-----BEGIN PGP SIGNED MESSAGE-----

===========================================================================
              AUSCERT External Security Bulletin Redistribution
                             
            ESB-2001.010 -- Microsoft Security Bulletin MS00-099
Patch Available for `Directory Service Restore Mode Password' Vulnerability 
                               10 January 2000

===========================================================================

	AusCERT Security Bulletin Summary
	---------------------------------

Product:                Windows 2000 Server
                        Windows 2000 Advanced Server
Vendor:                 Microsoft
Operating System:       Windows 2000
Impact:                 Execute Arbitrary Code/Commands
Access Required:        Local

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----

======================================================================
Issue:             "Configure Your Server" tool creates blank
                   password for Directory Service Restore Mode
Date:              20 December 2000
Affected Software: Windows 2000 server and Advanced Server
Impact:            Install malicious code
Bulletin ID:       MS00-099
Bulletin:
   http://www.microsoft.com/technet/security/bulletin/MS00-099.asp
======================================================================

- -----BEGIN PGP SIGNATURE-----
Version: PGP Personal Privacy 6.5.3

iQEVAwUBOkDgSY0ZSRQxA/UrAQHr1gf7ByD96GHc8pOXkGYvJBWd2MXhfKpHecH3
ui10Z0Xynmj46jh0B6MDywRKL2IiaT2REGzBW7f1zEYjQAJpaTlqMZyLTt4KqlQt
YU1IcP0JskbN1VVD9aGAacvd1LtiPwccOd4+yZovygIYhzYwfGXLGMojQCOP4ydl
9VnUwRlUxVZXZoz3Mxmb7FPARZYBNqPZPS5OMOlTESqrGEjTWG2A4OIUMN7W0o+d
XqCIugrflUNDoUOrxriVWdqfuafZ9lhsgndb+BanBKPdmdQX4AGZFm2KYYz6YUW0
MIoroSHAn72BVR1FwtuzJVIhb59SJJ6R0XW8uCe2YtBzz4h0sYBY6w==
=m5Bs
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content.  The decision to use any or all of this information is
the responsibility of each user or organisation, and should be done so in
accordance with site policies and procedures.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the original authors to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

	http://www.auscert.org.au/Information/advisories.html

If you believe that your system has been compromised, contact AusCERT or
your representative in FIRST (Forum of Incident Response and Security
Teams).

Internet Email: auscert@auscert.org.au
Facsimile:	(07) 3365 7031
Telephone:	(07) 3365 4417 (International: +61 7 3365 4417)
		AusCERT personnel answer during Queensland business hours
		which are GMT+10:00 (AEST).
		On call after hours for emergencies.


-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv
Comment: ftp://ftp.auscert.org.au/pub/auscert/AUSCERT_PGP.key

iQCVAwUBOm/yyih9+71yA2DNAQHyNAP7Bw2/vlx4OKo5GeykeYI/TcoQt6dGbtYZ
0BEoILkEYGGU4HNszFpqmLgVNlOq4xXC/TBDYKPXcn9WeQyNQf6pR3P2DM5Uh+B1
f1sGRa93kMxLJT+1lKskq45zE6M2uypIcVcGxGwSrN5ETDzOMTeS3BMVrWSVYmes
FNHLk99zx/E=
=R0aN
-----END PGP SIGNATURE-----