, was running
Linux on their edge servers!
 
Anyways, this is what it looks like to me...
 
-----Original Message-----
From: announce-zZVC6C/48Tk8cXGXCPjTtAC/[email protected] [mailto:[email protected]] 
Sent: Thursday, April 15, 2004 01:06
To: Bjorn Stabell
Subject: Netcraft News - Wednesday, April 14, 2004





 <http://news.netcraft.com/> Netcraft 

 <http://www.netcraft.com/security/dsm.html> 
 Site Search



Webserver Search
What's that site running?...    
Example: .microsoft.com
<http://www.netcraft.com/?restriction=site+ends+with&host=.microsoft.com
> 
Example: www.netcraft.com
<http://uptime.netcraft.com/up/graph?site=www.netcraft.com&mode_w=on>  
RSS feed <http://news.netcraft.com/index.rdf> 


 

Netcraft Services
Internet Exploration
Whats that site  <http://www.netcraft.com/whats> running?
Search  <http://www.netcraft.com/?host> Web by Domain
Sites on the Move <http://uptime.netcraft.com/netmove/today> 


Internet Data Mining
Hosting Provider Switching Analysis
<http://news.netcraft.com/archives/2003/06/18/hosting_provider_switching
_analysis_available.html> 
Hosting Provider Server Count
<http://news.netcraft.com/archives/2003/04/14/netcraft_hosting_provider_
server_count_available.html> 
Hosting Reseller Survey
<http://news.netcraft.com/archives/2003/05/10/site_operator_survey.html>

SSL Survey
<http://news.netcraft.com/archives/2003/04/09/netcraft_ssl_survey.html> 
Web Server Survey  <http://www.netcraft.com/survey/archive.html> Archive


Performance
MyDoom  <http://uptime.netcraft.com/perf/reports/sco-alert-DpHT0TjK6O9Wk0Htik3J/[email protected]>
Sites
Hosting Prospects Performance Alerts
<http://news.netcraft.com/archives/2003/08/26/hosting_prospect_monitorin
g_and_outage_alerting.html> 
Hosting  <http://uptime.netcraft.com/perf/reports/Hosters> Providers
Network Performance
Dedicated Server Monitoring
<http://news.netcraft.com/archives/2003/01/01/dedicated_server_monitorin
g.html> 


Security
Bank Fraud Detection
<http://news.netcraft.com/archives/2004/01/02/phishing_identity_theft_an
d_banking_fraud_detection.html> 
Automated Security Testing
<http://news.netcraft.com/archives/2003/01/01/automated_security_testing
.html> 
Dedicated Server Monitoring
<http://news.netcraft.com/archives/2003/01/01/dedicated_server_monitorin
g.html> 
Web Application Testing
<http://news.netcraft.com/archives/2003/01/01/ecommerce_security_testing
.html> & Site Audits
Security Services FAQ
<http://news.netcraft.com/archives/2003/01/01/security_service_faq.html>



Advertising
Banner Advertising on Netcraft
<http://news.netcraft.com/archives/banner_advertising.html> 


About Netcraft
About Netcraft
<http://news.netcraft.com/archives/2003/01/01/about_netcraft.html> 
Jobs at Netcraft
<http://news.netcraft.com/archives/2004/03/15/software_development_oppor
tunities_at_netcraft.html> 
Fair Use, Copyright
<http://news.netcraft.com/archives/2003/01/01/fair_use_copyright.html> 
Site Privacy Statement
<http://news.netcraft.com/archives/2003/01/01/privacy_statement.html> 
Visiting Netcraft
<http://news.netcraft.com/archives/2003/01/01/visiting_netcraft.html> 


