Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 26

Thread: New Windows Vuln. worse than WMF?

  1. #11
    Gonzo District BOFH westin's Avatar
    Join Date
    Jan 2006
    Location
    SW MO
    Posts
    1,187
    My apologies. I only half-way checked for duplicate posts... I am pretty new to AO
    \"Those of us that had been up all night were in no mood for coffee and donuts, we wanted strong drink.\"

    -HST

  2. #12
    Gonzo District BOFH westin's Avatar
    Join Date
    Jan 2006
    Location
    SW MO
    Posts
    1,187
    My apologies. I only half-way checked for duplicate posts... I am pretty new to AO
    \"Those of us that had been up all night were in no mood for coffee and donuts, we wanted strong drink.\"

    -HST

  3. #13
    Senior Member
    Join Date
    Jan 2003
    Posts
    3,915
    Hey Hey,

    Relyt: [off topic] I've never mentioned this but that was almost my original internet nick... a friend suggested it.. [/off topic] Now... I wouldn't say that you've already posted about this... I think their substantially different... You posted about the updates being available... this is more of a discussion on the impact of one of the flaws... I'd saw it warrants it's own discussion but then again that's just my opinion...

    As for the subject at hand... I don't think I agree with Litchfield.... It's definatey bad... but I don't see it as being worse than the WMF flaw.... This become public when the patch was released.... It wasn't previously published and there's no 0-day available for it... with the WMF there was.... Large corporation which wouldn't or couldn't trust the 3rd party patch were left vulnerable in many cases... in this case they simply have to apply the update... Will some people likely be "owned" by this.... no doubt... but most people will be fully patched (at the exchange level)... before a public exploit (or even a private one) starts circulating and causing damage.. So we're left with home users.. Outlook Vuln vs Outlook/IE vuln... both have patches available now... and the WMF is vulnerable to a broader form of attacks.. if you didn't update your computer... then you are vulnerable to both.. and with the broader scope.. it's more likely that WMF would affect the person...

    Then again... Security companies are becoming more and more popular these days... they seem to spring up over night in some cases... and I think that has the existing companies scrambling... before they had labs were they could analyze stuff that the average geek never could... with the latest technology that has changed... I could have a large test environment in my house for reasonably cheap.. anyone can search for and locate vulns... and it just keeps getting easier with some of the tools out there... This means they need a way to convince people that they're still needed.. that there's a reason to pay for software when free alternatives are available... to make people think they are better... NGS discovered TNEF... that's why they're saying it's worse... so that they'll look like the bigger hero.. so they must be smarter... A lot of this is just PR... The patch is out.. therefore it's not the end of the world... They're just trying to drum up business now..

    Peace,
    HT

  4. #14
    Senior Member
    Join Date
    Jan 2003
    Posts
    3,915
    Hey Hey,

    Relyt: [off topic] I've never mentioned this but that was almost my original internet nick... a friend suggested it.. [/off topic] Now... I wouldn't say that you've already posted about this... I think their substantially different... You posted about the updates being available... this is more of a discussion on the impact of one of the flaws... I'd saw it warrants it's own discussion but then again that's just my opinion...

    As for the subject at hand... I don't think I agree with Litchfield.... It's definatey bad... but I don't see it as being worse than the WMF flaw.... This become public when the patch was released.... It wasn't previously published and there's no 0-day available for it... with the WMF there was.... Large corporation which wouldn't or couldn't trust the 3rd party patch were left vulnerable in many cases... in this case they simply have to apply the update... Will some people likely be "owned" by this.... no doubt... but most people will be fully patched (at the exchange level)... before a public exploit (or even a private one) starts circulating and causing damage.. So we're left with home users.. Outlook Vuln vs Outlook/IE vuln... both have patches available now... and the WMF is vulnerable to a broader form of attacks.. if you didn't update your computer... then you are vulnerable to both.. and with the broader scope.. it's more likely that WMF would affect the person...

    Then again... Security companies are becoming more and more popular these days... they seem to spring up over night in some cases... and I think that has the existing companies scrambling... before they had labs were they could analyze stuff that the average geek never could... with the latest technology that has changed... I could have a large test environment in my house for reasonably cheap.. anyone can search for and locate vulns... and it just keeps getting easier with some of the tools out there... This means they need a way to convince people that they're still needed.. that there's a reason to pay for software when free alternatives are available... to make people think they are better... NGS discovered TNEF... that's why they're saying it's worse... so that they'll look like the bigger hero.. so they must be smarter... A lot of this is just PR... The patch is out.. therefore it's not the end of the world... They're just trying to drum up business now..

    Peace,
    HT

  5. #15
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    there's no 0-day available for it
    ERROR: There has been an error in the trust module. Windows XP has prepared an error report. Would you like to send this report to Microsoft.
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

  6. #16
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    there's no 0-day available for it
    ERROR: There has been an error in the trust module. Windows XP has prepared an error report. Would you like to send this report to Microsoft.
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

  7. #17
    BIOS Bomber
    Join Date
    Jul 2003
    Location
    Michigan
    Posts
    357
    Originally posted here by Relyt
    When only Commodore 64's existed?

    heh i have one of those
    "When in doubt, use Brute Force."

    Never argue with an idiot. They'll drag you down to their level, then beat you with experience.

  8. #18
    BIOS Bomber
    Join Date
    Jul 2003
    Location
    Michigan
    Posts
    357
    Originally posted here by Relyt
    When only Commodore 64's existed?

    heh i have one of those
    "When in doubt, use Brute Force."

    Never argue with an idiot. They'll drag you down to their level, then beat you with experience.

  9. #19
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    ...and before Commodore's there were ZX-80/1's... I remember those fondly....
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

  10. #20
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    ...and before Commodore's there were ZX-80/1's... I remember those fondly....
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •