Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » The Mother of All MS Exploits?
view: topics flat text 
Post a:

Comments on news posted 2004-02-10 18:24:35: Microsoft apparently sat on a serious Windows OS vulnerability for six months before announcing the availability of a fix today. One analysts calls the latest exploit one of the "most serious Microsoft vulnerabilities ever released". ..

page: 1 · 2

Mike
Premium,Mod
join:2000-09-17
Pittsburgh, PA
clubs:
·Verizon FIOS
·Verizon Online DSL

Host:
Site Tools
W.O.W.
FairPoint
World of Warcraft
Alltel Axcess

logic?

It's nice of all these hundreds upon hundreds of windows exploits are finally surfacing.

The question is, how many people were farked because of it?

It's like KDE having over 10,000 bug fixes / tweaks / optimizations to the GUI. How many people really noticed all of them?
--
Everyone is entitled to their opinion. Of course, they're entitled to be blithering idiots at the same time.
What this country needs is a good five dollar plasma weapon.

GNXPower
Got Boost?
Premium
join:2003-12-18
Huntington Beach, CA

Re: logic?

I agree, it's one of those if a tree falls in the woods kinda things.

There is a big difference between an exploit and an exploited exploit.
--
Don't have it?!? Demand it!!! The Anime Network »www.theanimenetwork.com

ArchAngel21x
MacFan Pro
Premium
join:2001-10-28
Lincoln, NE

Re: logic?

As long as you run a firewall, are most of these exploits not an issue?

enOehT
Premium
join:2003-05-17
Langhorne, PA

Nope!

They said they go right around the firewall like it wasn't even there.

ArchAngel21x
MacFan Pro
Premium
join:2001-10-28
Lincoln, NE

Re: Nope!

Now that is some scary s---

enOehT
Premium
join:2003-05-17
Langhorne, PA

Indeed!

I just pooped in my pants!

[capt. kirk] Scotty! We need more power! Keep that force field firewall up! [/kirk]

[scotty] I'm givin' it all I got captain! She's not going to hold! [/scotty]
--
vic102482
Premium
join:2002-04-30
Upper Marlboro, MD

said by enOehT See Profile:
They said they go right around the firewall like it wasn't even there.

Get a linksys. Software firewalls are good, but if the OS is compromised they are useless:).
--
I tie a rope around my penis and jump from a tree, don't you wanna grow up to be just like me!!!!

KoolMoe
Aw Man
Premium
join:2001-02-14
Annapolis, MD
clubs:
·Verizon FIOS
·Speakeasy

Who said that?
I read the first two articles (well, skimmed) and didn't catch a reference to firewalls.
Perhaps due to the nature, routers would decipher such a malformed request? In what scenario?

Server is patched, now to do all the clients...

Is this finally a better reason to use Ridge's Security Color Code system?

Ah, so many questions.
KM
--
"I'm respecting your privacy as an individual by knocking, but I'm asserting my authority as a parent by coming in anyway."--Fairly Odd Parents
Cape Media

enOehT
Premium
join:2003-05-17
Langhorne, PA

Worse than Y2K!

This one has the potential to be MUCH bigger than the Y2K scare.

53059959
Temp banned from BBR more then anyone

join:2002-10-02
PwnZone

Re: Worse than Y2K!

said by This Article:
security experts expect hackers to take advantage of the vulnerabilities in a matter of weeks or less
mmm. me thinks theres going to be some massive t@gging in the next few weeks. good time to download ftp post/non p2p warez

Omega
Displaced Ohioan
Premium
join:2002-07-30
Cheyenne, WY
clubs:
·Bresnan Online
·Verizon Wireless B..
·Comcast
·AT&T Midwest

Re: logic?

The article talked about automactic updates, the thing is microsoft needs to PROVIDE the updates in order for them to be downloaded.

It seems that microsoft need to get with it.
--
"166Mhz of Raw Processing Power!"
My site
SBC DSL 1500/256

ikarus1
Premium
join:2002-10-23
Urbanna, VA

said by Mike See Profile:
It's nice of all these hundreds upon hundreds of windows exploits are finally surfacing.

The question is, how many people were farked because of it?

It's like KDE having over 10,000 bug fixes / tweaks / optimizations to the GUI. How many people really noticed all of them?

Dude, the problem is that NOBODY KNOWS HOW MANY PEOPLE WERE FARKLED AND THEY NEVER WILL...

