PDA

View Full Version : WWooooups, they did it again....(new security hole in windows, please read)



lullysing
10-09-03, 23:58
And now for everybody's late night joy and entertainment, Microsoft has... well... did it again. Apparently ANOTHER hole has been discovered that, if used, can lead to any virus or bored script kiddie to 0wz0r your windows NT,2000 and XP box.Since you all probably know how blaster was.. well.... nasty to pretty much everybody, here's the general informations you will need to know ( in the links section ).

And now, all passengers please send your browser to http://windowsupdate.microsoft.com and pray the patching servers don't crash before some new and improved worm 0wz0rs your box.

Just being helpful. And being not letting go of a good smack to send in the general direction of micrsoft... hi hi hi


--links--
http://windowsupdate.microsoft.com
http://www.microsoft.com/technet
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-039.asp
http://slashdot.org/articles/03/09/10/200232.shtml?tid=109&tid=126&tid=172&tid=187

HellHound
11-09-03, 00:01
sigh... so not so much 'done it again' as 'there were a number of glaring cock-ups and this is the most recent to come to light'?

lullysing
11-09-03, 00:04
Remember when they were marketting windows XP as a "secure operating system, with a different codebase from windows NT"?

And at that time, what i said , said it all :
<h2>Roooiiiiiiiiiiigghhhhttttt</h2>

CerealKiller
11-09-03, 00:07
Microsoft PWNS!!!

I swear to god, if I could play Neocron and run Trillian in Linux, I'd never fucking touch Windows again.

Heavyporker
11-09-03, 00:11
Oh, agreed, cerealkiller...

If Linux had wider support from game vendors, I think I would leave Microsoft forever, I'm on it only cos it's on my dad's rig.

Linux got loads of good stuff already, though, I'm a bit nervous about trying it out.

It's got a decent GUI, right? I *don't* have to command-line everything, right? I don't like command-lining, I can't remember shit that way. I know that there's plenty of great freeware working programs like GIMP and the like...

CerealKiller
11-09-03, 00:14
You can't really use Linux without being able to use the CLI. I'm horrible at Linux, but the reason I'm not willing to learn it is simply because it's not beneficial to me....

lullysing
11-09-03, 00:15
Problem with linux ( and unix in general ) is that it's not user friendly. The X window system works, but getting 3d drivers for your card, that work under linux (nvidia, nvidia) and getting those to work, with sound, and the rest can be sometimes daunting even for people that deal with computers all the time.

And then, codebase and system calls are not the same. So if you have to start running the shit under windows emulation..... oh my.

Heavyporker
11-09-03, 00:26
Damn!

The things I been hearing about Linux (huge opensource community) and OpenBSD (supposed to be really, really secure) sound nice, but I can't handle commandlining... suppose it's because I grew up with Windows (I'm sorry, I'm sorry, I know, I'm Gate's hellspawn slave).

If Linux got a really userfriendly, yet not bloated and yet not obnoxious (by this, I mean - Remember that Microsoft PaperClip Helper? ^ ^ ) , then it'd be kicking Windows all over the place.

ericdraven
11-09-03, 09:22
Heh, as if Linux does not have tons of security vulnerabilities..

The difference to Windows is that not so many people use Linux.. and most of the Linux using people are professionals who know what they are doing.
Once Linux becomes a "homeuser" Operating System we will hear of those security vulnerbilities every day, just like we do now about Microsoft. ;)

And no, i don't work for M$. :p I use both, Linux and Windows.

Pill
11-09-03, 10:11
the last time i patched i got a fucked up neocron and a reformat, i will leave my box as is. most virii are stupid, and go after the drive with the windows files on it, ala, my windows is on an entirely seperate partition just for it ;p

DigestiveBiscui
11-09-03, 10:46
someone make this a sticky plz

Richard Slade
11-09-03, 12:04
Bah! Stop using those sucky OS's instead! Win98 roxxors!

djskum
11-09-03, 12:32
All OS's have exploits and security holes. Most proper hackers don't bother with Windows boxes anymore, they've left that for the 14yr old script kiddies, it's all too easy! Statisticly more Linux/Solaris/BSD/Darwin (Mac OS) are bieng attacked because they pose more of a challenge.

The only solution is to become very anal about your comuters security and keep up-to-date with vunerabilities (I use cert.org amongst others) and patch your kit as regualy as you can. Firewalling's a very good idea too. Personal Firewalls are OK but in my opinion there is no substitute for an external firewall. You get NATing aswell then which will obscure your machines IP.

Don't open and attackments either. Keep an eye on www.symantec.com for virus updates and familiarise yourselves with the latest viral symptoms and look out for them.

Failing that there are two options:

1) Lock yourself in a box (David Blane style) untill Judgement day (or insanity) claims you.

2) Employ me at a very reasonable rate...

DjSKum

PS And M$ fucking suck! I now have to go and patch our WinDoze boxes AGAIN!!! Good job we only have about 6 here or I'd be screwing!

DigestiveBiscui
11-09-03, 14:14
done and done

NC is running for me - so dont worry about that :)

thx for the info

DB

Lexxuk
11-09-03, 16:06
Originally posted by Heavyporker
If Linux got a really userfriendly, yet not bloated and yet not obnoxious (by this, I mean - Remember that Microsoft PaperClip Helper? ^ ^ ) , then it'd be kicking Windows all over the place.

Its already user friendly, depending on which one you choose. Bloat though, well, I installed Redhat 9 on my puter yesterday, couldnt be bothered to pick n choose, so went "everything" just over 4gig's worth of stuff installed, so major bloat :D

But, I cant connect to the net with Linux, my USB ADSL Modem isnt supported, so, it wont work which means I'm running Redhat thru Windows 2003 as my software router, unless I splash out on a proper router :(

Also, NVidia is well ard on teh Linux, download the file, type in sh N(tab) (enter) from the command line (cant be usin X) and bobs ur uncle, new NVidia drivers (just change a line from nv to nvidia in XFree86-config file. But Redhat dont give you an easy way to stop it booting into X on loadup, you gotta go "telinit s" to drop to pure terminal.