Contact Us
Webmaster <mailto:webmaster-DpHT0TjK6O9Wk0Htik3J/[email protected]> 

Categories
About Netcraft <http://news.netcraft.com/archives/about_netcraft.html> 
Around the Net <http://news.netcraft.com/archives/around_the_net.html> 
Banner Advertising
<http://news.netcraft.com/archives/banner_advertising.html> 
Dogfood <http://news.netcraft.com/archives/dogfood.html> 
Hosting <http://news.netcraft.com/archives/hosting.html> 
Netcraft Services
<http://news.netcraft.com/archives/netcraft_services.html> 
Performance <http://news.netcraft.com/archives/performance.html> 
Security <http://news.netcraft.com/archives/security.html> 
Web Server Survey
<http://news.netcraft.com/archives/web_server_survey.html> 
Full  <http://news.netcraft.com/fullindex.html> Index

Dates
April 2004 <http://news.netcraft.com/archives/2004/04/index.html> 
March 2004 <http://news.netcraft.com/archives/2004/03/index.html> 
February 2004 <http://news.netcraft.com/archives/2004/02/index.html> 
January 2004 <http://news.netcraft.com/archives/2004/01/index.html> 
December 2003 <http://news.netcraft.com/archives/2003/12/index.html> 
November 2003 <http://news.netcraft.com/archives/2003/11/index.html> 
October 2003 <http://news.netcraft.com/archives/2003/10/index.html> 
September 2003 <http://news.netcraft.com/archives/2003/09/index.html> 
August 2003 <http://news.netcraft.com/archives/2003/08/index.html> 
July 2003 <http://news.netcraft.com/archives/2003/07/index.html> 
June 2003 <http://news.netcraft.com/archives/2003/06/index.html> 
May 2003 <http://news.netcraft.com/archives/2003/05/index.html> 
April 2003 <http://news.netcraft.com/archives/2003/04/index.html> 
March 2003 <http://news.netcraft.com/archives/2003/03/index.html> 
February 2003 <http://news.netcraft.com/archives/2003/02/index.html> 
January 2003 <http://news.netcraft.com/archives/2003/01/index.html> 
September 2002 <http://news.netcraft.com/archives/2002/09/index.html> 
March 2002 <http://news.netcraft.com/archives/2002/03/index.html> 

Windows Update struggling to remain available
<http://news.netcraft.com/archives/2004/04/14/windows_update_struggling_
to_remain_available.html> 	 Performance
<http://news.netcraft.com/archives/performance.html>  	

Microsoft's Windows  <http://windowsupdate.microsoft.com> Update web
site has been experiencing slow
<http://uptime.netcraft.com/perf/graph?site=v4.windowsupdate.microsoft.c
om%2fen%2fdefault.asp&range=86400&collector=all> response times in the
wake of yesterday's release of critical security updates. A browser
request through Internet Explorer eventually raises the site after an
extended wait, and in some cases it is possible to successfully download
and install updates over a broadband connection. Dynamically updating
performance charts for Windows Update are available here
<http://uptime.netcraft.com/perf/graph?site=v4.windowsupdate.microsoft.c
om%2fen%2fdefault.asp&range=86400&collector=all> . 


The service is struggling for availability at a crucial moment of need
for Windows users. Microsoft yesterday released four
<http://www.microsoft.com/security/security_bulletins/200404_windows.asp
> security updates, including three critical patches that Microsoft
urged customers to install immediately. They include a patch for an SSL
<http://news.netcraft.com/archives/2004/04/14/microsoft_ssl_vulnerabilit
y_gives_attackers_opportunity_to_gain_control_of_leading_banking_sites.h
tml> vulnerability that leaves Windows 2000 and NT4 SSL sites open to
remote compromise. The current sluggish performance of Windows Update is
a particular challenge for Windows users ondial-up Internet connections,
as the Windows XP download is 3 megabytes.

The DNS for windowsupdate.microsoft.com is managed by Savvis
Communications, which runs the former Digital Island content
distribution network (CDN) it acquired from Cable & Wireless earlier
this year. CDNs help manage Internet traffic (including DDoS attacks) by
using large, geographically distributed networks of servers to move
files closer to the end user. Microsoft used a CDN service from Akamai
to keep its web site online last August, when the Blaster worm
programmed machines to launch a DDoS on the Windows Update site.
Microsoft's strategy drew considerable attention, as the front page of
the www.microsoft.com site was served
<http://news.netcraft.com/archives/2003/08/17/wwwmicrosoftcom_runs_linux
_up_to_a_point_.html> by Linux machines on Akamai's network. Savvis is
using Windows
<http://uptime.netcraft.com/up/graph?site=windowsupdate.microsoft.nsatc.
net> Server 2003 to manage the Windows Update traffic.

