Slashdot Log In
New Zero-Day Vulnerability In Windows
Posted by
Zonk
on Sat Nov 04, 2006 10:44 PM
from the worst-day-of-the-week dept.
from the worst-day-of-the-week dept.
Jimmy T writes "Microsoft and Secunia are warning about the discovery of a new 'Zero-day' vulnerability affecting all Microsoft based operating systems except Windows 2003. Both companies states that the vulnerability is currently being exploited by malicious websites. One attack vector is through Internet Explorer 6/7 — so be aware where you surf to."
This discussion has been archived.
No new comments can be posted.
New Zero-Day Vulnerability In Windows
|
Log In/Create an Account
| Top
| 231 comments
| Search Discussion
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Just curious (Score:3, Insightful)
Does anyone actually know anyone that has been affected by any of these exploits? Seems to me that the odds of actually visiting a site that "runs" the exploit is incredibly low.
Darn (Score:2, Funny)
(http://www.radioreference.com/)
"Trusted" Websites (Score:3, Insightful)
(http://thestonepedo.dyndns.org/ | Last Journal: Friday March 17 2006, @03:32AM)
Seriously, Is Firefox susceptible to this too? (Score:2)
(Last Journal: Thursday August 04 2005, @03:11PM)
What other ways can this exploit be triggered?
Re:Seriously, Is Firefox susceptible to this too? (Score:5, Informative)
Oh good... (Score:1, Troll)
(http://www.mithral.com/~beberg/)
Glad nobody I know is vulnerable to this. Everyone is OSX, Linux, or Win2003 for a long time now.
A Web "browser" - implies "just looking" (Score:2, Funny)
(Last Journal: Saturday December 09 2006, @10:46PM)
Is that so much to ask for, of ANY browser?
Your vs You're (Score:4, Funny)
In Soviet Russia (Score:1, Funny)
Hello my name is Microsoft... (Score:2)
It may very well be that stupid users or badly configured systems allow these exploits to thrive but FFS Microsoft just admit that you are actually at least partially to blame.
As long as they fail to realise that they are not gods and do actually write buggy software, what hope is there that they will ever succeed in producing something secure?
Oh No! (Score:1)
That's what they get (Score:2, Funny)
(http://www.jamesoft.net/)
Well that's what they get for not updating and running Internet Explorer 6/7! It's not even version 1.0!
Now for some real news (Score:2)
(http://slashdot.org/~davidwr/journal/ | Last Journal: Friday November 09, @09:19PM)
REDMOND - NOV 23, 2006
Microsoft is proud to announce that for the second day in a row, now 0-day exploits were discovered in its flagship Microsoft Operating System.
Payload (Score:1)
Oh neato (Score:1)
(http://crux88.com/)
In other news, it is being reported that the sun rose this morning. Tape at eleven.
Warning warning danager danger! (Score:1, Flamebait)
(http://www.geocities.com/orion_blastar/contact/ | Last Journal: Tuesday April 03 2007, @07:19PM)
Does not affect Vista (Score:2)
Get $browser, when $browser != IE (Score:1)
(http://opensourceme.blogspot.com/)
What about my Windows 95 box? (Score:2)
So a box running Windows 95 or DOS is at risk then?
I'm not sure which is more irritating - that the summary uses the above phrase that is not in the article, or that they article doesn't explicitly say which OS/browser versions are affected (and you'd have to go digging around to find whether you are using "XMLHTTP 4.0 ActiveX Control, part of Microsoft XML Core Services 4.0".
I suppose the most irritating thing for a Windows user is that this is yet another security hole.
No 2003? Someone can't read. (Score:3, Informative)
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Datacenter Server
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Server
Microsoft Windows Server 2003 Datacenter Edition
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows Server 2003 Web Edition
Microsoft Windows XP Home Edition
Microsoft Windows XP Professional
It's C again. (Score:2)
On a more serious note, I am using Firefox and Thunderbird, so it is highly unlikely that I am affected by the vulnerability. Open source wins again!
Let me guess what's going to happen next. (Score:1)
Does it affect XP 64? (Score:2)
"Customers who are running Windows Server 2003 and Windows Server 2003 Service Pack 1 in their default configurations, with the Enhanced Security Configuration turned on, are not affected. Customers would need to visit an attacker's Web site to be at risk. We will continue to investigate these public reports."
I'm on XP 64 SP1, equivalent to 2003 SP1.
Melissa
Use psexec to protect your system from your browse (Score:2)
http://download.sysinternals.com/Files/PsExec.zip [sysinternals.com]
C:\utl\psexec.exe -dl "C:\Program Files\firefox\firefox.exe"
or
C:\utl\psexec.exe -dl "C:\Program Files\Internet Explorer\iexplore.exe"
Aonther one? (Score:2)
(http://kurt555gs.blogspot.com/)
No, really?
Tell me it isn't so.
Wait! (Score:2)
(http://www.leperkhanz.com/ | Last Journal: Wednesday October 01 2003, @05:17AM)
What? Windows is insecure?!? Even with IE7?!?!? (Score:1)
(http://dotancohen.com/)
http://lyricslist.com/lyrics/artist_albums/425/re
MSXML4 is NOT part of Windows (Score:1)
Re:My first first post! (Score:1)
(http://browsers.garykeith.com/)
Re:The fix's already available (Score:2)
Just gimme enough time to grab the popcorn.
Re:Hey, Linux weenies! (Score:2)
Lay off the caffeine, dog. Now you're seeing things. There ain't no such thing as a sexy nerd girl. There are plenty of sexy girls (directly proportional to the amount of beer you've had), and there are some nerd girls. But sexy nerd girls? No way, unless you are really wasted.
Re:Hey, Linux weenies! (Score:2)
there's no trend here. windows searches are decreasing also.
Re:sigh. (Score:3, Funny)
(http://www.last.fm/user/uhlume/)
Linux - Ubuntu (Score:1)
(http://en.wikipedia.org/wiki/User:H2g2bob)
Linux searches become Ubuntu searches.
Re:LOL (Score:1)
Re:"Zero day" (Score:1)
Myths... (Score:2)
(http://www.mosehansen.dk/)
Nice try :) Let me see you run a windows machine for developing for a month, no crashes, no reboots. Repeat this for month after month. Then let me see you install a windows machine through booting a CD (or DVD if you prefer), seeing everything works as expected, and then initiate the install. The install will automatically accomodate the existing OSs on the computer, and making dual booting between any number of OSs possible. After the install, let me then see you find and install a secure browser, 2 different spreadsheets, a 3D object editor and maybe 30 small games for those 10 minutes with nothing to do. Then let me see you get an overview over all the applications installed, and press a button to upgrade all those to their newest version. Your budget is.... let's be generous and say 30 Euro.
Windows is good for exactly one thing... playing certain games. And it's getting worse all the time (not due to linux, but due to the PSn or whatever those playing boxes are called).As I have lost much of my interest in playing that sort of games, I have never been happier with Linux, which is so much better for what I do... developing software.
Re:"Zero day" (Score:2)
(http://www.abcseo.com/)
ahhh, I didn't know that but there is so much jargon around these days from people trying to sound sexy and intelligent I do let a lot go over my head. Thanks for the clarification. I've been hearing "zero day zero day" everywhere I thought it must be some kind of clevel attack like Birthday or something. There you go, learn something new every zero day.
Re:"Zero day" (Score:1)
Re:Hey, Linux weenies! (Score:1)