HardwareHeaven.com

HardwareHeaven.com

Looking for the skin chooser?
 
 
  • Home

  • Hardware reviews

  • Articles

  • News

  • Tools

  • Gaming at HardwareHeaven

  • Forums

 

Go Back   HardwareHeaven.com > Forums > News > Other Tech News


Other Tech News The latest community based technology news from across the globe. (If you aren't a community newsposter then use the "Submit News" section.)

Reply
 
Thread Tools
Old Jul 18, 2005, 09:54 PM   #1
DriverHeaven Extreme Member
 
Iria's Avatar
 
Join Date: Apr 2004
Posts: 7,275
Rep Power: 89
Iria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seen

Windows flaw reaches beyond XP

A security flaw that could let an attacker remotely crash computers running Windows exists in several versions of the operating system, not just Windows XP.

Windows 2000, Windows XP and Windows Server 2003 are vulnerable to a denial-of-service attack that exploits a problem in the Remote Desktop Protocol, Microsoft said in an advisory on Saturday.

RDP is a protocol that enables remote access to Windows systems. Because of a flaw in the way Windows handles remote desktop requests, an attacker could crash a PC by sending a malformed remote request, Microsoft said.

The advisory was released after the security researcher who discovered the flaw last week flagged Windows XP as vulnerable. Microsoft confirmed the issue on Friday and published the advisory over the weekend.

Microsoft said it is working on a patch, but noted that it is not aware of any attacks that try to exploit the vulnerability. However, security experts at The SANS Institute on Saturday did notice an increase in port-scanning activity on the network port used by RDP, which could be a sign that hackers are trying to look for targets.

While most Windows versions ship with RDP services disabled, Remote Desktop is turned on out-of-the-box in Windows XP Media Center Edition. Only computers using services that have RDP enabled are vulnerable, Microsoft said in its advisory.
__________
Read More / Source: News.com
Iria is offline   Reply With Quote


Old Jul 18, 2005, 10:08 PM   #2
HardwareHeaven Extreme Member
 
The_Neon_Cowboy's Avatar
 
Join Date: Dec 2002
Location: U.S.A.
Posts: 16,009
Rep Power: 92
The_Neon_Cowboy is a jewel in the roughThe_Neon_Cowboy is a jewel in the roughThe_Neon_Cowboy is a jewel in the rough
System Specs

"While most Windows versions ship with RDP services disabled"

I think the meant enabled unless thier not talking about XP
__________________
The_Neon_Cowboy is offline   Reply With Quote
Old Jul 18, 2005, 11:12 PM   #3
DriverHeaven Lover
 
Join Date: Mar 2003
Location: Silver Spring, MD
Posts: 136
Rep Power: 0
FDM80 is on a distinguished road

Well, I remote desktop to my home computer from my computer at work. It's a great way to do what you need to do without having to deal with "doing stuff on a work computer you shouldn't." If push comes to shove, you can actually change the port RDP uses. I believe it's just a matter of changing a registry key, or something like that. If you are being hit on the port, you can just change it. That would be a temporary bandaid until an actual patch is issued.
__________________
Verizon FIOS rules!
FDM80 is offline   Reply With Quote
Old Jul 19, 2005, 01:00 AM   #4
Twice the fun!
 
nForcer's Avatar
 
Join Date: Jul 2002
Posts: 1,404
Rep Power: 0
nForcer is on a distinguished road

Donator
I, for one, am actually quite suprised it took this long for something serious to affect the method of Remote Desktop. I also wonder if Terminal Services is affected as well.
nForcer is offline   Reply With Quote
Reply

Thread Tools