Security Software Zone Security Software Zone
Home Contact Us
Search in
Forum SecurityToolbox Submit Software
Security Software Zone Login
Security Software Categories
News - Articles - Reviews
Free Newsletter
Join our mailing list and receive
security software news and
advice from our experts.
Submit
  Security Software Zone » Software Reviews » General Security » Vista's tunnelling insecure!

Vista's tunnelling insecure!

Category: General Security
Published: 03/27/2007, 18:39  
Editor: Remus Zoica
 
Print article
Send to a friend
Search in reviews
    Teredo is the implementation of a tunnelling protocol in Windows Vista. A recent research from Symantec Advanced Threat Research shows that it has unforseen side-effects, Symantec said, among them that it could allow attackers to evade organisations security measures.
The report (PDF), called "Windows Vista Network Attack Surface Analysis", was prepared by Dr. James Hoagland, Matt Conover, Tim Newsham and Ollie Whitehouse. The researchers noted that Vista introduces a completely rewritten network stack, which means Vista will behave differently than Windows XP - something network administrators need to be wary of, according to Symantec.
In the symantec's research report we can find: "Tunnelling methods can be used to evade security controls, and that is what Teredo does (though that was not the intent). Unless network firewalls and IDSs are specifically aware of this protocol, they will not be applying the appropriate filtering to the IPv6 packet and its contents; this reduces defence-in-depth, and may result in a failure to apply important security controls."

    The tunnelling protocol Teredo is designed as a temporary measure to allow devices with IPv6-unaware NAT devices to take advantage of IPv6 connectivity; it encapsulates IPv6 packets within IPv4 UDP datagrams. One problem with this is that if administrators aren't aware Teredo is being used, it may help attackers gain access to targets on private internal networks, Symantec said. Many intrusion detection systems and firewalls are not currently aware of Teredo. If left unhandled and unchecked, IPv6 and its accompanying transition technologies allow an attacker access to hosts on private internal networks without the administrator expecting this global accessibility," the report said.

    The researchers found that Teredo is enabled by default, though dormant, and "that it was readily used, despite Microsoft's apparently inaccurate statements that downplay its level of activity". Another problems that the resarcher found was that Vista, in some cases, switches on Teredo without any intervention from the user. The operating system requires a firewall to be running to activate Teredo, but this measure, while "sensible", "cannot compensate for all of Teredo's problematic security implications," Symantec said. Microsoft has responded that the paper in fact validates Microsoft's design decisions in Vista, while acknowledging that improvements could be made.
    "We believe many of the most recent third-party [analyses] of Windows Vista, including this paper, [validate] many of the key design decisions made in the product. We look forward to further discussing the areas where Symantec has noted improvements could be made to benefit customers." Jim Hahn, a product manager for Microsoft's Windows Client Team, said in a statement.
Bookmark to:
Add 'Vista's tunnelling insecure!' to Del.icio.us Add 'Vista's tunnelling insecure!' to digg Add 'Vista's tunnelling insecure!' to FURL Add 'Vista's tunnelling insecure!' to reddit Add 'Vista's tunnelling insecure!' to Technorati Add 'Vista's tunnelling insecure!' to Yahoo My Web Add 'Vista's tunnelling insecure!' to Stumble Upon Add 'Vista's tunnelling insecure!' to Google Bookmarks Add 'Vista's tunnelling insecure!' to RawSugar Add 'Vista's tunnelling insecure!' to Squidoo Add 'Vista's tunnelling insecure!' to Spurl Add 'Vista's tunnelling insecure!' to Netvouz Add 'Vista's tunnelling insecure!' to Rojo Add 'Vista's tunnelling insecure!' to Bloglines Add 'Vista's tunnelling insecure!' to Tailrank
Add comment
Security Software Zone is not responsible for the content of these User comments. The views and opinions expressed are those of the individual poster and not the Security Software Zone.
User comments (0):

There is no comment for this review.

 
Reviews related to Vista's tunnelling insecure!
 

Real-Time Data Replication Solution for Windows Server 2008 Introduced by SteelEye
 SteelEye DataKeeper for Windows, a comprehensive data replication solution for Microsoft Windows Server 2003 and 2008 that makes real-time data replication cost-effective and accessible to small to medium-sized businesses has been announced by a leading provider of disaster recovery and business continuity solutions for multivendor IT infrastructures, SteelEye Technology Inc. (steeleye.com).
Read More >
06/16/2008, 09:21
 

PCSecurityShield and Yugster Founders
 Security and e-commerce innovator PCSecurityShield announces that it will be exhibiting at this year's eagerly anticipated ad:tech Conference in New York.
Read More >
01/09/2007, 09:41
 

BZ WBK Deploys Digital Signage to Provide a Better Customer Experience
 The leading provider of end-to-end digital signage software, Scala, announced that, in order to enhance their brand and provide a better customer experience, Bank Zachodni WBK S.A. has deployed a Scala digital signage network.
Read More >
08/23/2008, 11:45
 

Plug-and-Play NAC Appliance Released by Mirage Networks
 The introduction of a new appliance that brings complete NAC coverage in the form of a plug-and-play appliance has been announced by developer of patented, full-cycle Network Access Control (NAC) technology, Mirage Networks, announced. The MAX-500, this new appliance, gives customers everything they need in the industry’s most innovative deployment model.
Read More >
06/12/2008, 09:12
 

New BuzzLogic Service Empowers Marketers to Gain Visibility In To Social Media
 Software from BuzzLogic Enterprise enables marketers to identify key online influencers leading the conversations they care about within social media.
Read More >
04/18/2007, 03:18

Sponsored