Eight-year-old Windows name resolution exploit re-emerges

By Scott M. Fulton, III | Published December 4, 2007, 11:25 AM

Microsoft acknowledged the discovery of an exploitable bug in the way one of its services handles domain name resolution -- a bug it thought it fixed in 1999.

At a so-called "ethical hacker conference" in New Zealand last week, a programmer named Beau Butler revealed a method whereby a malicious user could intercept and re-route Internet traffic throughout a network, using a man-in-the-middle-attack. The method involved being able to masquerade as something called Web Proxy Auto-Discovery Protocol (WDAP), whose purpose is to automatically detect whether a system utilizes proxies for domains higher than the second level (e.g., fileforum.betanews.com).

WDAP does this by adding wdap. to the front of domain names in the network, starting with the highest order names and then working backwards until it reaches the second level, and then pinging each name until it gets a response. If it does, it then communicates with the WDAP service at that level.

The man-in-the-middle attack is quite simple: By pretending to be WDAP, a malicious service can pretend to be resolving the domain name to something else entirely, creating an easy denial-of-service situation.

Microsoft thought it had solved this problem in 1999, and at one level, it actually had. But as Butler discovered, the fix the company had deployed only enabled malicious middlemen to be discovered for networks using the .com TLD. For any other TLD, the exploit was wide open -- including for Butler's home country TLD, .nz.

Yesterday, Microsoft issued a security advisory acknowledging the flaw, but treating it with kid gloves as though it were recently discovered. It impacts Windows versions dating back to Windows 2000 SP4 and Windows XP SP2, and users of all versions of Internet Explorer dating back to 5.01. But while the company credited Butler with the discovery, it gingerly avoided any mention of the exploit's age.

Thus once again, security blogs that picked up the Microsoft advisory and dubbed it another "zero-day" may want to re-investigate this exploit's history. And it's also worth noting that, while there continues to be healthy debate over the design flaws that continue to affect Windows services, this particular one lay in waiting for about eight years, only to be re-discovered by someone whose interests were in spotlighting and correcting the problem. It says something about the complexion of the modern malicious user community.

Security firm Secunia this morning rates the exploit as "less critical."

Comments

View comments by with a score of at least

"It impacts Windows versions dating back to Windows 2000 SP4 and Windows XP SP2, and users of all versions of Internet Explorer dating back to 5.01. But while the company credited Butler with the discovery, it gingerly avoided any mention of the exploit's age."

I wonder what Jeff Jones has to say about this :)

Score: 0

|

Dont worry this happened to Apple before as a matter of fact, it was last week.

Score: 0

|

yep, and all the M$ drones piled on Apple.

Score: 0

|

Same old, same old sad story...

Score: 0

|

http://www.news.com/2300-7349_3-6220587-1.html

This image sums it up pretty well I think.
"What to Do"

"What to Say"

Score: 0

|

You mean Marketing company Microsoft has no clue what they are doing? I'm shocked

Score: 0

|

"Windows 2000 XP4" :-P

Score: 0

|

Microsoft launches Office 2010 technical beta a few days early

A big week for Microsoft starts off with an out-of-sync surprise: the early release of the Office Technical Beta ahead of the launch keynote.

PDC 2009 Day 0: Vista is through

If there was any doubt in your mind that Microsoft is putting Vista behind it, the first session at PDC would eliminate it for good.

Windows Marketplace for Mobile launches on WinMo 6.0 and 6.1

No longer isolated to Windows Mobile 6.5, the Windows Phone app store has opened up to older versions of Windows Mobile.

Samsung releases another Android: where will it fit in with Bada approaching?

Samsung today announced the Galaxy Spica, sequel to its first Android handset destined for Europe and Asia.

Twitter to abandon 'politically biased' suggested user list

Twitter's suggested list of users to follow will be going away, says co-founder Biz Stone.

The Internet can still be a positive force, World Wide Web Foundation says

Sir Tim Berners-Lee's World Wide Web Foundation has launched worldwide operations.

Blockbuster's way down, but poised for a comeback

Though it took a serious beating in 2009, Blockbuster CEO Jim Keyes says the company can turn it around.

iTunes Preview doesn't go far enough to create Web-based option for store

Apple has rolled out iTunes Preview, a Web interface for browsing iTunes.

PDC 2009 Preview: The move to Office 2010 and Visual Studio 2010

The major focus of Microsoft's conference next week will likely be explaining why two pillars of its software sales strategy deserve to remain where they are.

Dell's first smartphone aids the Android onslaught

Longtime PC leader Dell has finally announced its Android-based smarphone.

After the Intel + AMD armistice: Do we really want a level playing field?

Scott Fulton On Point: One by one, the reasons for us to continue suspending the course toward open and fair competition in IT, are dropping like flies.