To register for an Internet.com membership to receive newsletters and white papers, use the Register button ABOVE.
To participate in the message forums BELOW, click here


EIT Planet's Security News
 Symantec Warns of New Security Breach
 Security Vulnerabilities Prove Increasingly Costly
 IPS Market Approaches $1 Billion

Security Products
 BugBopper (BugBopper)
 VBA Password Remover Tool (VBA Password Remover)
 VBA Password Remover Software (VBA Password Remover Software)
 Free keylogger download (Free keylogger download)
 Monitoring Software (Monitoring software)
 Retrieve Outlook 2007 Password (Retrieve PST Password)


Go Back   Antionline Forums - Maximum Security for a Connected World > Security Discussions > Microsoft Security Discussions

Microsoft Security Discussions Discuss security issues related to microsoft products.

Reply
 
Thread Tools Display Modes
Old February 6th, 2010, 01:14 PM   #1
ByTeWrangler
StOrM™
 
Join Date: Aug 2004
Posts: 988
ByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond repute
Microsoft to patch 17-year-old computer bug

I don't have words to describe this one..


http://news.bbc.co.uk/2/hi/technology/8499859.stm
__________________
Parth Maniar,
CISSP, CISM, CISA, SSCP

*Thank you GOD*

Greater the Difficulty, SWEETER the Victory.

Believe in yourself.
ByTeWrangler is offline   Reply With Quote
Old February 6th, 2010, 04:11 PM   #2
westin
Gonzo District BOFH
 
westin's Avatar
 
Join Date: Jan 2006
Location: SW MO
Posts: 933
westin has a reputation beyond reputewestin has a reputation beyond reputewestin has a reputation beyond reputewestin has a reputation beyond reputewestin has a reputation beyond reputewestin has a reputation beyond reputewestin has a reputation beyond reputewestin has a reputation beyond reputewestin has a reputation beyond reputewestin has a reputation beyond reputewestin has a reputation beyond repute
Wow... just... wow.

Kind of makes you want to switch to a less targeted OS?
__________________
\"Those of us that had been up all night were in no mood for coffee and donuts, we wanted strong drink.\"

-HST
westin is online now   Reply With Quote
Old February 6th, 2010, 06:50 PM   #3
gore
AO BOFH: Luser Abuser BModeratorFH
 
gore's Avatar
 
Join Date: Oct 2002
Location: Michigan
Posts: 6,649
gore has a reputation beyond reputegore has a reputation beyond reputegore has a reputation beyond reputegore has a reputation beyond reputegore has a reputation beyond reputegore has a reputation beyond reputegore has a reputation beyond reputegore has a reputation beyond reputegore has a reputation beyond reputegore has a reputation beyond reputegore has a reputation beyond repute
Lol you mean like DOS? I'm starting to wonder if they were really just tired of fixing it and said switch to Windows now.

Man....17 years of the same thing sitting there ready to be exploited, and NO ONE fixed it. I wonder if they're going to change those ads about how they take care of problems better than Linux does now. (Remember? With Linux you're waiting on a kid in China to fix your exploit, with Windows, we fix them!"....)....

I don't think I've ever heard of a bug going for this long ever. Anyone know if this is a record?
__________________
Kill the lights, let the candles burn behind the pumpkins’ mischievous grins, and let the skeletons dance. For one thing is certain, The Misfits have returned and once again everyday is Halloween.The Misfits We Are 138
Cannibal Holocaust
SuSE Linux
Slackware Linux
gore is offline   Reply With Quote
Old February 6th, 2010, 08:13 PM   #4
keezel
0_o Mastermind
 
keezel's Avatar
 
Join Date: Jun 2003
Location: Atlanta
Posts: 1,009
keezel has a reputation beyond reputekeezel has a reputation beyond reputekeezel has a reputation beyond reputekeezel has a reputation beyond reputekeezel has a reputation beyond reputekeezel has a reputation beyond reputekeezel has a reputation beyond reputekeezel has a reputation beyond reputekeezel has a reputation beyond reputekeezel has a reputation beyond reputekeezel has a reputation beyond repute
HAHAHAHAHA!!

Wow. Good job Microsoft.

And the ad campaign about "some kid in China" is hysterical. As if Linux is still primarily supported by random freelance coders. They are totally exploiting that misnomer.

Maybe we should go easy on them. After all, Microsoft bloatware is huge and hard to fully patch.

But then again, 17 years?! Wow.
__________________


http://tazforum.thetazzone.com/
keezel is offline   Reply With Quote
Old February 6th, 2010, 09:32 PM   #5
gore
AO BOFH: Luser Abuser BModeratorFH
 
gore's Avatar
 
Join Date: Oct 2002
Location: Michigan
Posts: 6,649
gore has a reputation beyond reputegore has a reputation beyond reputegore has a reputation beyond reputegore has a reputation beyond reputegore has a reputation beyond reputegore has a reputation beyond reputegore has a reputation beyond reputegore has a reputation beyond reputegore has a reputation beyond reputegore has a reputation beyond reputegore has a reputation beyond repute
Wasn't it the big Steve who said that originally? The part about "Well yea Linux has customers but do you really want to have to tell your boss the system will be patched once some 12 year old in China is done writing it?" ... I can't remember the exact quote but it was along those lines about a kid in China being the one writing your patches.

