ad info




CNN.com
 MAIN PAGE
 WORLD
 U.S.
 LOCAL
 POLITICS
 WEATHER
 BUSINESS
 SPORTS
* TECHNOLOGY
   computing
   personal technology
 SPACE
 HEALTH
 ENTERTAINMENT
 BOOKS
 TRAVEL
 FOOD
 ARTS & STYLE
 NATURE
 IN-DEPTH
 ANALYSIS
 myCNN

 Headline News brief
 news quiz
 daily almanac

  MULTIMEDIA:
 video
 video archive
 audio
 multimedia showcase
 more services

  E-MAIL:
Subscribe to one of our news e-mail lists.
Enter your address:
Or:
Get a free e-mail account

 DISCUSSION:
 message boards
 chat
 feedback

  CNN WEB SITES:
CNN Websites
 AsiaNow
 En Español
 Em Português
 Svenska
 Norge
 Danmark
 Italian

 FASTER ACCESS:
 europe
 japan

 TIME INC. SITES:
 CNN NETWORKS:
Networks image
 more networks
 transcripts

 SITE INFO:
 help
 contents
 search
 ad info
 jobs

 WEB SERVICES:

COMPUTING

Sun says fixes in place to stop attacks on Solaris servers

January 10, 2000
Web posted at: 12:12 p.m. EST (1712 GMT)

by Brian Fonseca

From...
InfoWorld
Image

(IDG) -- Sun Microsystems admits that many of its servers have been victimized by Denial of Service (DoS) attacks during the past few months, but in the same breath says the problem has been fixed. It's just that users aren't taking advantage of the patches that are readily available.

"The solution for the problem has been issued already. This is a problem that's come and gone," said Russell Castronoval, public relations manager for Sun Solaris. "They [the attacks] can happen if a person hasn't kept things up to date."

In some cases, Sun released operating system patches as much as six months ago as a deterrent to DoS attacks, Castronoval said.

Patches are available for Solaris 2.5.1 (Sparc and Intel), Solaris 2.6 (Sparc and Intel), and Solaris 7 (Sparc and Intel), at sunsolve.sun.com.

MORE COMPUTING INTELLIGENCE
IDG.net   IDG.net home page
  InfoWorld home page
  What Sun needs to do to improve Solaris
  Unlocking Solaris
  Getting to know the Solaris filesystem

The DoS attacks capable of crippling Sun servers have come in the form of Trojan-horse software attacks implementing stacheldratht -- the German for "barbed wire" -- trin00, the Tribal Flood Network, and TFN 2000, according to alerts by the Computer Emergency Response Team (CERT), the National Infrastructure Protection Center (NPIC), and the SANS Institute.

The trojans are deployed by master computers to assemble and control the infected machines with commands to continuously bombard sites with bogus flood packets, ultimately clogging up the traffic stream and shutting down sites both large and small, including Solaris-run sites.

Researchers from the SANS Institute said the most common paths used to compromise systems to insert trojans have been weaknesses in remote procedure call (RPC) implementation.



RELATED STORIES:
Sun apologizes to developers of Java on Linux
December 10, 1999
Sun CEO says Microsoft still doesn't get the Net
December 9, 1999
Sun cancels Java standard plans
December 9, 1999
Vendors to give Java a shot in the arm
December 8, 1999
10 companies that will make the Web grow
November 24, 1999

RELATED IDG.net STORIES:
What Sun needs to do to improve Solaris
(SunWorld)
Solaris 8 for data centers.com
(IDG.net)
Keeping time with Solaris
(SunWorld)
Unlocking Solaris
(SunWorld)
Will Solaris 'community source' have an impact?
(Computerworld)
Getting to know the Solaris filesystem
(SunWorld)
Solaris 7: Is this OS for you?
(SunWorld)
Year 2000 World
(Year 2000 World)
Note: Pages will open in a new browser window
External sites are not endorsed by CNN Interactive.

RELATED SITES:
Sun Microsystems
SunSolve
Note: Pages will open in a new browser window
External sites are not endorsed by CNN Interactive.
 LATEST HEADLINES:
SEARCH CNN.com
Enter keyword(s)   go    help

Back to the top   © 2001 Cable News Network. All Rights Reserved.
Terms under which this service is provided to you.
Read our privacy guidelines.