Ziff Davis Internet
News & Resources for the IT Reseller
NewsReviewsTech AnalysisCommentarySecurityLinux/Unix
My Account |  

Bugs, Exploits Dog XP SP2
By Larry Seltzer


Microsoft Corp. has issued a hotfix for Windows XP Service Pack 2 to solve a problem about which many users have complained: programs that attempt to connect to loopback addresses other than 127.0.0.1 get error messages.

ADVERTISEMENT

The problem—one of several that have appeared in the newly released SP 2—has been reported by many VPN users since Microsoft introduced the second release candidate in June. However, since it is a hotfix, it is not fully supported. It is expected that Microsoft will issue a more permanent fix in the future.

Meanwhile, security researchers are reporting a new vulnerability in SP2 that could allow a malicious Web site to deposit an attack program on a user’s system.

The attack utilizes Internet Explorer’s drag-and-drop features and the Windows “shell folders” to copy an executable from a malicious Web site to a user’s startup folder, from which it would execute the next time the user logged on. The researcher who reported the problem to security mailing lists provided proof-of-concept code that leaves a file named “malware.exe” in the user’s startup folder.

PointerClick here to read more about Internet Explorer’s security woes.

The report was echoed by Secunia, a security consulting firm. Secunia asserts that the attack also works on a fully patched Windows XP Service Pack 1 system, and that the drag-and-drop approach could be replaced with a single click.

eWEEK Special Report: Securing Windows

The vulnerability is related but not identical to a series of others patched by Microsoft in pre-SP2 versions of Windows. Those vulnerabilities allowed attackers to run code directly in the context of the shell folders and therefore the browser’s My Computer zone. This new attack simply writes a file in the shell folder.

For the attack to succeed, the user would have to visit a Web page that hosted it and follow the instructions. Any attack code deposited would be scanned by anti-virus software on the user’s computer.

Microsoft officials were not immediately available to comment on the reports.

PointerCheck out eWEEK.com’s Security Center for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzer’s Weblog.

horizontal rule

Be sure to add our eWEEK.com developer and Web services news feed to your RSS newsreader or My Yahoo page

     
Email


TALKBACK

MICROSOFT RESOURCE CENTER
Free Hands-On Training Lab
Find out how key features of SBS 2003 can help you open up a new line of revenue. Register now >>


SBS 2003 Sales Reference Card
This handy reference card contains features at a glance, sales objection handling, pricing guidelines & more. Get it now >>


Microsoft Empower for ISVs rewards your big idea with big benefits and support.
Access key development tools at a low cost to help you develop that idea into an innovative application. Learn more >>




 
FREE WHITE PAPER
Changing Business for the Better: A Practical Guide to BPM


This paper provides an overview of the benefits of BPM technologies and identifies the characteristics of BPM solutions that lead to successful BPM process-centric integration projects.


Download this free white paper to learn more!


>> brought to you by IBM

Attention Microsoft Solution Providers!



Want to gain a competitive edge? Try Microsoft Watch – FREE!



Each week you receive:
  • Microsoft News and Insider Information
  • Expert Analysis
  • Code Names of Upcoming MS Products
  • Year-Ahead Calendar, updated monthly



    Click Here to sign up now for your FREE 14 Day Trial to Microsoft Watch.
  •  
  • Add up to $1,200 of value with the new BONUS PACKS.
  • HP PartnerONE: The key to increasing your margins.
  • HP Compaq nc6129 Business Notebook. $1149 Smart Buy
  • HP xw8200 workstation. Smart Buy price $1549.
  • ProLiant DL360G4p server: HP Smart Buy price $1647
  • Microsoft files new anti-piracy lawsuits. Learn more.
  • New offers with Windows Genuine Advantage.


  • POPULAR TOPICS
    CHANNEL INSIDER BUYER’S GUIDE
    •Catalog Publishing
    •Dealer Management
    •Order Configuration
    •Price Management
    •Sales Management

    View All >

    CAREER CENTER
    Search the jobs you want & get the info you need – post your resume here today!

    Powered by Dice
    SPECIAL REPORTS
    White Boxes
    MS vs. IBM
    Linux in the Channel
    Network
    CHANNEL RSS FEED
    Stay in the Zone
    Put The Channel Insider on your desktop.
    FREE NEWSLETTERS
    Subscribe to The Channel Insider: Channel News, Reviews, Resources and more.

    Make your selections below:


    Contract Watch

    The Channel Insider Update

    Preferred e-mail format:

    Enter your e-mail:


    view all newsletters >>
    Channel Insider Quick Links
    Ziff Davis Footer Logo