Hackers step up search for unpatched servers

By Graeme Wearden, Special to ZDNet Asia
Thursday, January 06, 2005 10:41 AM
Network administrators who have failed to patch their systems against the Microsoft Windows Internet Naming Service vulnerability are now at much greater risk of attack.

The SANS Internet Storm Center warned Wednesday that it has detected a steep rise in probes directed at network ports handling Windows Internet Naming Service (WINS) services over the past several days. SANS believes this is a sign that the vulnerability is being exploited by malicious hackers.

"If you have not patched your WINS servers in your respective companies or campuses, beware. Patching these systems is now overdue," said SANS.

According to statistics gathered by the Research and Education Networking Information Sharing and Analysis Center, the increase in activity began on Thursday but became much greater on Saturday.

WINS, which is part of several Microsoft server products including NT 4.0 Server, Windows 2000 Server and Windows Server 2003, is used to identify the Internet Protocol addresses of specific computers on a network.

The flaw was first made public in November by security software maker Immunity. Microsoft then acknowledged that the WINS flaw could allow remote attacks to be launched against systems.

Graeme Wearden of ZDNet UK reported from London.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Migrating DHCP from Windows 2000 Server/Windows Server 2003 to Windows Server 2008

Windows Server

With a little bit of work, it's not hard to migrate DHCP services from Windows 2000 Server or Windows Server 2003 to Windows Server 2008. Here's how.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web