Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Microsoft virtualization tools reinforce user's data center plans
Air traffic network glitch cleared-up for now
Cisco buys into e-mail with $215 million PostPath acquisition
Locked iPhones can be unlocked without a password
Baseball's video and secure telephone links ready for instant replay
China aims for petaflop computer in 2010
Mozilla garners praise over Firefox security feature
Mt. Sinai Medical Center looks to open standards for patient smartcards
Immersion to pay Microsoft $20 million to settle patent suit
Expand Networks secures $8.5 million in venture capital
Alcatel-Lucent intros Gigabit Ethernet switches
Storage market thrives in down economy
Hosted RFID service targets mobile users
Best Western downplays data breach
Google drops Bluetooth, GTalkService APIs from Android 1.0
Security /

Microsoft patches another Telnet flaw in Win 2000

Related linksToday's breaking news
Send to a friendFeedback


If you don't succeed the first seven times, try, try (and try some more) again. That seems to be the lesson Friday, as Microsoft acknowledged new vulnerabilities in the Telnet code included in Windows 2000, eight months after issuing a patch that fixed seven other security holes in Windows 2000's Telnet.

A buffer overflow attack - an attack in which the amount of memory allotted to an application is overrun - against the Telnet service could cause a denial of service, or in some cases, allow the attacker to run any code they wanted in Win 2000 or Interix 2.2, Microsoft said in its alert. Telnet is a common line program often used for remote access to systems. Interix is a program that allows users to run Unix applications in Win 2000. Microsoft has issued a patch that fixes the problem in both applications.

The security hole does have some mitigating features, however, that could minimize its impact, the company said. First, if attack code is run, it will only run with the level of permission given to the Telnet service. Second, Telnet is not turned on by default in Win 2000 and would have to be turned on to make a system vulnerable. Finally, Telnet is not installed by default in Interix and would have to be intentionally installed to make a system vulnerable.

Advertisement:

In June 2000, Microsoft issued a patch that plugged seven security holes in Windows 2000's Telnet service, including serious holes that could have led to denial-of-service attacks.

The IDG News Service is a Network World affiliate.

RELATED LINKS


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.