Microsoft firewall liable to DoS attacks

Microsoft's first crack at the security market, its Internet Security and Acceleration firewall, has been dealt a major blow only weeks after its release as security experts warned that the product is vulnerable to denial of service attacks.

Written by James Middleton

Microsoft's first crack at the security market, its Internet Security and Acceleration (ISA) firewall, has been dealt a major blow only weeks after its release as security experts warned that the product is vulnerable to denial of service (DoS) attacks.

An advisory released by security firm SecureXpert Labs today revealed that Microsoft's ISA Server 1.0 running on a Windows 2000 platform with Service Pack 1 is vulnerable.

Advertisement

As a result, the firewall "is vulnerable to a simple network-based attack, which stops all incoming and outgoing web traffic from passing through the firewall until the firewall is rebooted or the affected service is restarted", said the advisory.

SecureXpert said that if the firewall is configured to use the 'Web Publishing' feature then the attack could be carried out remotely.

This feature is often used to publish web server content externally from inside the network and is more than likely to be enabled. SecureXpert said that sending a long path name or URL to the web proxy will force it to terminate due to an access violation error. Essentially, this means that the ISA server is vulnerable to a DoS attack.

However, Microsoft has been quick to point out that the flaw cannot be exploited further, so a hacker could not use it to take control of the server. The software giant has released a hotfix for the problem and will include the patch in the first ISA service pack.

The Microsoft advisory and security fix is available here.

Tags:

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

10 Oct 2008

7.33 MBPodcast Special: Views from the Valley More...

Podcast image

09 Oct 2008

12.99 MBComputing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security More...

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

MoD building

Latest data breach leads MPs to demand culture change

MoD admits to losing a hard drive containing up to...  More...

Online shopping

E-retailers urged to prepare for Christmas

Credit crunch sending shoppers online for cheaper presents   More...

Mobile phone

Emerging markets drive mobile growth

Mobile penetration rates expected to reach 95 per cent by...  More...

Digital information

Poor data classification costing companies dear

Millions wasted on searching through clutter, says analyst   More...

Primary Navigation