Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Microsoft says it would deal with new Yahoo board
Diary of a deliberately spammed housewife
Microsoft SharePoint popularity comes with issues
Report: Tech giants forming 'patent troll' alliance
Microsoft readies new try for Yahoo
Trojan lurks, waiting to steal admin passwords
Alliance to promote Windows-managed Macs in enterprise
California enacts cell-phone driving ban
Autonomy, Endeca rate among top enterprise search vendors
Gartner: Seven cloud-computing security risks
Barracuda countersues Trend Micro in patent case
When networks fail, hams to the rescue
IBM mainframe acquisition raises antitrust concerns
Mozilla's Firefox 3 sets geeky world record
Lockheed Martin gets $89 million to converge DoD distribution networks
Clothes don't make this man: Sweatshirt helps nail Citibank card scammer
/

Vulnerability in Netscape Servers Revealed

Today's breaking news
Send to a friendFeedback

Advertisement:

InfoWorld, 08/26/99

A bug that allows hackers to gain illicit access to the Netscape Enterprise Server and Netscape FastTrack Server, has been discovered by Internet Security Systems Inc. (ISS) and its research team, the X-Force.

The vulnerability in both Netscape Communications Corp.'s servers uses a well-known hacker technique-called buffer overflow-to overload a server and then allows the hacker to overwrite the systems stack and gain access. The attack takes the form of an overly long HTTP GET request, according to ISS and X-Force.

"The fact that it's a remote buffer overflow attack means that an attacker can exploit the vulnerability and remotely upload and execute arbitrary assembly language. An attacker can write an exploit to get the computer to do what ever they want," said Chris Rouland, director of the X-Force, a intrusion-detection research team within ISS. "Users of Netscape (Enterprise and FastTrack Servers) have to patch those systems to protect themselves from this attack."

Netscape and ISS have collaborated to create a fix for the bug, in the form of the Enterprise 3.6 SP 2 SSL Handshake fix. It is available from Netscape at http://www.iplanet.com/downloads/patches/detail_12_86.html.

Separately, Netscape yesterday announced an encryption and security upgrade for Netscape Communicator 4.61 for use with Internet commerce sites, which is easier to download.

While previously Netscape users would be required to download a full version of the browser to upgrade their level of encryption, the SmartUpdate service-at http://home.netscape.com/smartupdate-requires only a 36KBps file to provide 56-bit U.S. internationally exportable encryption or 128-bit U.S.-grade encryption.

Currently, 128-bit encryption is believed to be unbreakable, and 56-bit is the maximum the U.S. government will allow to be exported internationally due to security concerns.

InfoWorld This story from Infoworld.com Copyright © 1999 InfoWorld Media Group, Inc.


RELATED LINKS


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.