440Forums  |  MacMusic.org  |  PcMusic.org  |  440tv  |  Zicos  |  AudioLexic
bugs   {key13}


Microsoft patches security bugs in Exchange, SQL Server, and Windows

InfoWorld

Tuesday July 8, 2008. 08:44 PM
InfoWorld

Microsoft has patched bugs in its Exchange, SQL Server, and Windows software that could give hackers new ways to break into computers.The company released four sets of patches Tuesday, all rated "important." They address a total of nine bugs in Microsoft's products.Although Microsoft has not rated any of its patches as critical, they will still keep corporate system administrators busy this week, said Andrew Storms, director of security operations with security vendor nCircle. "Not only will the IT admins have their hands full with the normal client-side updates, but they also need to go patch two of the most important enterprise services in an organization -- e-mail and databases," he said via instant message.Security experts say that the DNS (Domain Name System) bug , is particularly worrisome. That's because the bug is due to a design flaw in the DNS protocol that affects all DNS servers on the Internet.By sending certain types of queries to DNS servers, the attacker could then redirect victims away from a legitimate Web site -- say, Bofa.com -- to a malicious Web site without the victim realizing it. This type of attack, known as DNS cache poisoning, doesn't affect only the Web. It could be used to redirect all Internet traffic to the hacker's servers.The bug could be exploited "like a phishing attack without sending you e-mail," said Wolfgang Kandek, chief technical officer with Qualys.Other DNS software providers, including the Internet Software Consortium, Cisco and, Sun are also patching this vulnerability.Although this flaw does affect some home routers and client DNS software, it is mostly an issue for corporate users and ISPs that run the DNS servers used by PCs to find their way around the Internet, said Dan Kaminsky, the IOActive security researcher who discovered the problem. "Home users should not panic," he said in a Tuesday conference call.One of the bugs that Microsoft patched on Tuesday had previously been disclosed, making it a priority fix. That flaw, which lies in the version of Windows Explorer used by Vista and Windows Server 2008, could give criminals a way of running unauthorized software on a Windows PC. For that to happen, the attacker would first have to convince the user to open and save a specially crafted saved-search file using Windows Explorer.Exchange shops that read e-mail via the Web should give the Exchange patch a top priority, Qualys' Kandek said. That's because it can be exploited to attack users of Outlook Web Access (OWA) for Microsoft Exchange Server with a cross-scripting attack. By sending maliciously encoded e-mails to OWA users, attackers could theoretically steal e-mail credentials and install malicious software on a victim's system, he said.Finally, the SQL Server patch fixes four bugs that affect all supported versions of SQL Server.
Microsoft patched bugs Exchange Server Windows software that could give hackers Microsoft patches security bugs Exchange Server Windows
Microsoft patches security bugs in Exchange, SQL Server, and Windows Read more at InfoWorld
www.infoworld.com/cgi-bin/redirect?source=rss&url=www.infoworld.com/article/08/07/08/Microsoft_patches_security_bugs_in_Echange_SQL_Server_Windows_1.html

 

 Related News 
Network Managers Fear Security Threats From Within Network Managers Fear Security Threats From Within
 PC World 07/19/08 10 PM 
An update to Friday's security advisories An update to Friday's security advisories
 LWN.net 07/19/08 06 PM 
INQ traces O2 MMS security breach victim INQ traces O2 MMS security breach victim
 The Inquirer 07/19/08 01 PM 
RIM Patches BlackBerry Security Hole RIM Patches BlackBerry Security Hole
 PC World 07/19/08 01 PM 
Going Mobile with Windows Live Mesh Going Mobile with Windows Live Mesh
 PC World 07/19/08 05 AM 
Gallery: From Tiny Machines to Security, the Future of Nano-F... Gallery: From Tiny Machines to Security, the Future of Nano-F...
 Wired: Tech. 07/19/08 02 AM 
Ex-Microsoft Manager Gets 22 Months for Fraud Ex-Microsoft Manager Gets 22 Months for Fraud
 PC World 07/19/08 01 AM 
Pondering Microsoft's 'Everett Dirksen moment' Pondering Microsoft's 'Everett Dirksen moment'
 CNET News 07/19/08 12 AM 
Users reporting failed Windows and Office validations (Updated) Users reporting failed Windows and Office validations (Updated)
 Ars Technica 07/19/08 12 AM 
Tech Stocks Follow Microsoft, Google Lower Tech Stocks Follow Microsoft, Google Lower
 InternetNews 07/18/08 11 PM 
pChart: 1.26c fixing bugs pChart: 1.26c fixing bugs
 SourceForge 07/18/08 10 PM 
Security Bites 108: Understanding white listing Security Bites 108: Understanding white listing
 CNET News 07/18/08 10 PM 
Slowing PC market, another online reinvestment ahead for Micr... Slowing PC market, another online reinvestment ahead for Micr...
 BetaNews 07/18/08 09 PM 
Opera Brings iPhone Experience to Windows Mobile Opera Brings iPhone Experience to Windows Mobile
 Wired: Tech. 07/18/08 08 PM 
Firefox Update Fixes Mac Security Issue Firefox Update Fixes Mac Security Issue
 PC World 07/18/08 08 PM 
Bugs & Fixes: Fixing IPhone 2.0 Sync Problems Bugs & Fixes: Fixing IPhone 2.0 Sync Problems
 PC World 07/18/08 08 PM 
Top Ten Worst Uses for Windows Top Ten Worst Uses for Windows
 PC World 07/18/08 07 PM 
RIM fixes critical BlackBerry Enterprise Server bug RIM fixes critical BlackBerry Enterprise Server bug
 InfoWorld 07/18/08 07 PM 
Yahoo's Worth to Microsoft: $19 and Change Yahoo's Worth to Microsoft: $19 and Change
 Microsoft Watch 07/18/08 07 PM 
Microsoft Feeds Cash to Online Services Business Microsoft Feeds Cash to Online Services Business
 PC World 07/18/08 07 PM 
Microsoft feeds cash to Online Services Business Microsoft feeds cash to Online Services Business
 InfoWorld 07/18/08 07 PM 

Search

Tech Zicos
Thu December 4, 05:49 PM
bugs   {key13}