The Active Network
ActiveWin Anonymous | Create a User | Reviews | News | Forums | Advertise | VBA in Excel | Users Online: 0  
 

neowin.net

Amazon.com

  *  

  Hackers Sniffing For Vulnerable Microsoft Servers
Time: 17:21 EST/22:21 GMT | News Source: InformationWeek | Posted By: Chris Hedlund

A vulnerability within Microsoft's WINS (Windows Internet Naming Service), a component of popular server software such as Windows Server 2003, has been heavily exploited since the last day of 2004. A vulnerability within Microsoft's WINS (Windows Internet Naming Service), a component of popular server software such as Windows Server 2003, has been heavily exploited since the last day of 2004, several security organizations reported Tuesday.

Read Only Comments
Return to News
  Displaying Comments 1 through 4 of 4
  This is an archived static copy of ActiveWin.com.
#1 By 17807 (216.160.190.241) at Wednesday, January 05, 2005 10:17:26 PM
whoa!!! since last year!!! holy crap how long does it take to get a patch around here??? ;)

#2 By 17807 (216.160.190.241) at Thursday, January 06, 2005 12:43:43 AM
I was being facetious http://dictionary.reference.com/search?q=facetious note the wink at the end of my post...

#3 By 9589 (68.17.52.2) at Thursday, January 06, 2005 10:55:51 AM
While WINS is indeed a part of Windows Server 2003, it just is not necessary. Unless you are still using Windows NT 4.0 on your network and some 16-bit applications that depend on WINS, it is not necessary to employ WINS. Microsoft has been discouraging its use since Windows 2000.

Notwithstanding the patch for this vulnearbility being out for nearly a month, who would have TCP and UDP ports 42 on their firewall anyway? This is just as absurd as those that had left open the vulnearable port that exploited a flaw in SQL Server several years ago.

By the way, the article starts out by saying that this vulnearbility "has been heavily exploited." Then we learn later in the article that, "have seen a drastic increase in the number of probes directed at WINS services (TCP and UDP ports 42)." Someone tell the writers at Information Week that there is a distinct difference between exploitation and probing.

Must be all that positive news that Microsoft is generating for itself coming out of the CES.

#4 By 9589 (68.17.52.2) at Thursday, January 06, 2005 05:12:22 PM
#9 The last time that Google provided the statistics that Parkker mentioned is June 2004. The link is at: http://www.google.com/press/zeitgeist/zeitgeist-jun04.html .

Frankly, it makes *nix looks pitiful - nothing new to that!

#10 Sorry, but should you happen to get a copy or pay for it ($1800), Netcraft's SSL Server Survey shows that over 60% of the Internet sites that use SSL (in other words one's that actually make money not Muddle's www.LAMPrunstheInternet.com" site) use Microsoft IIS. Likewise, every year Microsoft's share of servers sold, as reported by IDC, that use the Windows operating system has grown - it is now over 60% as well.

But, hey, Muddle, you keep on believing it and spewing it and maybe it will become reality! lol



 

  *  
  *   *
 
replica watches