Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

Computer Forum


You are currently viewing our Computer Forum as a guest. Please register to participate.
Login



Reply
Microsoft - WMF vulnerability updates
Old 01-04-2006, 05:14 PM Microsoft - WMF vulnerability updates
Marc's Avatar
Super Talker

Posts: 109
Location: EastCoast United States
Trades: 0
I'm sure your all aware of the major exploit in the windows OS but figured I'd post a link that will allow you to check and patch your system before Microsoft's releases their own patch on January 10th.

better safe than sorry.

Vulnerability checker and patch:
http://www.grc.com/sn/notes-020.htm

Both F-Secure and the Internet Storm Center recommend not waiting for
Microsoft and using Ilfak's patch:
http://news.zdnet.com/2100-1009_22-6...tag=zdnn.alert

have a good one!

Marc
__________________

Please login or register to view this content. Registration is FREE
Marc is offline
Reply With Quote
View Public Profile Visit Marc's homepage!
 
 
Register now for full access!
Old 01-04-2006, 05:17 PM
Anacrusis's Avatar
Defies a Status

Posts: 2,099
Name: Adam
Location: Colchester CT
Trades: 0
Thanks for the links Marc. This is a very critical patch to have installed.

Be sure to set a restore point, or backup your system before applying the above mentioned "unofficial" patch.
Anacrusis is offline
Reply With Quote
View Public Profile
 
Old 01-04-2006, 06:37 PM
Minaki's Avatar
Defies a Status

Posts: 1,626
Location: Guildford, UK
Trades: 0
Personally I'm gonna wait for the one from Microsoft. They're going to know their own product a lot better than someone else and it'll undergo proper testing, etc. Plus you won't get support from Microsoft on a patch that they didn't make.
__________________
Minaki Serinde MCP
"Wow, Linux is nearly on-par with Windows ME!"

Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
Minaki is offline
Reply With Quote
View Public Profile Visit Minaki's homepage!
 
Old 01-05-2006, 01:47 AM
luke456's Avatar
Webmaster Talker

Posts: 608
Trades: 0
thanks for alerting us, marc, and for sharing the link.
__________________

Please login or register to view this content. Registration is FREE



Please login or register to view this content. Registration is FREE
luke456 is offline
Reply With Quote
View Public Profile
 
Old 01-06-2006, 04:20 PM
Christopher's Avatar
Iced Cap

Latest Blog Post:
Cross-domain AJAX with JSONP
Posts: 3,110
Location: Toronto, Ontario
Trades: 0
MS has released an official patch now, for anyone reading. It got so much recognition that they didn't dare wait 'til their usual second Tuesday of each month.

As for not installing unofficial patches: usually. This "feature" of WMF allows an attacker to insert any arbitrary code into an image file that will be run anywhere an image could be displayed. In any browser viewing any page, your email etc. You don't need to click or accept or anything for this code to be run, and it will be run with the same permissions as the current user (and in Windows, that means 95% of the time, administrator). Waiting for MS to release a patch (and at first they said they were going to stick to their usual "Update Tuesday" schedule, which would mean another week) could be disastrous. The patch was written by a known author and has been recommended by trusted sources, there is no more risk in installing the temporary unofficial patch then there is running without it. But I do agree with you on the whole, but in this case I think it was better to install the unofficial patch.
__________________

Please login or register to view this content. Registration is FREE
- Latest Articles:
Please login or register to view this content. Registration is FREE
,
Please login or register to view this content. Registration is FREE

--
Please login or register to view this content. Registration is FREE

Christopher is offline
Reply With Quote
View Public Profile
 
Old 01-06-2006, 09:05 PM
Minaki's Avatar
Defies a Status

Posts: 1,626
Location: Guildford, UK
Trades: 0
I see what you're saying, but I tend not to visit any sites that could potentially be exploiting that vulnerability, anf my e-mail client is set not to display images, therfore I consider it low-risk.
__________________
Minaki Serinde MCP
"Wow, Linux is nearly on-par with Windows ME!"

Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
Minaki is offline
Reply With Quote
View Public Profile Visit Minaki's homepage!
 
Reply     « Reply to Microsoft - WMF vulnerability updates
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.76475 seconds with 12 queries