| 
          
         | 
        
          
            <<  
             ^ 
              >>
          
          
            
              
                Date: 2003-07-17
                 
                 
                Gravierende Microsoft Windows Sicherheitsluecke seit NT4
                Betroffen von dem RPC Buffer Overflow sind NT4, 2000, XP, und 2003. Ohne Firewall ist jeder aktuelle Windows Rechner aus dem Internet über RPC angreifbar. Humoresq/ue: Am Vortag wurde bekannt, dass das Department of Homeland Security mit Microsoft einen 90 Millionen Dollar Fünfjahresvertrag abgeschlossen hat.
                 
-.-. --.- -.-. --.- -.-. --.- -.-. --.- -.-. --.- -.-. --.- 
                 
                
                  http://lists.netsyscom/pipermail/full-disclosure/2003-July/011335.html
                   
 
[...] 
We have discovered a critical security vulnerability in all recent versions 
of Microsoft operating systems. The vulnerability affects default 
installations of Windows NT 4.0, Windows 2000, Windows XP as well as  
Windows 2003 Server. 
                                 
This is a buffer overflow vulnerability that exists in an integral component 
of any Windows operating system, the RPC interface implementing Distributed 
Component Object Model services (DCOM). In a result of implementation error 
in a function responsible for instantiation of DCOM objects, remote attackers 
can obtain unauthorized access to vulnerable systems. 
[...] 
 
http://www.reuters.com/newsArticle.jhtml?type=technologyNews&storyID=3095377
                   
 
Microsoft Wins Homeland Security Contract  
Tue July 15, 2003 05:33 PM ET  
WASHINGTON (Reuters) - The Department of Homeland Security said on Tuesday 
it has awarded a five-year, $90 million enterprise agreement to Microsoft 
Corp MSFT.O to become the department's primary technology provider. 
 
Under the contract, Microsoft will supply desktop and server software to the 
newly created department, which has merged parts of 22 different agencies 
into one entity. 
[...] 
                
                 
- -.-. --.- -.-. --.- -.-. --.- -.-. --.- -.-. --.- -.-. --.- 
                
edited by typo  
published on: 2003-07-17 
comments to office@quintessenz.at
                   
                  
                    subscribe Newsletter
                  
                   
                
- -.-. --.- -.-. --.- -.-. --.- -.-. --.- -.-. --.- -.-. --.- 
                
                  <<  
                   ^ 
                    >> 
                
                
               | 
             
           
         | 
         | 
        
          
         |