Slashdot Mirror


BadTunnel Bug Hijacks Network Traffic, Affects All Windows Versions (softpedia.com)

An anonymous reader writes: Microsoft has just patched a vulnerability that affects all Windows versions ever released. Called BadTunnel, the security flaw allows attackers to pass as a WAPD or ISATAP server and intercept all network traffic. Exploitation is trivial and firewalls are natively designed to open the port through which the attack is carried out. BadTunnel can be triggered whenever the user clicks URI or UNC links/paths in Office files, IE, Edge, or other applications that support the URI/VNC scheme (and most do). Additionally, an attacker can carry out his attack from the other side of the world, and does not need to have a foothold on the victim's network. While recent Windows OS versions received patches, exploitation points remain open for non-supported Windows operating systems such as XP, Windows Server 2003, and others. For these operating systems, and for those that can't be updated just yet, system administrators should disable NetBIOS.

1 of 105 comments (clear)

  1. Re:WinXP Patch? by phrostie · · Score: 5, Funny

    just upgrade to Win 10 and everything will be ok.
    let go of your old OS and let MS set you free.

    for a limited time only.