KDE DOES NOT RUN AS ROOT... The signifigance of which is no doubt lost upon you.

-m-
--
»www.freeantennas.com

Mike
Premium,Mod
join:2000-09-17
Pittsburgh, PA
clubs:
·Verizon FIOS
·Verizon Online DSL

Host:
Site Tools
W.O.W.
FairPoint
World of Warcraft
Alltel Axcess

Re: logic?

Thank you for the personal attack. Try not to do it again. I know they slip sometimes when trying to prove someone is an idiot.

KDE is an application which the user runs and by default not with root permissions. I run linux, I own a couple macs, and I have a windows box (for games). I'm also not generally stupid.

Besides, sit on a linux topic IRC channel and see the response being logged in as root@x.~
It's rather amusing.
--
Everyone is entitled to their opinion. Of course, they're entitled to be blithering idiots at the same time.
What this country needs is a good five dollar plasma weapon.

ikarus1
Premium
join:2002-10-23
Urbanna, VA


2 edits

Re: logic?

said by Mike See Profile:
Thank you for the personal attack. Try not to do it again. I know they slip sometimes when trying to prove someone is an idiot.

KDE is an application which the user runs and by default not with root permissions. I run linux, I own a couple macs, and I have a windows box (for games). I'm also not generally stupid.

Besides, sit on a linux topic IRC channel and see the response being logged in as root@x.~
It's rather amusing.

What personal attack... talk stupid... get called on it... What is so personal about that?

Get your facts straight and document a clue and you'll have no problems in the arena...

Yes logic wins... you have to have logic to win... or... "What's in a name?"

I suppose you can ban me...

-m-
--
»www.freeantennas.com

Mike
Premium,Mod
join:2000-09-17
Pittsburgh, PA
clubs:

Re: logic?

Why would I ban you?

How did you get this?

"The signifigance of which is no doubt lost upon you."

ArchAngel21x
MacFan Pro
Premium
join:2001-10-28
Lincoln, NE
·Internet Nebraska

Re: logic?

said by Mike See Profile:
Why would I ban you?

An assumption you would get a power trip out of it?

Cystum
Systems
Premium
join:2002-12-26
Great Neck, NY
Windows are based on Learning Experiences. They should really test it before they sell the licenses to people.
Greed is one of the Deadly Sin.

SuperJudge
Magus
Premium
join:2002-11-14
Albany, GA
clubs:

And what's going to be next? The next 'big vulnerability?'

I know it makes the computer internet friendly to have Active X and whatnot, but is it worth it in the end?
--
Updated My Journal

enOehT
Premium
join:2003-05-17
Langhorne, PA

1 edit

Holy crap!

I just ran windows update and it says there is nothing for me to update. OMG! I am a sitting duck. Please, help!
--

exocet_cm
In memory of dadkins
Premium
join:2003-03-23
New Orleans, LA
clubs:
·Cox HSI
·Suddenlink
·Cingular Wireless
·AT&T Southeast
·Charter Pipeline

Holy Panties Batman!!!

quote:
company's XP/NT/2000 operating
If your not running one of those OS's, then your good to go. Otherwise, your screwed.

Although I do wish you the best of luck!
Cheerio!

--
He that feeds a disease, feeds an enemy. Some diseases are starved. Starve your sins by fasting and humiliation. Either kill your sin, or your sin will kill you. - Thomas Watson Harmless as doves 131

enOehT
Premium
join:2003-05-17
Langhorne, PA

Ohh man! I'm SOOOO Screwed!

When my boss finds out about this I am going to lose my job! Please help me patch this thing up before all the worms and trojans come running in!

SOS!

This ship is going down nose first!
--

trparky
Bite My Shiny Metal Ass
Premium,MVM
join:2000-05-24
Cleveland, OH
clubs:
·AT&T U-Verse


2 edits

Re: Ohh man! I'm SOOOO Screwed!

