Eight-year-old Windows name resolution exploit re-emerges

By Scott M. Fulton, III | Published December 4, 2007, 11:25 AM

Microsoft acknowledged the discovery of an exploitable bug in the way one of its services handles domain name resolution -- a bug it thought it fixed in 1999.

At a so-called "ethical hacker conference" in New Zealand last week, a programmer named Beau Butler revealed a method whereby a malicious user could intercept and re-route Internet traffic throughout a network, using a man-in-the-middle-attack. The method involved being able to masquerade as something called Web Proxy Auto-Discovery Protocol (WDAP), whose purpose is to automatically detect whether a system utilizes proxies for domains higher than the second level (e.g., fileforum.betanews.com).

WDAP does this by adding wdap. to the front of domain names in the network, starting with the highest order names and then working backwards until it reaches the second level, and then pinging each name until it gets a response. If it does, it then communicates with the WDAP service at that level.

The man-in-the-middle attack is quite simple: By pretending to be WDAP, a malicious service can pretend to be resolving the domain name to something else entirely, creating an easy denial-of-service situation.

Microsoft thought it had solved this problem in 1999, and at one level, it actually had. But as Butler discovered, the fix the company had deployed only enabled malicious middlemen to be discovered for networks using the .com TLD. For any other TLD, the exploit was wide open -- including for Butler's home country TLD, .nz.

Yesterday, Microsoft issued a security advisory acknowledging the flaw, but treating it with kid gloves as though it were recently discovered. It impacts Windows versions dating back to Windows 2000 SP4 and Windows XP SP2, and users of all versions of Internet Explorer dating back to 5.01. But while the company credited Butler with the discovery, it gingerly avoided any mention of the exploit's age.

Thus once again, security blogs that picked up the Microsoft advisory and dubbed it another "zero-day" may want to re-investigate this exploit's history. And it's also worth noting that, while there continues to be healthy debate over the design flaws that continue to affect Windows services, this particular one lay in waiting for about eight years, only to be re-discovered by someone whose interests were in spotlighting and correcting the problem. It says something about the complexion of the modern malicious user community.

Security firm Secunia this morning rates the exploit as "less critical."

Comments

"It impacts Windows versions dating back to Windows 2000 SP4 and Windows XP SP2, and users of all versions of Internet Explorer dating back to 5.01. But while the company credited Butler with the discovery, it gingerly avoided any mention of the exploit's age."

I wonder what Jeff Jones has to say about this :)

Score: 0

|

Dont worry this happened to Apple before as a matter of fact, it was last week.

Score: 0

|

yep, and all the M$ drones piled on Apple.

Score: 0

|

Same old, same old sad story...

Score: 0

|

http://www.news.com/2300-7349_3-6220587-1.html

This image sums it up pretty well I think.
"What to Do"

"What to Say"

Score: 0

|

You mean Marketing company Microsoft has no clue what they are doing? I'm shocked

Score: 0

|

"Windows 2000 XP4" :-P

Score: 0

|

Silverlight 3 goes live on Microsoft's servers

Microsoft's answer to Adobe's Flash is (unofficially) here, with prospects of higher-speed, higher-resolution video and for the first time, 3D.

Three Android phones on the way from T-Mobile in 2009

T-Mobile's myTouch 3G, launched Wednesday, will be followed by two more Android phones later this year, but neither of them will be HTC's Hero.

Best Buy-brand TVs to get TiVo

A new alliance will place the retailer's own brand alongide the manufacturers, and could also lead to future partnerships on services.

LTE still lacks a voice

The 4G Wireless standard that Verizon hopes to show off before this year is out is still at a loss for (spoken) words.

Data sharing among online advertisers: Is sanity in sight?

Lockdown with Angela Gunn In the middle of a 15-page plea not to get regulated, a spark of smart thinking.

T-Mobile's strategy to combat Apple's iPhone with Android

With a trio of Android phones now in the pipeline for 2009, T-Mobile hopes to break the iPhone's emerging stranglehold.

EC's Reding: Government should act as broker for media downloads

If Internet media services don't step up and build an attractive way for users to start paying for downloads, a commissioner says, government may do the job instead.

Sony TVs get Netflix, still no PS3

Though it's coming in behind LG, Samsung, and Microsoft, Sony will begin to offer Netflix streaming, too.

Google Chrome OS: Too little, too early

Carmi Levy: Wide Angle Zoom Don't start the revolution just yet, says Carmi, who isn't so certain Chrome OS will be the "Windows Killer."

GAO pen test brings the hammer down on federal rent-a-cops

But are the computers to blame for the contract-guard fiasco at FPS?

What's Next: Chrome OS will have at least some friends in high places

Also: South Korea takes another round of DDoS abuse, and Neelie Kroes and Steve Ballmer may shake hands before she exits stage left.

Report: Evidence of further creativity with Windows 7 upgrade prices

A ZDNet blogger did some serious digging for clues as to a reported price break on multiple Windows 7 Home Premium licenses, and may have found it.