Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


November 11, 2004

Update: Ten New Security Holes in Windows XP SP2?

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Ten new security holes in Windows XP Service Pack 2 have been discovered, so get ready to insert new patches into your patch management schedule. Microsoft recently announced their Security Bulletin Advance Notification Program, which gives administrators a several days advance notice of upcoming patches, however these new security holes were announced by security product maker Finjan Software.

Finjan said their Malicious Code Research Center discovered the new vulnerabilities, at least some of which are very dangerous. A spokesperson for the company said "Finjan has provided Microsoft with full technical details concerning the vulnerabilities [... ]and has been assisting Microsoft to patch these holes. In order to prevent the creation of malicious viruses and worms, Finjan will not release any
technical details about these vulnerabilities until they are fully patched by Microsoft."

Shlomo Touboul, CEO and Founder of Finjan Software, said "Windows XP SP2 operating system is a continuation of the same Windows XP Operating System and Windows Kernel. All Windows versions have been developed with requirements for highest backward compatibility and open architecture, with maximum productivity and ease of use. In addition, Windows applications typically run with administrative permission with full and unlimited access to computer resources."

 "This, together with the emerging technology of mobile code has created a situation in which active content travels freely over the web and gains full control of host computers. These fundamentals create a green field for hackers shown by constantly increasing attacks and damage over the last few years. A security patch of Windows operating system without changing the rules of the game will not be enough to fight the recent complex malicious code attacks such as Scob, Mydoom, and others. End users and Enterprises must add an independent security layer that is not dependent on the above fundamentals. Application level behavior blocking is the leading technology designed to immunize systems from both known and unknown vulnerabilities and exploits; viruses, worms, Trojans, spyware, phishing and other threats," Touboul continued.

The vulnerabilities discovered at Finjan could allow attackers to "silently and remotely" take control over an affected system when a user visits a malicious Web page. As you well know, enticing someone to visit a Web page is relatively easy to do.

The company outlined several scenarios to better explain the risks:

  • Hackers can remotely access users' local files Windows(R) XP SP2 is designed to deny access to a local file in the course of Internet browsing. Therefore, any attempt by a remote web page to access a local file in any way other than downloading a file, is denied. Finjan has shown that this feature can be remotely compromised by hackers.
  • Hackers can switch between Internet Explorer Security Zones to obtain rights of local zone Internet Explorer uses the notion of security zones to differentiate between mobile codes by their origin. In this way, for example, the permissions of files running from the local hard drive are much higher than the permissions of code downloaded from the Internet. Finjan has shown that it is possible to elevate the privilege level of mobile code downloaded from the Internet. By gaining additional privileges, the remote code could read, write and execute files on the user's hard drive.
  • Hackers can bypass SP2's notification mechanism on the download and execution of EXE files and therefore download files without any warning or notification One of the mechanisms that have been implemented in SP2 is the verification of the download and the execution of content arriving from the Internet. This mechanism is implemented by three new features - an information bar inside Internet Explorer which filters and blocks unauthorized operations performed by web pages, a file download dialog which requires the user's confirmation for file save and execution operations, and
    an execution verification dialog. These features are important to prevent unauthorized silent "drive-by" installations of malicious software.

Upon learning of this news story a spokesperson for Microsoft said the company "is aware of the claims by Finjan Software and at this time cannot confirm Finjan's claims of  "ten new vulnerabilities" in Windows XP SP2. Moreover, Microsoft is currently unaware of active attacks against customers
attempting to utilize the alleged vulnerabilities as reported by Finjan.  We have been contacted by Finjan regarding various potential issues as part of the usual responsible disclosure protocol and are actively investigating those issues through our security response process to determine the validity and accuracy of the reported issues."

