Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Latest News

      Windows XP: Raw Nerve?

      Written by

      eWEEK EDITORS
      Published October 15, 2001
      Share
      Facebook
      Twitter
      Linkedin

        eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

        Windows XP is set for an extravagant New York City launch on Oct. 25, but the debate over the security of an element called “raw sockets” in Microsofts latest operating system release will rage for quite a bit longer.

        Steve Gibson, an independent software developer who has written several security programs, has been waging a public campaign since July against Microsofts inclusion of raw sockets in Windows XP. He has alleged that raw sockets – a TCP/IP feature included in XP for backward compatibility, but that also lets an application generate bogus IP headers – will soon make it much more difficult to prevent distributed denial-of-service (DDoS) attacks, which already occur frequently on the Internet.

        “If I brought this up a year and a half ago, [Microsoft] might have fixed it, but it didnt see the danger until it was too late,” Gibson said. To date, he said, no one at Microsoft has taken seriously his worries about raw sockets.

        A denial-of-service attack is the sending of a large number of data packets to a single resource on the Internet, usually a Web or application server, effectively disabling it. A DDoS attack is more virulent because it involves taking control of hundreds or thousands of PCs by using zombies, software programs that let hackers make those PCs into the minions that launch the attack. Raw sockets could amplify that threat by making IP-spoofing readily available to hacker tools.

        Microsoft adamantly refuted Gibsons claim that XPs support of raw sockets makes it a security problem. A Microsoft spokeswoman pointed out that Apple Computers Mac OS, Linux, Unix and Microsofts own Windows 2000 have all implemented raw sockets. She also noted that DDoS attacks have been launched using versions of Windows that didnt support raw sockets.

        But Gibson countered that while the raw sockets feature was implemented in previous OSes, those operating systems werent as widely used by consumers as Windows XP is expected to be. He also said raw sockets dont make it easier to launch a DDoS attack, but instead makes it more difficult to defend against one.

        Even one of Microsofts resellers expressed concern that the raw sockets in Windows XP will increase its susceptibility to hacking. “Its one less hoop that a hacker has to jump through,” said Richard Blair, a senior consultant of Chicagos SEI Information Technology, a consulting firm that is a Microsoft Gold Certified Partner.

        Other security experts were divided about the impact of raw sockets in Windows XP.

        “Im not sure it makes the situation any worse,” said Ted Julian, chief strategist of Arbor Networks, a developer of anti-DDoS software. Individual users, by securing their machines and networks against hacker intrusions, can do much more to reduce the threat of DDoS attacks than Microsoft or any single entity can, he said.

        But Microsoft could help mitigate some of the security risk by making it harder for hackers to create DDoS tools, said Keith Waldorf, co-founder and chief technology officer of Captus Networks, which also provides a DDoS defense product.

        “What were going to see if Microsoft continues down this path is that denial-of-service tools will be easier to implement and cause more problems for the Internet community as a whole,” Waldorf said.

        Matrix Editor Todd Spangler contributed to this report.

        eWEEK EDITORS
        eWEEK EDITORS
        eWeek editors publish top thought leaders and leading experts in emerging technology across a wide variety of Enterprise B2B sectors. Our focus is providing actionable information for today’s technology decision makers.

        Get the Free Newsletter!

        Subscribe to Daily Tech Insider for top news, trends & analysis

        Get the Free Newsletter!

        Subscribe to Daily Tech Insider for top news, trends & analysis

        MOST POPULAR ARTICLES

        Artificial Intelligence

        9 Best AI 3D Generators You Need...

        Sam Rinko - June 25, 2024 0
        AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
        Read more
        Cloud

        RingCentral Expands Its Collaboration Platform

        Zeus Kerravala - November 22, 2023 0
        RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
        Read more
        Artificial Intelligence

        8 Best AI Data Analytics Software &...

        Aminu Abdullahi - January 18, 2024 0
        Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
        Read more
        Latest News

        Zeus Kerravala on Networking: Multicloud, 5G, and...

        James Maguire - December 16, 2022 0
        I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
        Read more
        Video

        Datadog President Amit Agarwal on Trends in...

        James Maguire - November 11, 2022 0
        I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
        Read more
        Logo

        eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

        Facebook
        Linkedin
        RSS
        Twitter
        Youtube

        Advertisers

        Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

        Advertise with Us

        Menu

        • About eWeek
        • Subscribe to our Newsletter
        • Latest News

        Our Brands

        • Privacy Policy
        • Terms
        • About
        • Contact
        • Advertise
        • Sitemap
        • California – Do Not Sell My Information

        Property of TechnologyAdvice.
        © 2024 TechnologyAdvice. All Rights Reserved

        Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

        ×