Dear Customer:
If you are not hosting a Dedicated Server which operates on Microsoft Windows Server Operating System, you may ignore this message.
It has been brought to our attention that Microsoft is investigating new public reports of attack exploiting a vulnerability in the Domain Name System (DNS) Server Service in Microsoft Windows 2000 Server Service Pack 4, Windows Server 2003 Service Pack 1, and Windows Server 2003 Service Pack 2.
Please refer to Microsoft Advisory Article located at: http://www.microsoft.com/technet/security/advisory/935964.mspx
Fellow researchers at myNetWatchman are stating, that recently a flaw was discovered in the Microsoft DNS (Domain Name Services) Server's RPC (Remote Procedure Call) management server. This flaw is being actively exploited in the wild NOW on a limited scale but activity is expected to increase very soon. If your server is running Microsoft DNS Service with RPC over TCP (135/tcp) enabled with unrestricted remote access (e.g. NOT firewalled), then it is VULNERABLE TO THIS EXPLOIT. Compromise of this server could lead to compromise of ALL internal DNS clients that use this server as a DNS resolver!
As we always recommend, firewalling all servers with only necessary ports open is the best practice to follow. In this case if your Windows server is vulnerable if it is not firewalled properly.
We thank MyNetWatchman for proactive distribution of this information and Dan Kaminsky of DoxPara Research for this information.
If you suspect this server may already be compromised, feel free to run the myNetWatchman forensic scanner (SecCheck): http://mynetwatchman.com/tools/sc
If you are a Premier Managed Server Customer, the server management staff has already taken steps as recommended by Microsoft.
INFORMATION PROVIDED IN THIS EMAIL IS OFFERED TO YOU AS A CUSTOMER COURTESY. We do NOT GUARANTEE ACCURACY OF THIS INFORMATION. WE DO NOT HAVE FURTHER INFORMATION ON THIS MATTER AND THUS WE ASK OUR CUSTOMERS NOT TO OPEN SUPPORT TICKETS REGARDING THIS. OUR SYSTEM ENGINEERS WILL NOT BE ABLE TO ASSIST YOU WITH TASKS AND OR QUESTIONS RELATING TO THIS. PLEASE REFER TO MICROSOFT WEBSITE FOR MORE INFORMATION.
Customer Service
|