•Microsoft Windows NT® Workstation 4.0 Service Pack 6a – Download the update.
•Microsoft Windows NT Server 4.0 Service Pack 6a – Download the update.
•Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6 – Download the update.
•Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, Microsoft 2000 Windows Service Pack 4 – Download the update.
•Microsoft Windows XP, Microsoft Windows XP Service Pack 1 – Download the update.
•Microsoft Windows XP 64-Bit Edition, Microsoft Windows XP 64-Bit Edition Service Pack 1 – Download the update.
•Microsoft Windows XP 64-Bit Edition Version 2003, Microsoft Windows XP 64-Bit Edition Version 2003 Service Pack 1 – Download the update.
•Microsoft Windows Server™ 2003 – Download the update.
•Microsoft Windows Server 2003 64-Bit Edition – Download the update.
--
WedgeAntilles250

Logwind

join:2003-06-20

Re: Ohh man! I'm SOOOO Screwed!

I think he's being sarcastic guys. Jesus. Everyone knows it's cool to hate MS. Get with the program.

trparky
Bite My Shiny Metal Ass
Premium,MVM
join:2000-05-24
Cleveland, OH
clubs:
·AT&T U-Verse

Re: Ohh man! I'm SOOOO Screwed!

Fool around with this exploit? YEAH RIGHT! I don't think that we should be kidding around with this.

I for sure am going to be making a few CDs up tonight with SP1 and this patch on it to give to a few n00bs I know.
--
WedgeAntilles250

Logwind

join:2003-06-20

Re: Ohh man! I'm SOOOO Screwed!

That went so far over your head, it was hijacked and flown into a major landmark.

GNXPower
Got Boost?
Premium
join:2003-12-18
Huntington Beach, CA
LOL, finally someone who got it.
yabos

join:2003-02-16
Ingersoll, ON

Re: Ohh man! I'm SOOOO Screwed!

His first post sounds like a legitimate post because the same thing really DID happen to me. But I just downloaded it from MS's website instead.

enOehT
Premium
join:2003-05-17
Langhorne, PA

2 legit, 2legit 2 quit!

The part about it not being available on Windows update is totally legit! I downloaded it from the link provided by you here: »www.microsoft.com/technet/treevi···-007.asp

Thanks for the link!

As for the losing my job, that was to add to the drama. But you did provide me what I was looking for.
--
BosstonesOwn

join:2002-12-15
Everett, MA
clubs:
·Comcast

said by trparky See Profile:
•Microsoft Windows NT® Workstation 4.0 Service Pack 6a – Download the update.
•Microsoft Windows NT Server 4.0 Service Pack 6a – Download the update.
•Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6 – Download the update.
•Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, Microsoft 2000 Windows Service Pack 4 – Download the update.
•Microsoft Windows XP, Microsoft Windows XP Service Pack 1 – Download the update.
•Microsoft Windows XP 64-Bit Edition, Microsoft Windows XP 64-Bit Edition Service Pack 1 – Download the update.
•Microsoft Windows XP 64-Bit Edition Version 2003, Microsoft Windows XP 64-Bit Edition Version 2003 Service Pack 1 – Download the update.
•Microsoft Windows Server™ 2003 – Download the update.
•Microsoft Windows Server 2003 64-Bit Edition – Download the update.

you find a link for amd athlon 64 based win xp yet ?? i cant locate on their site at all.
--
This package does not contain a winner...

sycocowz

join:2002-06-13
Ottsville, PA

Re: Ohh man! I'm SOOOO Screwed!

"Microsoft Windows XP 64-Bit Edition Version 2003 " looks like what you need

Ryan F
Take Back The Web
Premium
join:2002-10-18
Alexandria, VA
Check your install history on Windows Update. If KB828028 shows up, then you're fine.
cablemoose

join:2001-06-25
Martinsburg, WV

I would worry about that Eno Eht. This is just another classic example of Microsoft's laziness and ineptness in fixing there products. Product deadline (it certainly is NOT quality) seems to be there main concern. I'm "preaching to the choir" about the rest. Nuff said.

Lars

seaman
Premium
join:2000-12-08
Seattle, WA

Re: Holy crap!

I noticed that too. It hasnt been posted to WU yet but you can find the patches here-
»www.microsoft.com/technet/treevi···-007.asp
yabos

join:2003-02-16
Ingersoll, ON

Re: Holy crap!

It was on there on some PCs I patched, but not others.

JollyStomper
The Funky Feel One
Premium
join:2003-03-16
Right 'Dere
·Comcast Formerly ..

Strange...

I got the updates from WU a couple of hours before this article even broke out.

