Find Web Hosts Shared Dedicated Managed Ecommerce VPS Adult NT Colo Database Reseller Canada Australia UK Budget Search
25% Off Managed IBM eServers Hostway - Get Free SetUp!
HOME | DAILY NEWS | FEATURES | EUROPE | EDITORIAL | INTERVIEWS | MAGAZINE | SUBSCRIBE
click here to subscribe for free
 
Security Flaw Warning Prompts Fixes

April 22, 2004 -- (WEB HOST INDUSTRY REVIEW) -- According to a report by research and analysis firm Netcraft (netcraft.com), a more advanced way of exploiting an old transmission control protocol (TCP) security hole has emerged, developed by Paul Watson, a security professional. The flaw would allow an attacker to reset an existing TCP session using specially crafted TCP packets.

Netcraft says most TCP sessions are short-lived, so the vulnerability had little impact, though certain critical protocols, such as Border Gateway Protocol (BGP), depend on long-lived sessions. Netcraft said the weakness can be addressed by using MD5 authentication to secure BGP sessions, a step most Internet service providers never take because an exploit seemed mathematically implausible.

Watson's exploit, however, makes the attack of the vulnerability much faster, especially for attackers controlling "bot networks" of compromosed machines.

Watson announced plans on March 14 to present a paper about his findings at the CanSecWest conference, held yesterday. Prior to the presentation, Watson had shared his plans with government security officials in the US and the UK, who organized a response with major vendors such as Savvis. Bill Hancock, chief security officer for Savvis, said in the report that his company implented fixes for the holes last weekend. The fixes were based on the information Watson passed along, Hancock said.


Subscribe to our print magazine
Read more web host news
Subscribe for email updates
Submit press releases, news
    Find Web hosts, domain names
Reseller, multi-account hosting
Get listed in Web Host Search
Web host industry marketing

Web Host Industry Insight, Interviews
Are You Hosting a Terrorist Site?
Qwest Redesigns Managed Web Hosting
Hosts Talk Common Sense, Ethics in Policy Debates
Telecom Spending to Increase, Confidence Returning
Ensim Ignite Completes the Web Hosting Package
EU Presses for Spam Crackdown
Enterasys Adds Security to Data Center Solutions
Solar Powered Web Host Building Green Data Center
Hosts Must Invest in Backup and Restoration
Worms, Routers Raise Downtime Concerns
Verio Refocuses on Resellers
More Web Host Industry Insight and Interviews

 
WEB HOSTING NEWS
Equinix Expands Washington Data Center

Q9 Networks Prices Offering at $8.50

DSL.net to Appeal De-Listing Notice

EarthLink Appoints New CFO

EDS Names Richard Fisher to Board

Security Warning Prompts Secret Fixes

Globix, Venaca Partner for Content

Phishing Attacks on Rise Netcraft Says

Webhosting Marketplace Debuts Services

Inflow Deploys Patches for iServerCare

Peak 10 Unveils New Managed Services

HelmTastic Offering URL Protector

Syndicate this news feed
More Web Host News

WEB HOSTING JOBS
CONSULTING ENGINEER (web hosting management)  Apr 20/04
 
Sales Consultant  Apr 06/04
 
Senior Perl Developer  Mar 31/04
 
System Developer  Mar 25/04
 
Developer with Marketing Skills  Mar 19/04
 
more web hosting jobs

WEB HOST AUTOMATION
Technical profiles of web hosting and data center automation. >>

RESELLER HOSTING
reseller hosting, billing, automation, web host marketing, more ... >>

INSIDE theWHIR.com
sponsored links
 
Host Services | Industry Jobs | Magazine | News | Reseller | Find Web Hosts | Domain Names | Article Central | VPN | Site Guide | Map

about us | terms | advertising | editorial | subscribe

© Copyright 2004 Web Host Industry Review, Inc. All rights reserved.