Security 11021 Published by Philipp Esselbach 0

Microsoft products may not be alone in contributing to the spread of the SQL Slammer worm, security researchers said on Wednesday. Other companies also make products containing the Microsoft database software that has been exploited by the worm. More than 30 products, from security scanners to backup servers, use the vulnerable Microsoft SQL Server 2000 and Microsoft SQL Desktop Edition (MDSE) 2000 software, according to a list compiled by database security site SQLSecurity.com.

Read more

Security 11021 Published by Philipp Esselbach 0

Still patching your SQL Server databases? Well, be sure not to miss the post-Slammer sale!

The new W32.Slammer worm, a nuisance for network administrators worldwide, has turned into a marketing boon for companies that sell a wide range of technology products and services.

Read more

Security 11021 Published by Philipp Esselbach 0

As corporate IT departments go about the business of cleaning up their networks, there are strong indications that the SQL Slammer worm that brought down portions of the Internet over the weekend is based on the work of an obscure Chinese cracking group.

Signatures within the worm's source code indicate that a group known as the Honker Union of China-also known as the Hacker Union of China-may be responsible for writing the code, according to security experts who have analyzed the code. However, experts caution that although they are certain of the code's origins, someone else may have actually loosed the worm on the Internet.

Read more

Security 11021 Published by Philipp Esselbach 0

Microsoft's policy of relying on software patches to fix major security flaws was questioned Monday after a series of internal e-mails revealed that the software giant's own network wasn't immune from a worm that struck the Internet last weekend.

Read more

Security 11021 Published by Philipp Esselbach 0

More than 48 hours since it first appeared, the spread of a new worm that targets servers running the Microsoft SQL Server database software had slowed and there had been no repeats of the major disruption caused to the Internet on Saturday.

Read more

Security 11021 Published by Philipp Esselbach 0

Microsoft has released a new security patch for Outlook 2002:

Flaw in how Outlook 2002 handles V1 Exchange Server Security Certificates could lead to Information
Microsoft Outlook 2002 provides the facility to encrypt e-mails sent between e-mail recipients. Encryption is used to prevent parties other than the intended recipients from reading the contents of an e-mail. Outlook uses public key certificates to facilitate the exchange of the cryptographic keys that are used in the encryption process, and Outlook offers a number of different options as to what type of certificates can be used. S/MIME certificates are the most commonly used (and are not affected by the vulnerability that is the subject of this bulletin), but there are other certificate options including V1 Exchange Server Security certificates.

A vulnerability exists because there is a flaw in the way Outlook
2002 handles a V1 Exchange Server Security certificate when using it to encrypt e-mail. As a result of this flaw, Outlook fails to encrypt the mail correctly and the message will be sent in plain text. This could cause the information in the e-mail to be exposed when the user believed it to be protected through encryption.
Read more