『尊米网』域名信息交流平台
设为首页 收藏本站
网站地图 RSS-订阅
反馈留言 高级搜索
尊米首页 | 域名新闻 | 域名知识 | 域名人物 | 域名标识 | 相关下载 | 信息专题 | 域名问答 | 域名经纪 | WHOIS查询 | Winindomain.com
 
╣当前位置╠
尊米首页 > 域名新闻 > 英文媒体报道 > 文章内容
Domain-name issue could aid eavesdroppers
来源:security focus 发布时间:2007-12-05 03:45:25
欢迎您在线投稿(需先登陆),也可将您的新闻线索/稿件电子邮件至:editor@zunmi.com

Microsoft warned companies on Monday that a flaw in the way Windows searches for Web proxies could allow an attacker the ability to reroute traffic through a malicious server.

The security issues occur when a Windows computer attempts to find a proxy server using Microsoft's Web Proxy Automatic Discovery (WPAD) technology and the organization's domain name starts at the third level or deeper, such as somecompany.co.jp, the software giant stated in an advisory. The WPAD search first attempts to find the server using the fully-qualified domain name (FQDN), and if it doesn't find the server will try the next higher level of the domain name. For example, a search for a proxy server in somecompany.co.jp will look for servername.somecompany.co.jp and then move on to servername.co.jp, which could be a malicious server outside the company's network.

"At this time, we are not aware of attacks attempting to use the reported vulnerability, but we will continue to track this issue," Tim Rains, a spokesman for the Microsoft Security Response Center, said on the teams' blog. "The advisory contains several mitigations that customers can use to help protect themselves from attackers."

Successfully exploiting the vulnerability would reroute a Windows computer's Web traffic through the malicious proxy server, allowing man-in-the-middle attacks and eavesdropping.

Microsoft has had to deal with a handful of vulnerabilities in recent months caused by the Windows software that handles domain names. In April, the software giant closed a buffer overflow in the remote procedure call functionality of its Domain Name Server for Windows 2000 and Windows 2003. The company is also one of the browser makers searching for a solution to the issue of DNS rebinding, which could be used by an attacker to gain access to resources on a Web surfer's network.

Because international domain names frequently assign both the top-level domain and the second-level domain, such as co.jp, to segments of users, the vulnerability primarily threatens non-U.S. organizations. Microsoft acknowledged white-hat hacker Beau Butler, who presented details of the issue at Kiwicon in New Zealand last month.


上一篇:IPGA Acquires iProperty.com Domain Name   下一篇:Top 10 Best & Worst Anti-Phishing Web Registrars
【免责声明】
以上文章由本站会员发布或网络转载,除色情、暴力及反政府等法律明确禁止内容以外,尊米网对其不承担法律责任。
[收藏] [推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]
发表评论
用户名: 新注册) 密码: 匿名评论 (未注册可直接匿名评论)
评论内容:(250字以内)
 §最新评论
进入主题评论页  
本月热点
相关新闻
·Internet overhaul wins approva
·Phoenix Clothing Brand BLaZa F
·.Asia Landrush Closes with Hal
·Internet agency to battle doma
·Alberta premier threatens to s
·Internet Polling Fails in N.H.
·Domain Front Running by Regist
·Network Solutions snarfing you
·How 2...Buy a domain name
·Registrar denies‘front-runnin
·Pompano domain name firm sold
·Moniker Acquired By Oversee.ne
赞助商广告
尊米首页 - 关于我们 - 本站动态 - 联系我们 - 媒体关注 - 网站地图 - 友情链接 - 原创投稿 - 帮助中心