I heard about the exploit while watching Fox News (Neil Cavuto) and immediately checked Windows Update. Sure enough, they were there. Updated my XpPro boxen and my W2K server box (That had two).

cheers...
--
"As I was sayin' buster, this planet ain't big enough for the two of us so... OFF YA GO!"

DSL4Brains
Premium
join:2003-08-26
Portland, OR

Re: Holy crap!

I'm still not seeing it on WU. Perhaps they found a major glitch in the patch.
miketavares

join:2000-12-10
North Dighton, MA

Re: Holy crap!

it looks as though a couple of the WU servers have not yet gotten the patch. Keep trying (took me 4 tries on my laptop)
--
I was here
yabos

join:2003-02-16
Ingersoll, ON
Download from here.

It didn't show up on my home PC running XP Pro, but 2 work PCs it showed up.

enOehT
Premium
join:2003-05-17
Langhorne, PA

TOO Late! :-(

Too late! I wasn't quick enough. :-( All the data is gone, all infected. Why would they announce it and then not provide the patch right away?

Where is that extra pair of under ware, I know I put them around here somewhere?
--

exocet_cm
In memory of dadkins
Premium
join:2003-03-23
New Orleans, LA
clubs:
·Cox HSI
·Suddenlink
·Cingular Wireless
·AT&T Southeast
·Charter Pipeline

Screw it...

I don't care anymore. Once I get infected I'll format my HD and install windows 3.1. You never hear of many security problems with windwos 3.1. I'll just die away in peace...

--
He that feeds a disease, feeds an enemy. Some diseases are starved. Starve your sins by fasting and humiliation. Either kill your sin, or your sin will kill you. - Thomas Watson Harmless as doves 131

See 8 replies to this post
Iceman4u2
Premium
join:2003-12-02
Rochester, NY

That is just what we expect from $soft!!!

It is one thing to work towards a fix, but it's another thing to leave the exploit open and do nothing. This is along the line of the URL in the browser being able to be changed

Dude
What Happens When I Do This
Premium
join:2000-11-20
Chicago, IL
clubs:

i guess

my idea of staying one os behind microsoft apparently isnt going to cut it

DSL4Brains
Premium
join:2003-08-26
Portland, OR

Does anybody out there have a Commodore 64

...they want to sell me? I can't deal with this pain anymore. I'm going to call my attorney and start a law suit against Micro$oft for emotional duress. I'm losing weight, I'm drinking heavily and...and...and I kicked my POOR DAMN DOG TODAY over this.

I've gone over the edge emotionally. I'm completly mental.

See 31 replies to this post
JoshCloud9

join:2001-08-25
Atlanta, GA

Download patch here

It's availkable here:
»www.microsoft.com/downloads/deta···ylang=en

DSL4Brains
Premium
join:2003-08-26
Portland, OR

Re: Download patch here

How do I know that link isn't some weird re-direct or something? I'm afraid that when I do my Windows update, I may not really be at Microsoft, but at some strange Austrian web site owned by some 16 year-old kid who'll plant strange stuff on my PC.

FWIW, how do I know this is really Broadband Reports? I could be hijacked right now!

Where's my Zoloft?

fearless345
Oh No, You Did What I Told You

join:2002-03-08
Denver, CO
clubs:

Re: Download patch here

Probably need a double dose....

Phil
Rojo Sol
Premium
join:2001-06-11
Camarillo, CA
·Verizon FIOS

I run a different OS I'm safe - give me a break.

Yeah if that 'other' OS you were running comprised of ~95%+ of the world market there would be just as many exploits. I'm just tired of reading the constant MS bashing. If you have a problem with them, and haven't already, switch your OS for "crying out loud".

See 14 replies to this post

Logwind

join:2003-06-20

Patched.

Thanks for the heads up. As for the IE phishing patch, I'll roam without it as I like my browser to recognize the "@" symbol in URLs.

KAD Imaging
Just Shoot It
Premium
join:2002-09-21
Hialeah, FL
·AT&T Southeast

Re: Patched.

"And it's a solid hit! A long drive to the left wall...Here comes Win2K rounding second...he's out! Here come's WinXP past 3rd...he's out! 98SE is trying for home plate...going...going...and....he's SAFE! Win98SE is SAFE!!

lol

Seriously though, I've been lovin my perfectly stable 98SE for some years now. I suppose my work PC is fooked though. I might get on XP by SP3-4...;)
--
-The Cobra
"Heh, your broadband style is good grasshopper....but not good enough. Watch my Bellsouth style..."
1180K download 218K upload (BS FastAccess 1.5M/256K @ 19,000ft!)

