Microsoft Update MS09-008 Fails To Protect Against Windows DNS AttacksBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
Internet security & monitoring for networks - Dld trial!   Get A Free iPod   Bookmark and Share 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
2009/12/24 0:00:00
2009/11/20 9:14:41
2009/11/20 9:14:41
2009/11/20 9:14:41
2009/11/20 9:14:41
Our Partners
Downloads
Windows Security : Microsoft Update MS09-008 Fails To Protect Against Windows DNS Attacks
Posted by Max on 2009/3/16 9:10:00 (940 reads)
Windows Security

Update MS09-008 was meant to patch windows DNS and WINS servers. The patch does not effectively protect against a vulnerability in DNS servers that could be exploited by cyber-crooks to redirect users to a malicious proxy. Cyber-crooks could monitor users' internet movements, access their confidential data and even redirect them to malicious web pages.


PandaLabs, Panda Security's malware analysis and detection laboratory, today issued a warning to Microsoft users that one of the company's latest security updates does not fix the vulnerability it was meant to patch. Update MS09-008, released yesterday by Microsoft, was designed to fix four vulnerabilities in Windows DNS server and WINS server. However, an unpatched flaw has been detected in the DNS server, more specifically in WPAD (Web Proxy Autodiscovery Protocol) registration. WPAD is a service that allows automatic detection of proxy settings without user intervention.

This vulnerability could be used to launch "man-in-the-middle" attacks on Windows DNS servers. Clients have to download WPAD entries from the DNS server, and those entries are ones that could be affected by the "man-in-the-middle" attack. An attacker that exploited this vulnerability successfully could redirect users' traffic through a malicious proxy. A proxy is a program or device widely used in companies to connect all computers in a network to the Internet through a single computer.

"If an attacker manages to redirect targeted users to a malicious proxy they could obtain private information, redirect them to malicious pages in order to infect them with malware or monitor their Internet movements, etc.," explains Luis Corrons, Technical Director of PandaLabs.

PandaLabs advises users who use these systems to be extra cautious and keep an eye on new Microsoft updates to patch this vulnerability as soon as possible.

About PandaLabs
Since 1990, its mission has been to detect and eliminate new threats as rapidly as possible to offer our clients maximum security. To do so, PandaLabs has an innovative automated system that analyzes and classifies thousands of new samples a day and returns automatic verdicts (malware or goodware). This system is the basis of collective intelligence, Panda Security's new security model which can even detect malware that has evaded other security solutions.

More information is available in the PandaLabs blog: http://www.pandalabs.com




Other articles
2009/11/3 14:55:39 - BitDefender Top Ten Malware Threats for October 09
2009/11/3 14:29:38 - Nov. 09 Microsoft Security Intelligence Report
2009/10/7 15:19:17 - StopSign AntiVirus and Anti-Malware is Windows 7 Compatible
2009/10/7 15:11:26 - New Outlook Backup and Migration Software By Disk Doctors
2009/9/30 4:20:57 - Microsoft Security Essentials, FREE Security Tool Just Released
2009/9/28 14:31:52 - New Rogue Antispyware Cloaked To Infects Computers
2009/9/9 4:31:49 - Trend Micro Proves Leadership in URL Filtering and Web Security
2009/9/9 4:16:20 - New Free Tool to Clean Conficker Once and For All
2009/9/1 8:37:11 - Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010 Out Now
2009/9/1 7:54:50 - NEW P2P Advertising Network Protects Users Against Lawsuits And Identity Theft

The comments are owned by the poster. We aren't responsible for their content.