Advertisement
Home
Saturday, 22 November 2008
 
 
Last week attacks
O.S.  Defs.  %
Linux  8778  71.58%
Win 2003  1950  15.90%
Win 2000  722  5.89%
Solaris 9/10  402  3.28%
FreeBSD  226  1.84%
Other  185  1.51%

Total attacks: 12263 of which 4619 single ip and 7644 mass defacements

Polls
Should Zone-H continue mirroring defacements? (floods will be purged)
 
Main Menu
Home
Digital Warfare
Geopolitics
ITsec News
ITsec Advisories
Test Drive
360°
Digital Attacks Archive
Zone-H events
Publications
Zone-H Friends/Partners
Contact Us
Search
Download Area
Zone-H forum
About this website
Login Form





Lost Password?
No account yet? Register
ZONE-H In Numbers
 News: 14559
 Advisories: 11
 Administrators: 1
 Managers: 1
 Super Administrators: 3
 Operators: 3
 Registered Users: 38290
 Downloadable Files: 3888
 Digital Attacks: 2981160
 Attacks On Hold: 3153
 Online Users: 118
Syndicate
Visitors' Map
Highlight on most recent attacks
jiefanglu.gov.cn/zkn.txt by ZoRRoKiN       ytjj.gov.cn/zkn.txt by ZoRRoKiN       bislig.gov.ph by Ashiyane Digital Security Team       prefeiturajoseraydan.com.br by Fatal Error       semag.taquarussu.ms.gov.br by Fatal Error       pmsaltodolontra.com.br by Fatal Error       cmirituia.com.br by Fatal Error       pmriobrancodoivai.com.br by Fatal Error       prefeituraborrazopolis.com.br by Fatal Error       pmcurionopolis.com.br by Fatal Error       
Latest advisories
Latest on Digital Warfare
Latest on Geopolitics
New Windows DNS flaw exploited... and that's how you saw a defaced zone-h yesterday PDF Print E-mail
User Rating: / 8
PoorBest 
Friday, 13 April 2007

 Microsoft warned  yesterday about a security flaw, stll un-patched ,in some Windows verions. The flaw has been used by cyber prankster to launch attacks against computers provided with Windows OS. 

Specifically, Microsoft warned in a security advisory    that the attack exploits “a vulnerability in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server Service Pack 4, Windows Server 2003 Service Pack 1, and Windows Server 2003 Service Pack 2.”

Microsoft Windows 2000 Professional Service Pack 4, Windows XP Service Pack 2, and Windows Vista are not at risk since they  do not contain the vulnerable code.

This flaw was used yesterday to compromise a computer located on the same network segment of ours, within the C class assigned to us by the farming company (Elion - Estonia). Initially we thought about a kind of 0day effecting Zone-H's Apache's cache, but then digging a bit more we discovered that the attacker, by conquering such windows-based server, was able to arp-poison the whole network segment, injecting a defacing message in the transiting HTTP traffic.

So, technically no hacks into Zone-H but our visitors were receiving altered HTTP traffic, carrying the defacing code. The arp posioning attack was not 100% functional as it couldn't effect each and every packets (probably because Zone-H traffic was indeed too intense to be all poisoned), this is why by reloading Zone-H's homepage sometimes you were seeing the normal page and other times you were getting the defacer's message. Nothing we could do about it, perhaps the next time we will buy an entire network segment from a server farm...

According to Microsoft, the issue could be exploited in a limited number of cases. An attacker could exploit such vulnerability and to run code in the security context of Domain Name System Server Service, which by default runs as Local System.

This is a common type of coding problem  for Microsoft and Windows users: a successful attack will give full control over a vulnerable machine without any user interaction, Microsoft said.

 Microsoft also declared that a security patch will be soon provided to protect Windows users from this threat . Moreover, the company recommends affected users to apply for support to local Microsoft subsidiaries. 


Comments Index (Total Messages: 3)
xD Written by Guest on 2007-04-22 13:27:24
Killing Virus Written by Guest on 2007-04-22 21:55:29
  wtf?! Written by Guest on 2007-04-27 11:28:04

Powered by a Zone-H(ified) version of AkoComment 3.0!


DISCLAIMER: Forum postings are the opinion of the posting author alone, and should not be taken as the opinion of Zone-h. The   author is entirely and solely responsible for all content that he/she uploads, posts, or otherwise transmits via the website. Zone-h is not responsible for such content. However, Zone-h shall have the right, but not the obligation, to delete, move, or edit any content that violates this agreement or is otherwise objectionable as determined by Zone-h in its sole discretion and without notice.
 
< Prev   Next >
Advertisement
 
Top! Top!