Announcement

Collapse
No announcement yet.

Windows XP SP2 breached

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • #16
    Originally posted by Asher
    Don't use IE.
    Believe me, I don't. But I can't get rid of it, either, as you can't remove it from the OS. Then you run into one of those fscking IE-only websites..

    Eh? Windows NT 4.0 still gets critical security vulnerabilities patched. The latest was on January 17, 2005...: http://www.computerweekly.com/articl...earch=&nPage=1
    I stand partly corrected:
    On its security site, Microsoft said its engineers had carried out the bulk of the work on fixing the vulnerabilities before the end of 2004 and so it had decided to release a security update for the operating system version as part of its security bulletin.

    The company said it did not anticipate doing this for future vulnerabilities that may affect NT4, but added, "We reserve the right to produce updates and to make these updates available when necessary."

    It urged users running NT4 Server to migrate to supported operating system versions to prevent potential exposure to vulnerabilities.
    "If you doubt that an infinite number of monkeys at an infinite number of typewriters would eventually produce the combined works of Shakespeare, consider: it only took 30 billion monkeys and no typewriters." - Unknown

    Comment


    • #17
      Still, comparing NT4 to kernel 2.2 or even 2.0 is a bit unfair. NT4 predates both of those by years, as well.
      "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
      Ben Kenobi: "That means I'm doing something right. "

      Comment


      • #18
        Looks like this is officially nothing but hysteria and FUD from Urban Ranger, as per usual.

        Celebrating 10 years of .xyz - over a decade of innovation! We are beginning the countdown to our decade-iversary! Over ten chapters, journey through a decade of innovation with .xyz. From its ambitious inception to quickly becoming a leader in the domain industry, each press release will unveil a year of .xyz’s history, challenges, and

        Microsoft: SP2 shimmy's not a flaw
        Published: February 1, 2005, 3:24 PM PST
        By Matt Hines
        Staff Writer, CNET News.com

        Microsoft downplayed the significance of a reported flaw in its latest update to Windows XP.

        Responding to a Russian security company's claim that it found a way to beat a protective element of Microsoft's Windows XP Service Pack 2, the software giant on Tuesday said it does not believe the issue represents a vulnerability. In fact, the company said the technology highlighted by Moscow-based Positive Technologies was never meant to be "foolproof" and added that the reported flaw does not, by itself, put consumers at risk.

        "An attacker cannot use this method by itself to attempt to run malicious code on a user's system," Microsoft said in a statement. "There is no attack that utilizes this, and customers are not at risk from the situation."

        Last week, Positive reported that the Data Execution Protection tools included in Service Pack 2--code intended to prevent would-be attackers from inserting malicious programs into a PC's memory--opened Windows XP systems up to additional threats. The security company said that two minor mistakes in the implementation of the technology could allow a knowledgeable programmer to sidestep the measures, known as the Data Execution Protection and the Heap Overflow Protection.

        But Microsoft representatives disagreed with Positive's interpretation of Data Execution Protection, saying the technology was not created to necessarily foil existing threats but to make developing attacks against Service Pack 2 harder.

        In an e-mail message to CNET News.com, Microsoft representatives said the company would continue to modify the technology and would evaluate ways to mitigate the reported method of bypass.

        Those "security technologies in Windows XP Service Pack 2 are meant to help make it more difficult for an attacker to run malicious software on the computer as the result of a buffer-overrun vulnerability," the representatives said in the statement. "Our early analysis indicates that this attempt to bypass these features is not security vulnerability."

        Positive said that attack programs that use the exploit to get around Windows XP Service Pack 2 protections work reliably, allowing intruders to introduce malicious code onto machines using a second vulnerability that would otherwise not work on Service Pack 2 because of the protection mechanisms.

        Yury Maksimov, chief technology officer at the security company, said Positive only publicized the issue after Microsoft refused to act on previous warnings of the flaw that it sent to the software giant. He said he believes the Data Execution Protection does open up potential vulnerabilities.

        "In this situation, we decided it would be much safer for the industry to be aware of the new, existing threat," Maksimov wrote in an e-mail. "Such a vulnerability cannot cause a new worm or virus (to appear). But that's exactly the situation when it is much better to know about the problem, than not."

        However, at least one industry expert said that Positive's report of the threat may not be completely fair to Microsoft. Peter Lindstrom, a research director at Spire Security, observed that the Data Execution Protection vulnerability is unlikely to be seized upon by hackers. It relates more to core security issues with the design of many different kinds of software, not just tools made by Microsoft, he said.

        "Maybe you could classify this problem as a lost opportunity on Microsoft's part to protect Windows better, but that doesn't make it a vulnerability," Lindstrom said.
        Funny how UR is ignoring this thread now.
        Last edited by Asher; February 2, 2005, 15:16.
        "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
        Ben Kenobi: "That means I'm doing something right. "

        Comment


        • #19
          Such a predictably disappointing performance from UR...
          "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
          Ben Kenobi: "That means I'm doing something right. "

          Comment


          • #20
            UR and Asher — pistols at high noon!
            "I may not agree with what you have to say, but I'll die defending your right to say it." — Voltaire

            "Wheresoever you go, go with all your heart." — Confucius

            Comment


            • #21
              UR has once again fled with his tail between his legs, though.

              This is hardly the first time he's done a troll-and-run without knowledge of what he's talking about.
              "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
              Ben Kenobi: "That means I'm doing something right. "

              Comment


              • #22
                yeah, where did UR go anyways?
                To us, it is the BEAST.

                Comment


                • #23
                  He got tired of getting his ass kicked in threads just like this.
                  "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
                  Ben Kenobi: "That means I'm doing something right. "

                  Comment


                  • #24
                    My understanding is that there are zero-days no one knows about for every major operating system, as evidenced by year after year of pwnage at DEF CON.

                    By the way, if you ever want to see the most convincing possible proof that really smart people can have really ****ing strange and off-the-wall beliefs, just go to defcon. Half of them are crypto-anarcho-socialists or some other triple-movement-montage whose only common factor is being bonkers. They're ****ing good at hacking though.
                    If there is no sound in space, how come you can hear the lasers?
                    ){ :|:& };:

                    Comment


                    • #25
                      If "smart" people had beliefs that conformed to social norms, they wouldn't be smart.
                      To us, it is the BEAST.

                      Comment


                      • #26
                        I saw this thread and thought "when did UR start posting again"?
                        Try http://wordforge.net/index.php for discussion and debate.

                        Comment


                        • #27
                          This thread signaled the doom of Windows XP
                          <p style="font-size:1024px">HTML is disabled in signatures </p>

                          Comment


                          • #28
                            Originally posted by Sava View Post
                            yeah, where did UR go anyways?
                            He was outed as a propaganda agent for the Chinese Communist Party. Just look up any old threads on Tienanmen Square.
                            <p style="font-size:1024px">HTML is disabled in signatures </p>

                            Comment


                            • #29
                              Originally posted by Oerdin View Post
                              I saw this thread and thought "when did UR start posting again"?
                              Man, I have a whole book on China trolls since he lasted posted here.
                              “As a lifelong member of the Columbia Business School community, I adhere to the principles of truth, integrity, and respect. I will not lie, cheat, steal, or tolerate those who do.”
                              "Capitalism ho!"

                              Comment


                              • #30
                                Originally posted by loinburger View Post
                                He was outed as a propaganda agent for the Chinese Communist Party. Just look up any old threads on Tienanmen Square.
                                i figured
                                i pretty much think poly is populated by foreign and domestic intelligence agents just blowing off steam
                                To us, it is the BEAST.

                                Comment

                                Working...
                                X