99c.org
Windows Firewall flaw may leave you wide open
Posted on 09.03.05 by templeton @ 2:37 pm

A flaw in Windows Firewall may prevent users from seeing all the open network ports on a Windows XP or Windows Server 2003 computer.

The flaw manifests itself in the way the security application handles some entries in the Windows Registry, Microsoft said in a security advisory published Wednesday. The Windows Registry stores PC settings and is a core part of the operating system.

The bug could allow a firewall port to be open without the user being informed through the standard Windows Firewall user interface, according to the Microsoft advisory. The company has released a fix that can be downloaded from Microsoft’s Web site and will be part of a future Windows service pack, the company said.

Microsoft said the firewall issue is not a security vulnerability but said the flaw could be used by an attacker who already compromised a system in an attempt to hide exceptions in the firewall.

For example, miscreants who have penetrated a computer could create and hide a firewall exception by inserting a malformed Windows Firewall exception entry in the Windows Registry. “An attacker who already compromised the system would create such malformed registry entries with the intent to confuse a user,” Microsoft said.

Like other firewall software, Windows Firewall is meant to block incoming traffic to a computer. Users can allow incoming connections by creating exceptions. Windows Firewall displays these exceptions in the firewall UI, which can be reached by going to the Windows Control Panel and selecting Windows Firewall.

PC users can view all firewall exceptions—including those the unpatched Windows Firewall doesn’t see—through other tools, Microsoft notes. Typing “netsh firewall show state verbose = ENABLE” at a command prompt will display all active exceptions, the company said in its advisory.

—-
Download the fix


Filed under: Security
Comments:

1 Comment »

No comments yet.

RSS feed for comments on this post. TrackBack URI

Leave a comment

Line and paragraph breaks automatic, e-mail address never displayed, HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>




Shorten URL




 Engadget

 Privacy


 Open Source


Recent Stories
» Apple cuts copy protection and prices on iTunes (AP)
» Apple disappoints: No Jobs or big news at Macworld (Reuters)
» Social Security unveils new online application (AP)
» Apple Unveils New MacBook Pro, Drops DRM for iTunes (NewsFactor)
» Apple disappoints--no Jobs or big news at Macworld (Reuters)
» Curl bolsters RIA data access (InfoWorld)
» Model wants Google to identify anonymous commenter (AP)
» Best Buy Offers Refurbished IPhones (PC World)
» Fake celeb LinkedIn profiles lead to malware (CNET)
» Truphone adds Skype, Twitter to iPhone client (CNET)
» Apple cuts copy protection and prices on iTunes (AP)
» Even in recession, CES to have stuff worth seeing (AP)
» Apple's Jobs has hormone imbalance, will stay CEO (AP)
» Logitech to cut salaried staff by 15 percent (AP)
» Fake celeb LinkedIn profiles lead to malware (CNET)