PDA

View Full Version : Another Windows security leak


Jonathan Long
30th December 2005, 12:45 PM (12:45)
Check out the following link....

I'm becoming more and more aggravated by Microsoft...

http://www.computerworld.com/softwaretopics/os/story/0,10801,107375,00.html?source=x72

It seems that they believe that Beta testing is done by having consumers purchase their product first.... then attempting to fix the bugs!

Jon

Joel Merrill
30th December 2005, 04:13 PM (16:13)
I've thought that about Microsoft ever since Windows ME came out. It had lots and lots of problems. Now I am starting to feel that way about Mozilla Firefox 1.5 I'm having troubles with it and wish I would have stayed with the old Firefox.

Joel

Keith Isley
2nd January 2006, 09:26 PM (21:26)
Jonathan -

From what I can tell by reading various accounts, this is a SERIOUS, serious flaw -- and it affects, to greater or lesser degree, every version of Windows all the way back to Win 95. Apparently Microsoft designed WMF files to be able to run code - and this was needed, pre-Internet, to cancel printing jobs in process or other such things. Now, though, it basically opens a security hole a mile wide - just by viewing an affected file. No user intervention required. Just view the file - in Outlook, Internet Explorer, Firefox - it doesn't matter - and your system is open to a hacker, who can install software, wipe your hard drive, whatever.

Unless Microsoft gets their rear in gear and patches this ASAP, this is going to be huge. Lots of people are going to get stung.

There is an "unofficial" patch that's been put out there by the SANS Internet Storm Center. It can be found here. (http://isc.sans.org/diary.php?storyid=999) Use at your own risk, and only if you know what you are doing - no guarantees. :) Microsoft is expected to have something out by the 10th, so let's all cross our fingers.

Joel - I had problems with early versions of Firefox 1.5 as well. Re-downloading and re-installing seemed to fix the issues for me. Hope this helps.

Paul Whitaker
2nd January 2006, 11:34 PM (23:34)
http://news.ft.com/cms/s/0d644d5e-7bb3-11da-ab8e-0000779e2340.html

Hans Deventer
3rd January 2006, 02:37 AM (02:37)
http://news.ft.com/cms/s/0d644d5e-7bb3-11da-ab8e-0000779e2340.html

Yes, we should. Certainly until Microsoft has released a patch.