Tuesday, August 25, 2009

WINS Security Vulnerability

WHAT IS WINS?

The Windows Internet Name Service, or WINS is Microsoft's answer to the question that no one ever asked. No really, WINS is the core service which translates the names of computers into their numeric IP addresses. This is a necessary service for one computer to be able to talk to another.

WHAT IS THE WINS VULNERABILITY?

The vulnerability found within the WINS service has been classified as critical, and can "...allow remote code execution if a user has received a specially crafted WINS replication packet on a affected system running the WINS service...", states a representative from Microsoft. The replication packet allows the attackers to write arbitrary memory locations and execute the arbitrary code via a modified pointer within the packet sent to TCP Port 42. This attack has been found to be coming form China, and is targeting no less than 70,000 IP addresses daily.

WHAT THIS MEANS TO YOU, THE SMALL BUSINESS OWNER?

What this means is that if you or a member of your team have manually installed this particular WINS component, you WILL be affected. A representative of Shavlik Technologies says that this "...is an unauthenticated server-side attack. The bad guy simply points and shoots some packets at the WINS server and they can execute code of their choice on that server." This could mean that anyone can gain access to all of your sensitive information remotely.
And you would never know!

0 comments:

UPDATE: A New School To come...The Art Institute of Pittsburgh, And a New Writing Job!

I am currently a student at Kaplan University's KU Campus. But starting on November 12th of this year, I will be transferring to The Art Institute of Pittsburgh. It is another online program in which I will earn my Associate's degree in Interactive Media and Web Design. The difference i that this will be a degree not only in the Sciences, but in Fine Arts as well. I am still interning with Tymor Technologies Inc., which is owned and operated by Craig Weiss, CEO. I have also been writing for a website in Europe, called Youserbase.org. It is the #1 Consumer Electronics Wikli in Europe.

I will gain great experiences and knowledge while doing something I love! Who could ask for anything more?

I will be updating this blog frequently with my experiences as an intern, as well as my progress in class, so stay tuned, and check back often!