![]() |
![]() |
All Products | Support | Search | microsoft.com Guide | |
![]() |
|||
| Security Home | New Headlines | Bulletins | Events & Training | | |||
|
|
Microsoft Security Bulletin Since March 2, 1998, there have been numerous reports of malicious network-based, denial-of-service attacks launched against Internet-connected systems. We were notified of these attacks, which affected some Internet-connected Microsoft� Windows NT� and Windows� 95 systems, by customers and security alert organizations, including CIAC and CERT. This issue was also reported on the NTBUGTRAQ mailing list. Special thanks to Russ Cooper, the list moderator, for his assistance in this issue. Based on analysis of data received from customers and alert groups, this is not a new issue. Systems that contain up-to-date patches were not vulnerable to this wave of attacks. This vulnerability exploited by this attack was addressed by a patch issued in early January. The attack is called by various names, including Teardrop2, NewTear, Bonk, Boink. These are all varied attacks that exploit the same vulnerability, which was addressed in the patch released in January. For more information specifically on the NewTear/Bonk/Boink attack and the available updates for that vulnerability, please read our bulletin on that issue. What Microsoft is Doing Additionally, replaying the network traces we obtained from attacked customers against patched systems had no effect, while these same traces replayed against an unpatched system caused it to crash. This was further evidence that the wide-spread attack since Monday was a NewTear/Bonk/Boink-type attack. We will continue to work with customers who are affected by this issue, and with the security response organizations to ensure that there is no new issue here, and to ensure that all customers are aware of the security updates necessary to protect against these network denial of service attacks. The following are some alerts have been posted by other alert organizations on this issue:
Additional information and discussion is available on a number of newsgroups, including the NTBUGTRAQ. What Customers Should Do Customers should evaluate their current environment to determine their exposure, and install all relevant security updates. Information about available updates is included in the following sections. Windows NT 4.0
Windows 95
The “Winsock 2 Update” update (approximately 192k) is available from http://www.microsoft.com/windows95/info/ws2.htm. This is a fully supported and regression tested update.
Windows 98 Release
Candidate 0 (RC0) Notifying Law Enforcement of a Computer Crime The first step is to contact your local law enforcement office with jurisdiction over computer related crimes. In most areas the local FBI office would be a good place to start. They would be able to help you decide what criminal activity, if any, might have taken place. Many FBI agents nationwide have had specialized computer training to handle this type of investigation. For more assistance you can contact FBI's CITAC Watch hotline at 202-324-6715. � 1999 Microsoft Corporation. All rights reserved. Terms of Use. |