Augustus III
If Only Rome Could See Us Now....

join:2001-01-25
Gainesville, GA

hi i am a l33t linux g33k

half the people that whine don't even know what they are whining about.

you all got your dell computers preinstalled with xp and all you can do now is whine. seriously, stop it. bugs are there and will be. the ones that are patched have been found. so if something has been there since the release of a program 2 years ago but never found by those who do that for a living, chance is that well... you are pretty safe.

ikarus1
Premium
join:2002-10-23
Urbanna, VA

Re: hi i am a l33t linux g33k

said by Augustus III See Profile:
so if something has been there since the release of a program 2 years ago but never found by those who do that for a living, chance is that well... you are pretty safe.

... or not ... you see "Oh, l33t, Linux g33k wanna be"...
The are are those professionals who don't call up Microsux and give them six months to fix their sheite.

But you're so l33t that you don't worry at all about the Intelligence communities of a dozen nations or organized crime...

I'm REALLY impressed with all the professional sarcasm in this thread...

BAWAHAHAHAHAH Microsoft manages to get a little bity think tank to keep their mouths shut for SIX MONTHS WHILE THEY FIGURE OUT HOW TO FIX THEIR OWN STUFF. IOW it took Microsoft six months to FIGURE OUT how to fix this one.

Jeeeeezzzzeweeee.... yep... that's impressive.

-m-
--
»www.freeantennas.com

Augustus III
If Only Rome Could See Us Now....

join:2001-01-25
Gainesville, GA

1 edit

Re: hi i am a l33t linux g33k

reading this gave me a headache. re-phrase it please.

kv5e
Ride Free
Premium
join:2001-12-04
Mesquite, TX

Laissez Faire?

M$ believes in $inning first and a$king for forgiveness later. Unbelievable to know this exploit and sit on it for six months.

There should be a fine for this exposure, but we all know the gov's track record with the Monolith $tentorian!
joebear29

join:2003-07-20
Alabaster, AL

Re: Laissez Faire?

Wow, you used $ instead of S. How witty.
Samwoo

join:2002-02-15
Rancho Palos Verdes, CA


1 edit
hmm... does this policy work though... i mean microsoft said that it doesn't want to make bugs and exploits public because that would make it easier for hackers to exploit it.
and in the report it said that this 6 month old exploit has not been exploited.
quote:
While there are no documented cases of attacks yet, security experts expect hackers to take advantage of the vulnerabilities in a matter of weeks or less
(wait they had 6 months right?)
well... now that the bug is public they estimate 2 weeks or less... but what if the bug was never public?
well... as far as I'm concerned it seems that sitting on it does work

and wait... who knows what would have happened if this bug was announced before microsoft had a fix for it?
maybe it really did take them 6 months to patch up the hole... i mean they are notorious for being slow with security

Smitedogg
Uzbekikitty
Premium
join:2000-11-11
Pueblo, CO

Re: Laissez Faire?

Security through obscurity? Doesn't work very well, I'm afraid. There could very well be exploits out for this right now, and it's just being kept quiet...afterall, if MS doesn't (seem to) notice, then it's the greatest 'sploit ever! Unpatched because there are no patches, and everyone is your slave! At least if you were aware of the problem you could have prevented these theoretical-crackers from doing what they want.

Dogg
--
My sig sucks.

ikarus1
Premium
join:2002-10-23
Urbanna, VA

said by Samwoo See Profile:
hmm... does this policy work though... i mean microsoft said that it doesn't want to make bugs and exploits public because that would make it easier for hackers to exploit it.
and in the report it said that this 6 month old exploit has not been exploited.
quote:
While there are no documented cases of attacks yet, security experts expect hackers to take advantage of the vulnerabilities in a matter of weeks or less
(wait they had 6 months right?)
well... now that the bug is public they estimate 2 weeks or less... but what if the bug was never public?
well... as far as I'm concerned it seems that sitting on it does work

and wait... who knows what would have happened if this bug was announced before microsoft had a fix for it?
maybe it really did take them 6 months to patch up the hole... i mean they are notorious for being slow with security

Blind faith... Microsoft lovers unite... Place your blind faith here...

