eSecurity Planet   Earthweb  
Images Events Jobs Premium Services Media Kit Network Map E-mail Offers Vendor Solutions Webcasts
   eSecurity subjects:
E-Security Planet Webcasts:
Keeping Your Data Secure from the Outside In

Beyond Basic Data Security

more Webcasts...


Search EarthWeb Network

internet.commerce
Be a Commerce Partner














esecurityplanet : Products & Services: Low-end ISS Firewalls Subject to DoS Attack

Related Articles
Study Shows Attack Activity Increasing
Driveby Hacking on the Go
eSecurity Glossary
biometrics
encryption
keylogger
malware
phishing
RFID
security
spyware
virus
worm
Search for more eSecurity terms ...
FREE Tech Newsletters

Low-end ISS Firewalls Subject to DoS Attack
February 11, 2002
By eSecurityPlanet.com Staff

Internet Security Systems (ISS) has announced that its BlackICE Defender and BlackICE Agent desktop firewall/intrusion detection systems (IDS) and potentially its RealSecure Server Sensor products may be subject to a denial of service vulnerability that allows intruders to execute code on targeted computers.

ISS issued a series of patches for the flaw that cover the various products in question. An advisory posted here contains links to the patches.

The BlackICE products combine firewall and IDS functions and are intended for home and small-office users. RealSecure Server Sensor is an enterprise-level product intended to identify and respond to attacks targeted at individual servers.

The routine the products use to capture transmitted packets contains a flaw that allows memory of the host system to be overwritten. ISS says it may be possible for hackers to control which areas of memory are overwritten, potentially enabling the intruder to execute arbitrary code on the systems.

The type of attack the vulnerability is susceptible to is based on the Internet Control Message Protocol (ICMP), which is used to send error and control messages. Given that most corporate firewalls can block ICMP messages from external IP addresses, the vulnerability is not likely to affect corporate users, ISS says.

Specific ISS systems that are affected by the flaw include the Windows 2000 and XP versions of: BlackICE Defender 2.9 and BlackICE Defender for Server 2.9; BlackICE Agent for Workstation 3.0 and 3.1; BlackICE Agent for Server 3.0 and 3.1.

The attack also may affect RealSecure Server Sensor 6.01 and 6.5 on Windows 2000, although ISS says attack results are inconsistent on those systems.

 

Tools:
Add www.esecurityplanet.com to your favorites
Add www.esecurityplanet.com to your browser search box
IE 7 | Firefox 2.0 | Firefox 1.5.x
Receive news via our XML/RSS feed

Products & Services Archives








JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers