PDA

View Full Version : Great News for Windows Users


DrGuile
08-04-2005, 11:01 AM
http://techrepublic.com.com/2100-1009_11-5817400.html?tag=nl.e019

A serious flaw has been discovered in a core component of Windows 2000, with no possible work-around until it gets fixed, a security company said.

The vulnerability in Microsoft's operating system could enable remote intruders to enter a PC via its Internet Protocol address, Marc Maiffret, chief hacking officer at eEye Digital Security, said on Wednesday. As no action on the part of the computer user is required, the flaw could easily be exploited to create a worm attack, he noted.

What may be particularly problematic with this unpatched security hole is that a work-around is unlikely, he said.

"You can't turn this (vulnerable) component off," Maiffret said. "It's always on. You can't disable it. You can't uninstall."

eEye declined to give more details on the flaw or the Windows 2000 component in question. As part of company policy, it does not release technical details of the vulnerabilities it finds until the software's maker has released either a patch or an advisory.

A Microsoft representative said the software giant will issue a comment once it has had a chance to review the eEye advisory, which has yet to be posted on the security company's Web site.

The vulnerabilities affect Windows 2000, but Maiffret noted eEye is still conducting tests, and he anticipates other versions of Microsoft's OS will likely be affected.

For Microsoft, this marks the second eEye advisory it's received this week. On Monday, eEye notified the software giant it had found critical vulnerabilities in Internet Explorer.

The IE vulnerabilities could allow malicious attackers to launch a remote buffer overflow attack should users click on a malicious Web site link.

The flaw, which is rated as a "high" risk, affects IE, Windows XP and SP1, Windows 2003 and Windows 2000.

Microsoft confirmed it received the eEye advisory regarding IE through its standard vulnerability reporting system.

"We are investigating the report and will take appropriate action to help protect customers as part of our normal security response process," a Microsoft representative said. Microsoft issues a monthly bulletin of patches and also has a program of security advisories with work-arounds for unpatched, reported flaws.

Weg Cory
08-04-2005, 11:03 AM
I love my Mac. It is really pretty.

Peaches
08-04-2005, 11:04 AM
I love my Mac. It is really pretty.
West coast freak.

Nickatilynx
08-04-2005, 03:14 PM
Frenchie!!

Stop using all your PCs resources will ya!!!

I'm trying to mail.

;-))))

DrGuile
08-04-2005, 03:18 PM
that HDTV beastiality video is really a resources hog!


:D

Nickatilynx
08-04-2005, 03:34 PM
that HDTV beastiality video is really a resources hog!


:D

Sells well too.....


;-))

Newton
08-04-2005, 04:03 PM
Mandrake Linux ;)

Nickatilynx
08-04-2005, 04:04 PM
Mandrake Linux ;)

I thought your Jamacian boyfriend diodn't want his name posted?
;-))

Trev
08-04-2005, 04:11 PM
I'll stick with the devil I know, and take the odd shot of cyber penicillin every now and then.

Newton
08-04-2005, 04:30 PM
I thought your Jamacian boyfriend diodn't want his name posted?
;-))

I dont want your cast-offs but nice try lol I'll take his sister

RyanLanane
08-04-2005, 04:57 PM
Sells well too.....


;-))

So THAT's what you spammed all those years ?!??

I think it's incredibly intelligent for the company to announce to the world (which wow.. actually has thousands of serius hackers who could find this exploit in no time and use it) the exploits they find BEFORE Miscrosoft has a chance to do anything about them.

You would think it would go something along the lines of "Microsoft, we found an exploit and the solution.... We Want $x,xxx,xxx for the package. We will give you a brief overview of what the flaw is without showing you specifics"

The company makes millions, not news... Microsoft plugs their holes ... And we don't have to worry about hackers more now than we used to .. Yeesh!

I do think with the increasing amount of busines being done on the internet.. Hacking will become a much mor penalized crime this decade. Will be interesting to see...

DrGuile
08-04-2005, 05:01 PM
So THAT's what you spammed all those years ?!??

I think it's incredibly intelligent for the company to announce to the world (which wow.. actually has thousands of serius hackers who could find this exploit in no time and use it) the exploits they find BEFORE Miscrosoft has a chance to do anything about them.



They havent disclosed the flaw except to Microsoft. And for the hackers who could "easily find it", well they could have before, since 6 years ago when Win2k was released... so could have microsoft... and neither did.

Now, with a bit of public noise, you just know M$ will fix it.

Trev
08-04-2005, 06:17 PM
Run a check on how tight your MS/IE ship is:

http://grc.com/x/ne.dll?bh0bkyd2