On topic - Blaster worm vulnerability was spotted long before Blaster was released into the wild, MS had the patch up a long long time ago, unfortunatly, people tend not to update their system often, so, the Blaster had a party. In a few months, a vulnerability that MS knows about, and released patches for, will be exploited by a worm, because people dont update enough, or have a firewall which prevents the worm from finding they exist :rolleyes:

lullysing
11-09-03, 16:29
Originally posted by DigestiveBiscui
done and done
NC is running for me - so dont worry about that :)
thx for the info
DB

No problemo paderino .

( arrgg!!! I'm speaking Flanders!!!)
*goes and PKs a bunch of innocent people*

aahhhhhhh

Heavyporker
11-09-03, 22:53
Well, okay, but how resource-intensive is Linux compared to Windows? This Windows Xp my dad's on chews everything up that the processor/ram has got to offer.

lullysing
12-09-03, 00:52
If your dad just surfs and does random office/wordprocessing, just put a well installed win98 on the thing and forget about it : most people don't need XP. Myself, the only reason i originally upgraded was because i had a gig of ram, and windows 98 only supports up to 512 - 766 ish ram.

Millenium, on the other hand, supports 1 gig of ram. And it's pretty much the same codebase as win98. Some people say it's a piece of crrap, but personally i never had any problems with it when i had it on my computer.

Heavyporker
12-09-03, 01:44
He says he prefers Win2000 for control (yeah, he's kind of techie) but I don't seem to be able to get much headway with it (problems and such, that I can't really get around, plus I don't have admin access, making it harder) so I use WinXP much more.

I just don't want hassles when I use a computer, which would be mainly surfing (webcomics rule my life, judging from the amount of time I spend each, yes, EACH, day reading them) and gaming (no, not fps - more along the lines of the Myst games and Neocron). I don't particularly like programming (not enough dedication, I think, though I grasp the basics relatively well enough).

Security would kinda be an issue with me, considering I've been slapped twice by malicous programs (once by a trojan off some freeware that I *thought* was safe, once just now by that damn blaster thing). That blaster thing took me by suprise, because I've been savvy enough not to touch email attachments if I could help it.

I know that Linux isn't autmatically more secure, but I've been peeking at Linux because it's got, well, for lack of better description, less cashcow-ing issues.

Game support with Linux's pretty important to me though, I *love* to play the games that I like to play.


I suppose when I get enough cash to put together my own desktop (spent the first k on a lapwarmer, err, laptop from compaq (yes, I have paid for the sin, thank you)) And I'm pretty much put off by it (right now, I'm only using the lapwarmer, dammit, laptop because since it's mine, I got admin access, hence, less hassle installing proggies and for data storage, plus, it's got GIMP on it, love that program) I will probably try a dual-boot. Still gotta look around for a decent free/reallycheap flavor of Linux that I can handle.

Hell, Dad's even talking about putting together a new desktop (well, more like upgrading, but still) so I'll see what MS OS he'll put on it. He's hardcore MS so I wouldn't bother about preaching Linux to him :D

Stigmata
12-09-03, 01:59
i had a gig of ram, and windows 98 only supports up to 512 - 766 ish ram.

win98 can take any amount of ram, it just takes one minute reg key to set it. same as all the MS OS's. oh and there is no such memory configuration to give you a total of 766 :p i believe you mean 768 ?

So did any of your miss me during my un-timely ban ?

note to self dont post on forums when one has been drinking, can lead to a ban :(

Andy

oh forgot to say, when someone gets banned isn't it custom to receive a email or pm telling you why ?

rob444
12-09-03, 05:35
Well, I dont want to take Microsoft's side but.. If it wasnt for Windows, many of you guys probably wouldnt sit infront of a computer today, *nix is just to hard for newbies.

lullysing
12-09-03, 08:36
Originally posted by stigmata
oh and there is no such memory configuration to give you a total of 766 :p i believe you mean 768 ?


Waaahhh....
* turns around and shoots the typo demon, then hacks the belt *

Kazuko
12-09-03, 15:25
Originally posted by djskum
PS And M$ fucking suck!


Originally posted by ericdraven
And no, i don't work for M$.

http://www.penny-arcade.com/images/2002/20020722l.gif

So on that note, for the people here that think they Windows sucks because of all of the security issues and want to switch to linux, don't bother. _IF_ you get through the install of a real distro (other than Redhat or Mandrake--those are for stupid sysadmins not desktop systems) you'll be crying because you can't make the GATOS drivers for your ATI card work, or no one in #linux will answer you on how to mount your ntfs partition (because we all know you won't just delete windows) so you can listen to your mp3s.

Linux DOES NOT replace Windows. It probably has applications that do pretty much everything windows does, but not the way windows does it. For most of you you'll be limited to what your package manager offers you; by far not a complete set of applications.

If you are sitting here complaining about how windows sucks and the real answer is linux you shouldn't even be running linux. In the past if you were a good little boy/girl you would know just to run windows update to keep the script kiddies away. But now in this day in RPC age you _MUST_ run a firewall. If you cannot even turn on the built in windows firewall to block the RPC port you will not be able to manage linux security--that requires you to watch the numerous bug and exploit fixes for the hundreds if not THOUSANDS of apps on your linux box.

So stop complaining.
Control Panel -> Network Connections -> [connection] properties -> Advanced -> Check the little box -> Press Ok

Tah dah.