News:

Pretty crazy that we're closer to 2030, than we are 2005. Where did the time go!

Main Menu

More XP SP2 Vulnerabilities

Started by iago, January 07, 2005, 09:00:55 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

iago

There's been a lot of ways found to run arbitrary code from remotely in Internet Explorer lately, even with fully patched SP2.  This is one of them:
http://secunia.com/advisories/12889/

My point is, stop using IE if you are :)

From Secunia, some stats:
QuoteVendor: Microsoft
Product Affected By: 75 Secunia Advisories


Microsoft Internet Explorer 6 with all vendor patches installed and all vendor workarounds applied, is currently affected by one or more Secunia advisories rated Extremely critical

This is based on the most severe Secunia advisory, which is marked as "Unpatched" in the Secunia database. Go to Unpatched/Patched list below for details.

Currently, 21 out of 75 Secunia advisories, is marked as "Unpatched" in the Secunia database.

Mythix

My point is, most will never change, they're afraid of it, thus they depend on M$ for all of their needs.


Philosophy, n. A route of many roads leading from nowhere to nothing.

- Ambrose Bierce


Newby

- Newby
http://www.x86labs.org

Quote[17:32:45] * xar sets mode: -oooooooooo algorithm ban chris cipher newby stdio TehUser tnarongi|away vursed warz
[17:32:54] * xar sets mode: +o newby
[17:32:58] <xar> new rule
[17:33:02] <xar> me and newby rule all

Quote from: Rule on June 30, 2008, 01:13:20 PM
Quote from: CrAz3D on June 30, 2008, 10:38:22 AM
I'd bet that you're currently bloated like a water ballon on a hot summer's day.

That analogy doesn't even make sense.  Why would a water balloon be especially bloated on a hot summer's day? For your sake, I hope there wasn't too much logic testing on your LSAT. 

iago

I hate SP2 soo much.  Computers shouldn't even need a personal firewall.  All a firewall is is a coverup for lousy programming.  If a vulnerability is found in a service, it should be disabled.  It's unfortunate that, on Windows, you can't.

iago

Apparnetly the product has 2 nice features:
1. It listens on port 2571 (which I would imagine goes through SP2's firewall, since it's MS)
2. Its icon is a big target

Gee, I wonder what's coming? :)

Stay tuned for the first annual Anti-Spyware Worm!

Mythix

hahaha

I did enjoy the little notifications every 5 minutes.


"YOU ARE NOW ACCESSING NOTEPAD, BE CAUTIOUS, OPEN PORTS WITH NOTEPAD OPEN COULD LEAD TO INTRUDERS!"
Philosophy, n. A route of many roads leading from nowhere to nothing.

- Ambrose Bierce


Quik

Then, we will have the evil jpg of doom, which will give you a virus just by looking at a jpg file while on Windows.
Quote[20:21:13] xar: i was just thinking about the time iago came over here and we made this huge bomb and light up the sky for 6 min
[20:21:15] xar: that was funny

iago

I'm just waiting for Spyware that uses Microsoft's Anti-Spyware program to propogate.  If that happens, I'm going to laugh soooo hard.

rabbit

You should make one, then laugh your ass off.  Not a malicious one even, actually, make it like the Polite Virus and have it ask the user if they want to allow the worm to spread around a little :)

Quik

I'm surprised a vulnerability has been finally found where the only immune Windows system is SP2, usually it's the other way around ;)
Quote[20:21:13] xar: i was just thinking about the time iago came over here and we made this huge bomb and light up the sky for 6 min
[20:21:15] xar: that was funny

iago

Quote from: Quik on January 08, 2005, 05:17:25 PM
I'm surprised a vulnerability has been finally found where the only immune Windows system is SP2, usually it's the other way around ;)

There were lots of those.  Jpeg vulnerabliity, several IE vulnerabilities, and others.  SP2 is doing pretty well, still and has only had a few vulns :)