MSN flaw highlights dangers of instant messaging
MSN flaw highlights dangers of instant messaging
R E L A T E D   C O N T E N T
ADVERTISEMENT

IM security threat still being ignored

Recent MSN incident should be seen as a wake up call, warns Gartner

Robert Jaques, vnunet.com 18 Feb 2005
ADVERTISEMENT

A recently discovered security flaw in MSN Messenger demonstrates that instant messaging (IM) presents a serious security threat and should act as a wake up call for enterprises, industry experts have warned.

According to Gartner, firms must "implement comprehensive IM policies now" after the MSN Messenger vulnerability prompted Microsoft to restrict access to its service in a bid to prevent the exploit from spreading.

Gartner senior analyst Lawrence Orans said: "The MSN Messenger exploit highlights the risks of not establishing and implementing an enterprise IM policy."

"The MSN Messenger client, like those for Yahoo Messenger, AOL Instant Messenger and other IM services, is available for download free of charge.

"As a result, IM is so widely used that most enterprises have no idea how many IM clients are installed on their systems or how much IM traffic passes through their networks."

The warning comes after Microsoft moved to lock out any users not running the latest versions of its MSN Messenger and Windows Messenger clients after proof of concept of a vulnerability was posted on the internet.

The problem centred on the inability of older versions of MSN Messenger and Windows Messenger to properly handle corrupted image files. By exploiting this vulnerability, an attacker could take control of an affected system.

"Microsoft acted quickly to control this malicious code outbreak by denying access to clients that were not up to date," said Orans.

"However, the next time an IM exploit emerges, Microsoft or another IM provider may not be able to respond as quickly or as effectively.

"Enterprises must take responsibility for ensuring that the use of IM does not compromise their security. If necessary, they must be able to temporarily shut it down when a serious security threat emerges."

Gartner advised that, because IM has become so popular, it is rapidly becoming unrealistic to block IM traffic entirely. In many enterprises, one or more business units can make a compelling case for the need to use the technology.

The analyst firm believes that enterprises have three options: implement an enterprise IM system; deploy a product that makes it possible to build policies around public IM services; or do both.

See also:

Complacency in IM management putting firms at serious risk  16 May 2005
IM threats increasing in frequency and pervasivenessViruses target firm's IM soft underbelly  09 Mar 2005
Microsoft to build 'presence awareness' into all future appsNew versions of Office real-time collaboration offerings  09 Mar 2005
Fatso.A worm spreads via MSN MessengerFatso.A squeezes onto hard drives with tirade at Bropia author  08 Mar 2005
Kelvir.B carries Spybot payloadSpammers on the look out for new recruits?  08 Mar 2005
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C# Web Developer, Finance, London Financial Services Required: C#, ASP.NET, AJAX Fantastic opportunity not to be missed!! This is a great opportunity to work on a unique objectives that no other company is doing working ... more >
| JAM Recruitment
Senior Hardware Engineer Scotland/Edinburgh Communication Systems Permanent Position 40-45K+Benefits A leading organisation involved with the design and development of data acquisition systems and synthesis boards for a range of radar, signal intelligence and software radio ... more >
| JAM Recruitment
FPGA Engineer Defence/Safety Critical Buckinghamshire Permanent Position 45K+Benefits A leading UK defence organisation requires an experienced digital design engineer to strengthen its existing development team due to a number of long-term projects that have recently ... more >
| JAM Recruitment
DSP Engineer 3 Months Contract Hertfordshire £Excellent Rates£ This position requires you to have experience of measurement algorithms development for the generation and analysis of digital wireless communication standards including GSM, EDGE, UMTS, WLAN and ... more >
More job opportunities