Original URL: http://www.channelregister.co.uk/2007/11/26/wpad_vuln_investigated/
Microsoft bug squashers are investigating reports of a serious security vulnerability in Windows operating systems that could allow attackers to take control of vast numbers of machines, particularly those located off US shores.
A Microsoft spokesman had only minimal details about the investigation, which was prompted by a presentation last week by researcher Beau Butler at the Kiwicon security conference in New Zealand. According to this report (http://www.smh.com.au/news/technology/microsoft-flaw-a-massive-shock/2007/11/23/1195975914416.html) in the Sydney Morning Herald, the flaw affects every version of Windows including Vista and is actually the continuation of an old vulnerability that Microsoft supposedly fixed years ago.
The bug, according to Symantec's DeepSight (https://deepsight.symantec.com/) threat notification service, resides in a feature known as Web Proxy Autodiscovery (WPAD), which helps IT administrators automate the configuration of proxy settings in Internet Explorer and other web browsers. The vulnerability can be "widely exploited" to "intercept web sessions, direct browsers to malicious proxies, and effectively gain control over unsuspecting users' web traffic," according to Symantec, which said it had yet to confirm the vulnerability.
Vulnerable browsers will traverse a company's host domain to search for a WPAD data file used to set up the proxy feature. IE running on host a.b.c.d.net, for example, first would look in b.c.d.net, then c.d.net and finally d.net. "In certain configurations, the third-level domain is not a trusted part of the network; an attacker can set up a malicious driftnet-type WPAD server situated outside of an organization's normal administrative control," Symantec warned.
"Now that we understand the issue we're researching comprehensive mitigations and workarounds to protect customers," Microsoft's general manager of product security, George Stathakopoulos, wrote in an email to the Sydney Morning Herald. Engineers in Australia and the US were scrambling to replicate and confirm the issue over the US Thanksgiving holiday, according to the paper. A Microsoft spokesman had no additional details on Monday.
Microsoft appears to have released a patch for the vulnerability (http://www.microsoft.com/technet/security/bulletin/ms99-054.mspx) in 1999. But the patch only protected domain names ending in .com, so WPAD servers using all other addresses have remained vulnerable. ®
Microsoft dishes out six critical updates (13 February 2008)
http://www.channelregister.co.uk/2008/02/13/patch_tuesday_february/
Hey, HP laptop owners: click here to get hijacked (12 December 2007)
http://www.channelregister.co.uk/2007/12/12/hp_laptop_vuln/
Microsoft releases battling OS release candidates (6 December 2007)
http://www.channelregister.co.uk/2007/12/06/microsoft_os_plans/
Ugly view mars Windows Vista birthday (30 November 2007)
http://www.channelregister.co.uk/2007/11/30/vista_birthday/
Next year's next big thing (28 November 2007)
http://www.channelregister.co.uk/2007/11/28/2007_reader_feedback/
HP wallops server rivals in Q3 (27 November 2007)
http://www.channelregister.co.uk/2007/11/27/hp_server_gartner_q3/
Win XP also prone to random number bug (23 November 2007)
http://www.channelregister.co.uk/2007/11/23/win_xp_random_bug/
We know security and usability are orthogonal - do you? (22 November 2007)
http://www.channelregister.co.uk/2007/11/22/security_usability_are_orthogonal/
DNS security improves as firms tool up to tackle spam (20 November 2007)
http://www.channelregister.co.uk/2007/11/20/dns_security_survey/
With one bound, Apple is free of 54 security bugs (15 November 2007)
http://www.channelregister.co.uk/2007/11/15/behemoth_apple_patch_batch/
Windows update offers defence against shell bug (14 November 2007)
http://www.channelregister.co.uk/2007/11/14/windows_novemeber_patch_update/
Windows random number generator is so not random (13 November 2007)
http://www.channelregister.co.uk/2007/11/13/windows_random_number_gen_flawed/
Macrovision update plugs zero-day DRM exploit (6 November 2007)
http://www.channelregister.co.uk/2007/11/06/macrovision_drm_update/
© Copyright 2008