Posted by Rich Miller at 03:04 PM UTC on Apr 14, 2004 in Performance
<http://news.netcraft.com/archives/performance.html>  | Link to this
article
<http://news.netcraft.com/archives/2004/04/14/windows_update_struggling_
to_remain_available.html>  | Subscribe
<http://www.netcraft.com/cgi-bin/Survey/subscription>  
Microsoft SSL Vulnerability gives attackers opportunity
<http://news.netcraft.com/archives/2004/04/14/microsoft_ssl_vulnerabilit
y_gives_attackers_opportunity_to_gain_control_of_leading_banking_sites.h
tml> to gain control of leading banking sites	 Security
<http://news.netcraft.com/archives/security.html>  	

Microsoft has issued a fix for a security vulnerability that has exposed
tens of thousands of sites offering encrypted transactions to potential
compromise. The bug in Microsoft's Secure Sockets Layer (SSL) library
allows remote attackers to gain control of unpatched Windows 2000 and
Windows NT4 servers offering encrypted services over the internet. 


The vulnerability was revealed Tuesday by Internet Security
<http://xforce.iss.net/xforce/alerts/id/168> Systems, which warned that
"hackers will aggressively target this vulnerability given the
high-value nature of Web sites protected by SSL," which secures web
sites for online banking, stock trading and retailing. Microsoft issued
a critical
<http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx>
security update Wednesday to address the vulnerability, which allows a
buffer overflow in Private Communications Transport (PCT) packets. "An
attacker who successfully exploited this vulnerability could take
complete control of an affected system," Microsoft said in its advisory,
adding that "only systems that have SSL enabled" are vulnerable. SSL is
only commonly used protocol for encrypted transactions of financially
important or confidential information on the Web.

More than 132,000 web-facing SSL servers are running either Windows 2000
or Windows NT4, according to our March Secure
<http://news.netcraft.com/archives/2003/04/09/netcraft_ssl_survey.html>
Server Survey, representing nearly 45 percent of all SSL servers. The
PCT and SSL 2.0 protocols targeted by the exploit are enabled by default
in Win2K and NT4.

More...
<http://news.netcraft.com/archives/2004/04/14/microsoft_ssl_vulnerabilit
y_gives_attackers_opportunity_to_gain_control_of_leading_banking_sites.h
tml> 
Posted by Rich Miller at 04:15 AM UTC on Apr 14, 2004 in Security
<http://news.netcraft.com/archives/security.html>  | Link to this
article
<http://news.netcraft.com/archives/2004/04/14/microsoft_ssl_vulnerabilit
y_gives_attackers_opportunity_to_gain_control_of_leading_banking_sites.h
tml>  | Subscribe <http://www.netcraft.com/cgi-bin/Survey/subscription>

 
<http://news.netcraft.com/archives/2003/01/01/automated_security_testing
.html> 

Copyright (c) Netcraft Ltd 2004


Subscription Details

To Subscribe: Send SUBSCRIBE webserver-survey to majordomo-DpHT0TjK6O9Wk0Htik3J/[email protected]
<mailto:majordomo-DpHT0TjK6O9Wk0Htik3J/[email protected]?subject=Subscribe&body=SUBSCRIBE
webserver-survey> 
To Unsubscribe: Send UNSUBSCRIBE webserver-survey to
majordomo-DpHT0TjK6O9Wk0Htik3J/[email protected]
<mailto:majordomo-DpHT0TjK6O9Wk0Htik3J/[email protected]?subject=Unsubscribe&body=UNSUBSCRIBE
webserver-survey>

_______________________________________________
blug-general list
[email protected]
http://list.beijinglug.org/cgi-bin/mailman/listinfo/blug-general
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.