"Our early analysis indicates that Finjan's claims are potentially misleading and possibly erroneous regarding the breadth and severity of the alleged vulnerabilities in Windows XP SP2.  Once Microsoft concludes investigating Finjan's claims and if Microsoft finds any valid vulnerability in Windows XP SP2, Microsoft will take immediate and appropriate action to help protect customers. "

Other vendors also offer advance notice of unpatched security holes in Windows platforms and related services. For example, eEye Digital Security maintains a Web page of upcoming advisories on their Research site. As of November 10 the page lists one upcoming advisory that relates to remote code execution, which eEye given its highest severity rating. The company notifies the vendor (in this case Microsoft) of vulnerabilities and when the vendor releases a patch then eEye releases its own advisory to the public. Often times knowledge of still other unpatched vulnerabilities can be gathered from intrusion detection systems, which store signatures to recognize attacks.

The practice of notifying the public about the mere existance of security vulnerabilities (not to mention any significant details) is a sore spot in many people's minds. Researchers gain publicity for themselves and their products, and at the same time some claim they offer advance notice in order to keep a tiny bit of pressure on vendors to work quickly to produce patches. Striking a balance in that sort of act is difficult at best since it's not likely that everyone can be pleased all of the time and invariably it's the end users of products who suffer most in the event that too much information is released too soon.

End of Article



Reader Comments
XP SUCKS!!!!!!!

98 (With 2000 as a runner up) IS and was the best OS's ever put out!!!!!!

Anonymous User November 11, 2004


clearly you are the type of person that loves to propagate malware by allowing your out of date box to become a transmitter.
Thanks, but i chose to be secure with XP, and at $40/hour I'll bet someone out there is waiting for your call...

Anonymous User November 11, 2004 (Article Rating: )


Although I'm not a basher of companies, I do agree with the first post that MS is getting a little too messy.

Anonymous User November 11, 2004 (Article Rating: )


>>XP SUCKS!!!!!!! <<

You are stupid.

Anonymous User November 11, 2004


Mac OS X baby :)

Anonymous User November 11, 2004


When everyone slagged MS off about the stability of Windows, they fixed it. Now, everyone is slagging Windows off because of security, and they are making good progress on that. You have to remember that *nix was designed from the ground up for multiuser-ness, Windows was not (Macs are based on Unix now). Give them a chance, anyway, if it really was as bad as people made out, no one would use it, and clearly 97% of people douse it.

Anonymous User November 11, 2004


I don't believe xp is very stable. it's better then 98 , me and 2k but i don't think i could trust it to be reliable. I reboot atleast 1x a day still. as for 97% of the people using it. well they don't necessarily have a choice now do they. try getting a machine with linux or without a windows license from dell, hp, compaq, gateway, blah blah, blah. it's almost impossible. perhaps it because of the.. brace yourself... here it comes MONOPOLY!! I remember s report where MS forced IBM to shutdown OS/2 development or MS would start charging IBM more money per copy of windows 9x. I love how over in Asia not sure of the specific country, developers are forced to sign a document stating that they cannot sue MS if MS uses thier IP in MS Products. Imagine that! Buying a car from FORD and having FORD lease or sell your car anytime and you not being able to stop it. scary scary stuff

Anonymous User November 11, 2004 (Article Rating: )


If your computer is working fine. Why do you wanna screw with it and install a bunch of crap like SP2?

Anonymous User November 11, 2004 (Article Rating: )


ONE WORD: LINUX

Anonymous User November 11, 2004 (Article Rating: )


Hi all
I have used XP and i think its great,better than ME any day, put it this , without microsoft where would we be as i think Mr gates and the rest of the people at m/soft have done a great job over the years to bring O/S systems to the market, all the best i say to them, they lead,others follow, and if you dont like XP . there are always the other O/S systems to use, as for me XP still the best

Anonymous User November 11, 2004


 See More Comments  1   2   3   4   5   6   7   8   9   10 

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

WinInfo Short Takes: Week of November 9, 2009

An often irreverent look at some of the week's other news, including some more Windows 7 sales momentum, some Sophos stupidity, Microsoft's cloud computing self-loathing, more whining from the browser makers, Zoho's "Fake Office," and much, much more ...

Understanding File-Size Limits on NTFS and FAT

A general confusion about files sizes on FAT seems to stem from FAT32's file-size limit of 4GB and partition-size limit of 2TB. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events Introduction to Identity Lifecycle Manager "2"

SQL Server Security: How to Secure, Monitor & Audit Your Databases

Protecting Mobile Users' Data

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement