Dr. I Doctor's Informational Juggernaut

Platform: Windows XP with Service Pack 2 running Microsoft's integrated firewall
Microsoft Severity: CRITICAL
Actual Severity: CRITICAL
Service Pack 2 has a critical vulnerability which can give the entire Internet access to file and print services that Microsoft's integrated firewall is supposed to protect.
According to a knowledgebase article Microsoft released last week (#886185), a flaw in the way the firewall interprets network scopes results in the Internet being considered a local network (The "My network" subnet). This happens when the Windows dial-up adapter is used to make the Internet connection, which can be the case with both modem and broadband Internet services. In particular, PPP-over-Ethernet connections, favored by some cable and DSL providers, often use this approach.
Microsoft has a fix available.
If an XP user opens printer and/or file sharing to his local network (not uncommon), the same services then become accessible via the Internet. Microsoft says this is not a bug, but rather "a configuration setting that shipped with Windows XP that was not optimal, but that is not classified as a security vulnerability," (Gary Schare, Windows director of product management, in a copyrighted Network World story). You can hear the weasels being tortured in every word.
Dr. I. Doctor always recommends a hardware firewall, even at home, as the primary security for a network. Software firewalls built on general purpose operating systems like Windows are just too unreliable to count on as your first line of defense. A hardware firewall, consisting of purpose-built software running on a dedicated network appliance, has a much lower probability of catastrophic bugs like this one. And you can buy very good name-brand firewalls for as little as $50, so cost is no excuse.
Microsoft's KB bulletin on the problem:
http://support.microsoft.com/kb/886185
The downloadble hot fix:
Posted by mbeckman at December 21, 2004 10:57 AM

| Sun | Mon | Tue | Wed | Thu | Fri | Sat |
|---|---|---|---|---|---|---|
| 1 | ||||||
| 2 | 3 | 4 | 5 | 6 | 7 | 8 |
| 9 | 10 | 11 | 12 | 13 | 14 | 15 |
| 16 | 17 | 18 | 19 | 20 | 21 | 22 |
| 23 | 24 | 25 | 26 | 27 | 28 | 29 |
| 30 | 31 |
We welcome your comments and opinions and encourage lively debate on the issues. However, Penton Media reserves the right to delete or move any content that it may determine, in its sole discretion, violates or may violate its Terms of Use or is otherwise unacceptable. For more information, see Penton Media's Terms of Use.