How would Microsoft even know whether it was ever exploited or not? That is utterly undocumentable. They KNOW it has never been exploited. These are the kinds of lies Microsoft users have come to love... Anyone want a little salt with that baloney.

-m-
-m-
--
»www.freeantennas.com

mr_slick

join:2003-05-22
Lynnwood, WA

...may bypass firewall

and i thought i was fairly safe behind nat router and NIS and (most of all) "safe computing". looks like i'm going to have to build a linux box firewall to put in front of the router ---this site has made me a believer --amen!

blazerx

join:2003-10-07
Lakeport, CA

how long before big bad virii emerge?

a week? two? place your bets now!

DSL4Brains
Premium
join:2003-08-26
Portland, OR

Re: how long before big bad virii emerge?

If memory serves me correctly, the last time somebody posted something like this, two weeks later SoBig emerged. I'll take two weeks.

ikarus1
Premium
join:2002-10-23
Urbanna, VA

Re: how long before big bad virii emerge?

Not me, I figure it has already been exploited by real professionals. You know these Microsoft lovers spend all their time whining about the "kids" who write this stuff, while in the *nix world, we have been dealing with PROFESSIONALS who exploit these holes for a very long time... "One flew over the..." yeah, whatever.

I see all this whining and complaining. "If you were number one they'd be after you too." Hell, kids, *nix STILL rules the server world. WE ARE NUMBER ONE. Nobody runs as many servers. So step back, take a look at reality. Which would you rather crack, a desktop or a server? Well... There you go...

No, my money is this one has already been exploited by one or another Intel shop or one or another professional criminal.... In the *nix world when we are compromised, there is exactly one option. Reformat... Reinstall... Know why? Because we GET it. We know what it means when someone gets "root". Microsoft and way too many others DO NOT GET IT, 'cause it means exactly the same thing when someone gets "Administrator". Once a trojan is on your system, you can no longer trust the system. PERIOD. END OF STORY. Yet, we see all sort supposed professionals telling us how to recover from this or that trojan...

There is only one way and it is not the Microsoft way.
-m-
--
»www.freeantennas.com

Smitedogg
Uzbekikitty
Premium
join:2000-11-11
Pueblo, CO

Re: how long before big bad virii emerge?

As a long time linux user, I have to admit that you're embarrassing me.

quote:
ell, kids, *nix STILL rules the server world. WE ARE NUMBER ONE
quote:
There is only one way and it is not the Microsoft way.
Ah yes, the One True Path advocate/zealot.

quote:
In the *nix world when we are compromised, there is exactly one option. Reformat... Reinstall... Know why? Because we GET it. We know what it means when someone gets "root". Microsoft and way too many others DO NOT GET IT, 'cause it means exactly the same thing when someone gets "Administrator".
Besides the fact that you went on a tangent in one sentence, you are also not making sense. We reformat and reinstall everything because we use the word root, which means the same as administrator in Windows?

Dogg
--
My sig sucks.

ikarus1
Premium
join:2002-10-23
Urbanna, VA


1 edit

Re: how long before big bad virii emerge?

said by Smitedogg See Profile:
quote:
There is only one way and it is not the Microsoft way.
Ah yes, the One True Path advocate/zealot.

quote:
In the *nix world when we are compromised, there is exactly one option. Reformat... Reinstall... Know why? Because we GET it. We know what it means when someone gets "root". Microsoft and way too many others DO NOT GET IT, 'cause it means exactly the same thing when someone gets "Administrator".
Besides the fact that you went on a tangent in one sentence, you are also not making sense. We reformat and reinstall everything because we use the word root, which means the same as administrator in Windows?

Dogg

LoL... Naw... The truth is that if you are compromised and the person who compromised you has the opportunity to execute even a single command as Admin or Root or whatever... From that moment forward, you really can't trust the box. You don't know what was done. The person might have recompiled the kernel or replaced any of the .DLL files. You simply do not know and can not prove what was done without extensive and expensive analysis... but the Microsoft world insists upon giving us worthless cookbook formulae for removing these trojans... yet we do not know what was actually done to the system...

1) Take the system off line.
2) Save whatever data you wish for forensics.
3) Format and Reinstall...

And I suppose the point was that Admin is root is Admin... If you don't get it, you don't understand the flag bits in a microprocessor... Once someone had System Administrator authority, no matter what that is called, they can do anything they wish to the system and delete/modify all accounting records... That goes for ALL systems.

