Windows Under Attack Again

kc0arf kc0arf is offline Offline | Jan 3rd, 2006, 3:04 pm |
0
The Washington Post, among other news agencies is reporting a "severe" security flaw that affects Microsoft Windows 98 - XP. According to the article, the flaw allows computer virus and spyware manufacturers to disribute malicious programs designd to take control of affected computers.

Macintosh and Linux users are immune to the problem, even those computers that operate Microsoft Software. The issue is a core Windows problem that has not been addressed since Windows 98.

Feel free to read the article at: http://www.washingtonpost.com/wp-dyn...122901456.html

Unfortunately, due to limited time, your author (me) has not had the chance to track down and determine what the "official" name of the flaw is, nor been able to nail down Microsoft's response to the problem. I encourage readers to post via comments the latest information on the situation, to help those affected survive the situation.

Christian
Quick reply to this message  
0
DaveSW DaveSW is offline Offline | Jan 4th, 2006
The article isn't very clear, but it sounds like the .WMF exploit.
See the top announcement on GRC.com
http://grc.com/default.htm

You can get a temporary patch on
http://www.grc.com/sn/notes-020.htm
That page (scroll down) also lists all the background etc.

The official update is hoped for on the 10th of this month.
 
0
kub365 kub365 is offline Offline | Jan 4th, 2006
yea it is; there are simple things you can do to dimish the risk of you installing it till they release the patch. One is disable the image viewer, second is disable downloads (set security settings to high), third you can switch to firefox for the time being.
 
0
DaveSW DaveSW is offline Offline | Jan 4th, 2006
This vulnerability apparently affects the way windows itself handles wmf files, so using firefox doesn't protect you.
 
0
kub365 kub365 is offline Offline | Jan 4th, 2006
thanks for the headsup on FF; my anti-virus software avast now catches any of those wmf downloads :-).
 
0
DaveSW DaveSW is offline Offline | Jan 5th, 2006
I just can't believe they've ignored it right from day dot...
Says a lot about them as a company.
 
0
DaveSW DaveSW is offline Offline | Jan 6th, 2006
The official patch is now out:
http://www.microsoft.com/technet/security/bulletin/ms06-001.mspx
 
0
kub365 kub365 is offline Offline | Jan 6th, 2006
Yay, Just ran the update.

I am happy that they addressed the problem and provided a fix for it. Kudos to them.
 
0
The Dude The Dude is offline Offline | Jan 15th, 2006
Steve Gibson is saying that MICROSOFT purposely put this in Windows (I wouldnt be a bit surprised)

http://media.grc.com/sn/sn-022-lq.mp3

16Bit Stream - 39Mins

Whadda ya think?
 
 

Message:


Similar Threads
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC