Eight-year-old Windows name resolution exploit re-emerges

By Scott M. Fulton, III | Published December 4, 2007, 11:25 AM

Microsoft acknowledged the discovery of an exploitable bug in the way one of its services handles domain name resolution -- a bug it thought it fixed in 1999.

At a so-called "ethical hacker conference" in New Zealand last week, a programmer named Beau Butler revealed a method whereby a malicious user could intercept and re-route Internet traffic throughout a network, using a man-in-the-middle-attack. The method involved being able to masquerade as something called Web Proxy Auto-Discovery Protocol (WDAP), whose purpose is to automatically detect whether a system utilizes proxies for domains higher than the second level (e.g., fileforum.betanews.com).

WDAP does this by adding wdap. to the front of domain names in the network, starting with the highest order names and then working backwards until it reaches the second level, and then pinging each name until it gets a response. If it does, it then communicates with the WDAP service at that level.

The man-in-the-middle attack is quite simple: By pretending to be WDAP, a malicious service can pretend to be resolving the domain name to something else entirely, creating an easy denial-of-service situation.

Microsoft thought it had solved this problem in 1999, and at one level, it actually had. But as Butler discovered, the fix the company had deployed only enabled malicious middlemen to be discovered for networks using the .com TLD. For any other TLD, the exploit was wide open -- including for Butler's home country TLD, .nz.

Yesterday, Microsoft issued a security advisory acknowledging the flaw, but treating it with kid gloves as though it were recently discovered. It impacts Windows versions dating back to Windows 2000 SP4 and Windows XP SP2, and users of all versions of Internet Explorer dating back to 5.01. But while the company credited Butler with the discovery, it gingerly avoided any mention of the exploit's age.

Thus once again, security blogs that picked up the Microsoft advisory and dubbed it another "zero-day" may want to re-investigate this exploit's history. And it's also worth noting that, while there continues to be healthy debate over the design flaws that continue to affect Windows services, this particular one lay in waiting for about eight years, only to be re-discovered by someone whose interests were in spotlighting and correcting the problem. It says something about the complexion of the modern malicious user community.

Security firm Secunia this morning rates the exploit as "less critical."

Comments

View comments by with a score of at least

"It impacts Windows versions dating back to Windows 2000 SP4 and Windows XP SP2, and users of all versions of Internet Explorer dating back to 5.01. But while the company credited Butler with the discovery, it gingerly avoided any mention of the exploit's age."

I wonder what Jeff Jones has to say about this :)

Score: 0

|

Dont worry this happened to Apple before as a matter of fact, it was last week.

Score: 0

|

yep, and all the M$ drones piled on Apple.

Score: 0

|

Same old, same old sad story...

Score: 0

|

http://www.news.com/2300-7349_3-6220587-1.html

This image sums it up pretty well I think.
"What to Do"

"What to Say"

Score: 0

|

You mean Marketing company Microsoft has no clue what they are doing? I'm shocked

Score: 0

|

"Windows 2000 XP4" :-P

Score: 0

|

Microsoft's Ray Ozzie: 'Nobody's going to be 100% open'

The mobile apps ecosystems of the world may converge over time, led by apps being ported over across platforms, according to the Chief Software Architect.

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

AOL's decision to rebrand as Aol. takes a bad brand and makes it worse

The idea behind the social Web is to crowd source before bringing out something new. But not at AOL, which new logo debuted with a cry of "fail!" across the blogosphere and Twittersphere today.

Microsoft 'worked with Apple' for Silverlight on iPhone, says Goldfarb

By not making such a big deal out of trying to stream video to the iPhone, Microsoft got a big deal out of it, revealed the Silverlight product manager.

Clicker.com cuts through the Web video chaos

In a world where homemade video and Hollywood movies travel the same pipeline, it's good to have a real search engine to cut through the clutter.

A case study in improving software: What Office 2010 can learn from Notion 3

A music composition product gambles with a complete overhaul, in an effort to make headway against two well-known competitors in a tough market.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.

Microsoft's Bob Muglia and Ray Ozzie on Silverlight vs. standards

Bob Muglia: "We're trying to provide people with an environment that has capabilities that you just simply can't do today in the standards-based world."