All the latest UK technology news, reviews and analysis

Microsoft firewall liable to DoS attacks

by James Middleton

17 Apr 2001

Be the first to comment

  • Tweet this

Microsoft's first crack at the security market, its Internet Security and Acceleration (ISA) firewall, has been dealt a major blow only weeks after its release as security experts warned that the product is vulnerable to denial of service (DoS) attacks.

An advisory released by security firm SecureXpert Labs today revealed that Microsoft's ISA Server 1.0 running on a Windows 2000 platform with Service Pack 1 is vulnerable.

As a result, the firewall "is vulnerable to a simple network-based attack, which stops all incoming and outgoing web traffic from passing through the firewall until the firewall is rebooted or the affected service is restarted", said the advisory.

SecureXpert said that if the firewall is configured to use the 'Web Publishing' feature then the attack could be carried out remotely.

This feature is often used to publish web server content externally from inside the network and is more than likely to be enabled. SecureXpert said that sending a long path name or URL to the web proxy will force it to terminate due to an access violation error. Essentially, this means that the ISA server is vulnerable to a DoS attack.

However, Microsoft has been quick to point out that the flaw cannot be exploited further, so a hacker could not use it to take control of the server. The software giant has released a hotfix for the problem and will include the patch in the first ISA service pack.

The Microsoft advisory and security fix is available here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

28%

1%

13%

58%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

IT Service Desk Technician

Working within the central Service Desk Team of a well...

GIS Technician

GIS Applications Engineer - circa £35k Excellent opportunity...

Senior C++ Developer x 2 - Embedded C++ Developer

Senior C++ Developer x 2 - Senior C++ Software Engineer...

Information security SOC specialist for world leading organisation

We are actively searching for Information security specialists...

To send to more than one email address, simply separate each address with a comma.