I think he was pissed off because people have seen a problem in Linux where there was an exploit possible, and within like 4 hours, there was a patch. The same problem popped up on a few other OSs and it took like a month to get one.
__________________
Kill the lights, let the candles burn behind the pumpkins’ mischievous grins, and let the skeletons dance. For one thing is certain, The Misfits have returned and once again everyday is Halloween.The Misfits We Are 138
Cannibal Holocaust
SuSE Linux
Slackware Linux
gore is offline   Reply With Quote
Old February 7th, 2010, 12:01 PM   #6
nihil
Super Moderator: GMT Zone
 
nihil's Avatar
 
Join Date: Jul 2003
Location: United Kingdom: Bridlington
Posts: 15,990
nihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond repute
Quote:
Kind of makes you want to switch to a less targeted OS?
Not really..................you need an authenticated login and physical access from what I can see?

Hell! I am looking at a CD on my desk that will reset the admin password from bootup................no login required.

I am still of the opinion that if someone has unrestricted physical access you are as good as owned.

Anyway, it took 17 years to find it..............hardly earth shattering?
__________________
If you cannot do someone any good: don't do them any harm....
As long as you did this to one of these, the least of my little ones............you did it unto Me.
nihil is offline   Reply With Quote
Old February 7th, 2010, 02:49 PM   #7
ByTeWrangler
StOrM™
 
Join Date: Aug 2004
Posts: 988
ByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond repute
Since it took me lot of time to find words to describe this one (abuse basically). I've decided to switch to Linux. OpenSuse, buddy i love you..
__________________
Parth Maniar,
CISSP, CISM, CISA, SSCP

*Thank you GOD*

Greater the Difficulty, SWEETER the Victory.

Believe in yourself.
ByTeWrangler is offline   Reply With Quote
Old February 7th, 2010, 03:22 PM   #8
nihil
Super Moderator: GMT Zone
 
nihil's Avatar
 
Join Date: Jul 2003
Location: United Kingdom: Bridlington
Posts: 15,990
nihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond reputenihil has a reputation beyond repute
Well,

1. I don't believe in security through obscurity as a general principle.
2. I will certainly stay where the money is (Microsoft).
3. What makes you think that Linux is any better?..............if I have physical access and a password you are owned.

Do you still run 16bit applications?...............I do, and have Windows 3.11, 98, 98SE and ME boxes for that. They are mostly games that won't work in compatibility mode anyway, because they want to directly access the hardware and do other things that 2000, XP, Vista and 7 don't allow.

This is the fix:

1.
Click Start, click Run, type gpedit.msc in the Open box, and then click OK.
This opens the Group Policy console.
1.
Expand the Administrative Templates folder, and then click Windows Components.
2.
Click the Application Compatibility folder.
3.
In the details pane, double click the Prevent access to 16-bit applications policy setting. By default, this is set to Not Configured.
4.
Change the policy setting to Enabled, and then click OK.
Impact of Workaround: Users will not be able to run 16-bit applications.


REMEMBER: You have to make the change in both User and Computer settings. If it isn't turned off in Computer settings it will be allowed because they override the User settings


No big deal as far as I am concerned.
__________________
If you cannot do someone any good: don't do them any harm....
As long as you did this to one of these, the least of my little ones............you did it unto Me.
nihil is offline   Reply With Quote
Old February 7th, 2010, 03:50 PM   #9
ByTeWrangler
StOrM™
 
Join Date: Aug 2004
Posts: 988
ByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond reputeByTeWrangler has a reputation beyond repute
Nihil how dare you come in defense of Microsoft.. I write this from my Opensuse using Opera (and after uninstalling Firefox)..
__________________
Parth Maniar,
CISSP, CISM, CISA, SSCP

*Thank you GOD*

Greater the Difficulty, SWEETER the Victory.

Believe in yourself.

Last edited by ByTeWrangler; February 7th, 2010 at 04:01 PM..
ByTeWrangler is offline   Reply With Quote
Old February 7th, 2010, 10:03 PM   #10
The-Spec
BANNΕD
 
The-Spec's Avatar
 
Join Date: Jan 2008
Posts: 455
The-Spec has a brilliant futureThe-Spec has a brilliant futureThe-Spec has a brilliant futureThe-Spec has a brilliant futureThe-Spec has a brilliant futureThe-Spec has a brilliant futureThe-Spec has a brilliant futureThe-Spec has a brilliant futureThe-Spec has a brilliant futureThe-Spec has a brilliant futureThe-Spec has a brilliant future
The thing about linux is these distros either lie or spend so much time repackaging stuff they have no idea whats-what themselves. They'll sit there and call something a "local denial of service flaw" for five years intil someone changes a single byte in the return address. People know better than that... you don't just make something seg fault at ring-0.

Meh... people don't want to admit there are more kernal flaws out there than the number of waves in the pacific ocean.
__________________
The-Spec is offline   Reply With Quote
Reply

Bookmarks

Tags
community driven software

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
August security hotfixes mohaughn Microsoft Security Discussions 1 August 9th, 2005 07:37 PM
Spyware/Maleware User Agreements moxnix Spyware / Adware 7 July 8th, 2004 01:42 PM
suse is crap on finding cdrom rajunpl Operating Systems 43 July 1st, 2004 07:30 AM
The history of the Mac line of Operating systems gore Operating Systems 3 March 7th, 2004 07:02 AM
Securing Your Windows PC E5C4P3 The Security Tutorials Forum 10 June 12th, 2002 04:54 PM


All times are GMT +1. The time now is 03:59 PM.












Acceptable Use Policy

Internet.com
The Network for Technology Professionals

Search:

About Internet.com

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | E-mail Offers

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.