Code Newbie
News     Forums     Search     Members     Sign Up    

My Code Newbie
Username

Password

Articles/Snippets
ASP Classic
ASP.NET
C
C#
C++
HTML / CSS
Java
Javascript
Linux / BSD
Perl
PHP
Python
Ruby
SQL
VB 6
VB.NET

C.N. Friends
  Planet Rome

Link to Us!
Code Newbie
  Code Newbie
    forums
Old 01-03-2006, 03:28 PM   #1 (permalink)
Belisarius
Java fanboy
 
Belisarius's Avatar
 
Join Date: Aug 2003
Posts: 1,140
Belisarius is on a distinguished road
New Windows Vulnerability.

I try not to be too much of a chicken-little on these things, and I'm usually not too concerned about viruses as I use best-practices, but the buzz surrounding this vulnerability is pretty intense. The rumor is that it *isn't* reliability picked up by virus scanners, and (I didn't even think this was possible) is imbedded in images. That means all you need to do is view a website (I think message boards are particularly vulnerable as seed-points) with an infected image and you've got it.

Sans message. Slashdot articles here and here.

Microsoft isn't planning on pushing out an update for about a week, but if a working virus hits first, it sounds like there's no real defense. Sans is suggesting that people install a third-party patch they have tested and are hosting here until the official MS patch comes out. I've installed it and so far my computer hasn't exploded, so take that as you will . . .
__________________
GitS
Belisarius is offline   Reply With Quote
Old 01-03-2006, 04:53 PM   #2 (permalink)
DJMaze
Senior Contributor
 
DJMaze's Avatar
 
Join Date: Mar 2005
Posts: 651
DJMaze is on a distinguished road
Thank god i don't use WindowsMediaFiles.
DJMaze is offline   Reply With Quote
Old 01-03-2006, 05:25 PM   #3 (permalink)
Belisarius
Java fanboy
 
Belisarius's Avatar
 
Join Date: Aug 2003
Posts: 1,140
Belisarius is on a distinguished road
The problem is that I could simply rename a .wmf file as a .jpg, and Windows will look at the *header* information and load the file anyways.
__________________
GitS
Belisarius is offline   Reply With Quote
Old 01-05-2006, 05:57 AM   #4 (permalink)
DJMaze
Senior Contributor
 
DJMaze's Avatar
 
Join Date: Mar 2005
Posts: 651
DJMaze is on a distinguished road
Shure but which windows ?
I use plain Windows 2k because i hate all that embedded picture viewing, audio reading and IE
DJMaze is offline   Reply With Quote
Old 01-05-2006, 01:55 PM   #5 (permalink)
Belisarius
Java fanboy
 
Belisarius's Avatar
 
Join Date: Aug 2003
Posts: 1,140
Belisarius is on a distinguished road
All of them. Seriously. It's a problem with legacy code introduced in Windows 3.0, and included in every version since.
__________________
GitS
Belisarius is offline   Reply With Quote
Old 01-05-2006, 02:01 PM   #6 (permalink)
Belisarius
Java fanboy
 
Belisarius's Avatar
 
Join Date: Aug 2003
Posts: 1,140
Belisarius is on a distinguished road
Official Microsoft Fix can be found here:
http://www.microsoft.com/technet/sec.../ms06-001.mspx
__________________
GitS
Belisarius is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Pirated software used to create help content in Microsoft's Windows XP sde Code Newbie News 3 11-17-2004 02:14 PM
Accessing the Windows desktop remotely bdl Windows 7 11-10-2004 07:39 AM
The Windows of two minds creed Windows 4 11-10-2004 07:37 AM
A critical security vulnerability has been found in the Linux kernel redhead Code Newbie News 0 02-19-2004 10:37 PM
Bloody Windows IE rendering sarah31 PHP 6 06-05-2002 07:31 PM


All times are GMT -8. The time now is 04:32 AM.


Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0 RC8





Copyright © 2000-2008, Milano Interactive
Web Hosting provided by Portal 360 Web Hosting