Announcement

Collapse
No announcement yet.

Yet one more microsoft security hole

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Yet one more microsoft security hole

    Apparently there's a security hole so bad that experts are strongly recommending people to download an independent fix until Microsoft's official patch on Jan 10th.


    Experts Advocate Non-Microsoft Windows Patch


    By Brian Krebs
    Special to the Washington Post
    Wednesday, January 4, 2006; D04

    Security experts yesterday criticized Microsoft Corp. for waiting until next week to address a recently revealed flaw in the Windows operating system that they say is unusually dangerous.

    The experts took the unusual step of urging users to install a patch created by a private developer, saying Microsoft is downplaying the severity of the security hole.

    The flaw, revealed last week, allows hackers to break into computers running versions of Windows software -- from Windows 98 through the most recent Windows XP. The flaw allows computers to be infected with spyware or viruses by visiting a Web site or opening on an image or link in an e-mail or instant message.

    Debby Fry Wilson, a director in Microsoft's security response unit, said the company began working on a fix as soon as it confirmed the technical details of the ongoing attacks, which so far have affected computers running Windows 2000, Windows XP and Windows Server 2003. Its patch, which is being tested to ensure that there are no conflicts with other software, is to be issued next Tuesday.

    While the threat "is serious and malicious attacks are being attempted, Microsoft's intelligence sources indicate that the scope of the attacks are not widespread," she said.

    Thomas F. Liston, an incident handler with the SANS Internet Storm Center in Bethesda, said Microsoft was downplaying the threat from the flaw.

    "They're just keeping their fingers crossed that this doesn't blow up in a big way until the 10th," Liston said.

    Another computer-security firm, Symantec Corp., said Microsoft's decision to delay the patch for another week presents attackers with a "seven-day window that attackers could exploit this issue in a potentially widespread and serious fashion." The Cupertino, Calif., company raised its threat alert to the highest level in 16 months.

    Liston said hundreds of Web sites are exploiting the flaw. Malicious hackers expanded into instant messages on New Year's Eve to take advantage of the vulnerability, he said.

    In an advisory posted on its Web site earlier this week, SANS urged Windows users to download and install the unofficial patch. SANS and other security experts checked the patch to ensure that it fixes the security flaw without compromising other programs or creating other problems for the users, Liston said.

    "I was kind of afraid for my own computer because you can get infected just by visiting a site with your Web browser," said Ilfak Guilfanov, the programmer who developed the unofficial patch and is author of IDA Pro, a debugging tool. "I decided if it works for me, then maybe it will help others, too."

    It is rare for established computer security experts to urge Windows users to install a third-party software patch for a Windows problem. They tend to advise users to ignore patches for Windows security flaws not issued by Microsoft because criminals frequently disguise their malware as Windows patches to trick users into installing them.

    Wilson declined to comment on the quality and security of Guilfanov's patch.

    Until Microsoft releases its patch, customers should practice "safe computing habits," such as updating anti-virus software and avoiding unfamiliar Web sites, she said. However, it's unclear whether safe computing is enough because the exploit it altered every time it infects a new machine, making it tougher for anti-virus software to detect it.

    F-Secure Corp., the Finnish anti-virus company that first spotted the exploit on the Internet on Dec. 27, also vouched for the safety of the unofficial patch and advised customers to use it.

    "We will see this vulnerability being used for various different purposes for months to come, and I wouldn't be surprised to see a massive worm outbreak before Microsoft releases this patch," said Mikko H. Hypponen, chief research officer at F-Secure.

    Brian Krebs is ahttp://washingtonpost.comreporter. Updates on the security flaw and instructions on how to deal with it can be found athttp://washingtonpost.com/securityfix.
    Who is Barinthus?

  • #2
    Microsoft has an intelligence service?
    I make no bones about my moral support for [terrorist] organizations. - chegitz guevara
    For those who aspire to live in a high cost, high tax, big government place, our nation and the world offers plenty of options. Vermont, Canada and Venezuela all offer you the opportunity to live in the socialist, big government paradise you long for. –Senator Rubio

    Comment


    • #3
      Microsoft should burn in hell

      Comment


      • #4
        Originally posted by DinoDoc
        Microsoft has an intelligence service?

        Yes, but it's been down for a while....
        -Never argue with an idiot; He will bring you down to his level and beat you with experience.

        Comment


        • #5
          Re: Yet one more microsoft security hole

          Originally posted by Barinthus
          Apparently there's a security hole so bad that experts are strongly recommending people to download an independent fix until Microsoft's official patch on Jan 10th.
          Is it called OS X?

          Comment


          • #6
            Originally posted by Wiglaf
            Microsoft should burn in hell
            Along with Wiglaf
            “I give you a new commandment, that you love one another. Just as I have loved you, you also should love one another. By this everyone will know that you are my disciples, if you have love for one another.”
            - John 13:34-35 (NRSV)

            Comment


            • #7
              Hi people. Is there a link?
              urgh.NSFW

              Comment


              • #8
                Originally posted by Wiglaf
                Microsoft should burn in hell


                Don't think it will work - that company is founded in hell.
                With or without religion, you would have good people doing good things and evil people doing evil things. But for good people to do evil things, that takes religion.

                Steven Weinberg

                Comment


                • #9
                  Originally posted by Imran Siddiqui


                  Along with Wiglaf
                  Wiggie would be kicked out for bad behaviour.
                  Why can't you be a non-conformist just like everybody else?

                  It's no good (from an evolutionary point of view) to have the physique of Tarzan if you have the sex drive of a philosopher. -- Michael Ruse
                  The Nedaverse I can accept, but not the Berzaverse. There can only be so many alternate realities. -- Elok

                  Comment


                  • #10
                    Originally posted by DinoDoc
                    Microsoft has an intelligence service?
                    Yes, and they swear that Apple has WMD.
                    "I am sick and tired of people who say that if you debate and you disagree with this administration somehow you're not patriotic. We should stand up and say we are Americans and we have a right to debate and disagree with any administration." - Hillary Clinton, 2003

                    Comment


                    • #11
                      Re: Re: Yet one more microsoft security hole

                      Originally posted by Verto


                      Is it called OS X?


                      Az, oops I forgot the link to the article. Or did you want the link to the fix?

                      You might probably to register to view those links:
                      the article

                      More specific information

                      You don't need to register to view this link...

                      SANS' FAQ on the fix
                      Who is Barinthus?

                      Comment


                      • #12
                        a link to the fix, please.
                        urgh.NSFW

                        Comment


                        • #13
                          Read and use at own risk:
                          (it is MS based)


                          Is God willing to prevent evil, but not able? Then he is not omnipotent. Is he able, but not willing? Then he is malevolent. Is he both able and willing? Then whence cometh evil? Is he neither able nor willing?
                          Then why call him God? - Epicurus

                          Comment


                          • #14
                            The official update has been pushed through windows update.
                            "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
                            Ben Kenobi: "That means I'm doing something right. "

                            Comment


                            • #15
                              Originally posted by Az
                              a link to the fix, please.
                              The fix are in two last links I provided.
                              Who is Barinthus?

                              Comment

                              Working...
                              X