All the latest UK technology news, reviews and analysis

Microsoft flaw leaves PCs open to phishing

by Robert Jaques

10 Nov 2004

Be the first to comment

  • Tweet this

Microsoft has warned users of a serious vulnerability in ISA Server 2000 and Proxy Server 2.0 products that could allow malicious hackers to execute internet content spoofing scams.

According to alert MS04-039, the flaw could be used by cyber-criminals to carry out phishing attacks to trick unwary users into disclosing passwords and sensitive financial information.

"This is a spoofing vulnerability that exists in the affected products that could enable an attacker to spoof trusted internet content," Microsoft warned.

"Users could believe they are accessing trusted internet content when in reality they are accessing malicious internet content, for example a malicious website.

"However, an attacker would first have to persuade a user to visit the attacker's site to attempt to exploit this vulnerability."

Software affected by the vulnerability includes Microsoft Proxy Server 2.0 Service Pack 1, Microsoft Internet Security and Acceleration Server 2000 Service Pack 1 and Microsoft Internet Security and Acceleration Server 2000 Service Pack 2.

Microsoft Small Business Server 2000 (which includes Microsoft Internet Security and Acceleration Server 2000) and Microsoft Small Business Server 2003 Premium Edition are also affected.

As a workaround Microsoft advised users of the affected products to set the DNS cache size to zero.

"Setting the DNS cache size to zero effectively disables DNS caching on the affected system. This would prevent the affected software from using potentially spoofed data from the cache. This may have negative performance impact on DNS resolution," Microsoft said.

The software giant added that, if a customer suspects that their system has been affected by attempts to exploit this vulnerability, clearing the web proxy cache will help remove the suspected malicious content.

Full information and details of the fix are available here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Linux Systems Administrator- Red Hat- Cambridge - £30-40k

Linux Systems Administrator- Red Hat- Cambridge - £30...

Head of Strategic Development - eCommerce - £80-95k+Bens

HEAD OF STRATEGIC DEVELOPMENT - ECOMMERCE - LONDON...

Business Analyst / Lead Business Analyst

My client seeks an experienced Business Analyst to provide...

Lead Business Architect / Business Architect

My client a large forward thinking organisation is looking...

To send to more than one email address, simply separate each address with a comma.