LDAP blues: Server weakness throws up security fears

Denial-of-service threat revealed...

NEWS Researchers have uncovered a vulnerability in LDAP (lightweight directory access protocol) which has left thousands of web servers open to email bombardment by malicious attackers. According to the CERT security team at Carnegie Mellon University, the flaw leaves servers open to denial-of-service (DoS) attacks and enables unauthorised access from outside the network. The University of California estimates some 5,000 DoS attacks take place every week. LDAP is a simple and widely used protocol enabling companies to access and search directories of names, phone numbers, addresses stored on a variety of incompatible systems. Users running versions of IBM SecureWay, iPlanet Directory Server, Lotus Domino R5 Server, Network Associates' PGP Keyserver, Microsoft Exchange 5.5 LDAP Service, OpenLDAP, Oracle 8i Enterprise Edition, Qualcomm Eudora mail program and Teamware Office are at risk.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your silicon.com account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ

Get silicon.com's daily newsletter

  • Register on silicon.com

    Enter your email to register

Keep in touch with silicon.com

silicon.com newsletters