It is very simple.
-m-
--
»www.freeantennas.com

Smitedogg
Uzbekikitty
Premium
join:2000-11-11
Pueblo, CO

Re: how long before big bad virii emerge?

quote:
And I suppose the point was that Admin is root is Admin...If you don't get it, you don't understand the flag bits in a microprocessor...
What does knowing that admin describes root on a microsoft OS have to do with flag bits on a microprocessor?
--
My sig sucks.

Pole883
Premium
join:2004-01-27
Schenectady, NY

Huffin' and Puffin'!!

Boy, oh boy..........:o:o:p
--
Pole883

enOehT
Premium
join:2003-05-17
Langhorne, PA

eEye Digital Security, RAP SONG?

This is too funny, here: »www.eeye.com/html/Research/Advis···210.html is the companies press release, they made a RAP SONG about the whole thing. ROFLOL!
--

enOehT
Premium
join:2003-05-17
Langhorne, PA

Check it out!

Preamble:
We wanted to write another "Night Before Xmas" poem but the vendor missed the last few release dates, so we had to resort to some MC(SE) Hammer:

U Can't Trust This
By: MCSE Hammer

Blaster did ya some harm
We just say, hey, another worm
But thank you, for trusting me
To mind your site's security
It's all good, when your server's downed
Our dope PR will pass blame around
Cuz it's known as such
That this is some software, you can't trust

I told ya Homeland
U can't trust this
Yeah that's why we're giving ya the code
U can't trust this
Check out eEye, man
U can't trust this
Yo let 'em bust more funky system
U can't trust this

Give 'em a string or recvfrom
Like no sweat they got the keys to your kingdom
Now ya know
You talk about eEye, you're talking about holes
Remote and tight
Coders still sweating so someone better write
A book to learn
What it's gonna take in '04
To earn some trust
Legit, either secure or ya might as well quit

That's the word because you know
U can't trust this
U can't trust this

Breakin' in

Stop -- eEye time
--

ikarus1
Premium
join:2002-10-23
Urbanna, VA

Re: Check it out!

Are we having fun yet? They just refuse to believe, because it is easier to live in denial than it is to accept the truth and learn another OS.

-m-
--
»www.freeantennas.com

DSL4Brains
Premium
join:2003-08-26
Portland, OR

Re: Check it out!

said by ikarus1 See Profile:
Are we having fun yet? They just refuse to believe, because it is easier to live in denial than it is to accept the truth and learn another OS.

-m-

You seem to think that I would lose sleep over this. Tell me, why do I suspect that even in your most tender, loving moments of intimacy (if you have them), you have Linux on your mind?

ikarus1
Premium
join:2002-10-23
Urbanna, VA

Re: Check it out!

said by DSL4Brains See Profile:
said by ikarus1 See Profile:
Are we having fun yet? They just refuse to believe, because it is easier to live in denial than it is to accept the truth and learn another OS.

-m-

You seem to think that I would lose sleep over this. Tell me, why do I suspect that even in your most tender, loving moments of intimacy (if you have them), you have Linux on your mind?

Why do I think that in your most tender loving moments of intimacy... you have a mind that I should loose sleep over?

... or something like that anyway? ...
-m-
--
»www.freeantennas.com
Freezone

join:2000-09-29
Southfield, MI

So if the org that found the exploit had...

gotten themselves hacked we would alll be screwed. Unfound exploits that lead to worms is onething, but MS knew about this for 6 months. Now I have two weeks to tell everyone to patch their machines before I have to fix them all.

enOehT
Premium
join:2003-05-17
Langhorne, PA

Re: So if the org that found the exploit had...

What makes you think you have two weeks?

ikarus1
Premium
join:2002-10-23
Urbanna, VA

said by Freezone See Profile:
gotten themselves hacked we would alll be screwed. Unfound exploits that lead to worms is onething, but MS knew about this for 6 months. Now I have two weeks to tell everyone to patch their machines before I have to fix them all.

Naw bud;

It's way worse than that. If the people in the org talked in a bar during that six months or the people at Microsoft had talked in a bar during that six months... If somebody's ex-wife or ex-girl friend had wanted to make a little money with organized crime... If some employee at Microsoft had wanted to make a little extra money... and stalled the patch for six months... Well you get the idea... anything is possible.

It's way worse than that. If the org wasn't the only one who figured it out... Looking at the applicable patch list... Anyone, for a very long time could have discoverd and exploited the hole FOR YEARS and nobody would know. Hell, after they fix this we may discover that credit card fraud on the internet is down sixty percent...

It is THAT bad. God knows what sort of privacy breaches, intelligence breaches, and ect...etc.... might have occured.

-m-
--
»www.freeantennas.com

Tyrano2K

join:2001-07-29
Canada


1 edit

If your have a hardware firewall

If you have a hardware firewall you should be safe since it doesn't run the windows OS
Thats pritty scray if you don't have one tho.
--
~Tyrano2K
-
Owner Of RP614 Firmware Site
( »home.cogeco.ca/~firmware/ )

enOehT
Premium
join:2003-05-17
Langhorne, PA

bypasses firewall!

article says the firewall can be totally bypassed with this one.

linicx
Caveat Emptor
Premium
join:2002-12-03
United State

Re: bypasses firewall!

I can't help but wonder if it can bypass a Nat Firewall Router that does NOT have a backdoor built into it? Mine has passed all security scans run against it so far.
--
Be careful what you ask for - you just might get it.

enOehT
Premium
join:2003-05-17
Langhorne, PA

Well, in that case......

In your case, I am very confident nothing will happen. You are obviously immune to such feeble attacks from simple mortals.

Can I come over to your house and surf the net while microcrap resolves the issue for everyone else?
--
XknightHawkX

join:2003-02-13
Morton, IL
clubs:

Well what do you expect

Look at Microsoft. They are just building OS after OS and not worrying about security issues. What did they think that putting a firewall in XP (over bloated OS in my opinion). But listen to half the people complain about a getting a virus almost as soon as they connect to internet. I still run 98se and now they won't support it anymore cause they want me to spend hundreds of dollars on a newer OS that takes more space and more speed and more memory. The next OS they are working on will probably be over bloated and have a bunch of new security exploits. Why does all the new software have to be bigger and more memory leaking. Sorry if I got a little off subject it's just annoying to have to read about more problems with IE. IE will all ways have security exploits.

ikarus1
Premium
join:2002-10-23
Urbanna, VA


1 edit

Re: Well what do you expect

said by XknightHawkX See Profile:
Look at Microsoft. They are just building OS after OS and not worrying about security issues. What did they think that putting a firewall in XP (over bloated OS in my opinion). But listen to half the people complain about a getting a virus almost as soon as they connect to internet. I still run 98se and now they won't support it anymore cause they want me to spend hundreds of dollars on a newer OS that takes more space and more speed and more memory. The next OS they are working on will probably be over bloated and have a bunch of new security exploits. Why does all the new software have to be bigger and more memory leaking. Sorry if I got a little off subject it's just annoying to have to read about more problems with IE. IE will all ways have security exploits.

Well, yes they do want you to buy the new OS and the new hardware required to run it... but they will throw in the security vulnerabilities free of charge.

While I knew that Linux (SuSE/RedHat) was functional on a P-200 with 64 Megs of ram... (Don't try that with 2K/XP/2K3) I was shocked at the raw speed of FreeBSD on the same hardware the other day.... Don't get me wrong, I'm a linux lover but DAMN, that BSD was fast....
-m-
--
»www.freeantennas.com

DSL4Brains
Premium
join:2003-08-26
Portland, OR

Re: Well what do you expect

said by ikarus1 See Profile:

Well, yes they do want you to buy the new OS and the new hardware required to run it... but they will throw in the security vulnerabilities free of charge.

-m-

Ahhh...what better way to keep the American economy moving than by purchasing and spending your money instead of trying to take it all to Heaven with you? And freebies thrown in to boot!

ThunderCorp

join:2002-03-11
Chula Vista, CA

Wow, nice.

Must be a grand day to be a Microsoft Windows user. First MyDoom.a, then MyDoom.b, now DoomJuice .. and to top it off, this critical Windows exploit that affects nearly all of MS's modern OS line? I'm almost glad to be a Mac user.. wait I am glad. In fact, I'm thankful.

/goes back to uneventful creative work on Final Cut Pro and iDVD, while listening to iTunes

See 15 replies to this post
Forums » The Mother of All MS Exploits?page: 1 · 2


Monday, 30-Nov 21:31:29 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF