republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Microsoft Security Advisory (935423) Vulnerability in Window
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
dinput.dll »
« Pimp my Tinfoil hat  
AuthorAll Replies

Mele20
Premium
join:2001-06-05
Hilo, HI

reply to NICK ADSL UK
Re: Microsoft Security Advisory (935423) Vulnerability in Window

Whoa! This is nasty! There is NO WAY to protect yourself if you use Outlook Express (even if you use IE7) and even Windows Vista Mail is somewhat vulnerable. From Microsoft Security Advisory (935423):

"Caveat: Reading e-mail in plain text on Windows Vista Mail does not mitigate attempts to exploit the vulnerability when Forwarding and Replying to mail sent by an attacker.

Note: Reading e-mail in plain text on Outlook Express does not mitigate attempts to exploit this vulnerability."

I have always read all email in OE in Plain Text. That has been excellent protection until this. Alexander Sotirov from Determina recommends reading ALL MAIL with Telnet. That is sure going to be fun.
--
"If you want to do DRM on a PC then you need to treat the user as the enemy." Ross Anderson in "`Trusted Computing' Frequently Asked Questions"

»www.msfirefox.com/


AB
Premium
join:2006-04-04
Leesburg, VA

said by Mele20 See Profile :

Whoa! This is nasty! There is NO WAY to protect yourself if you use Outlook Express (even if you use IE7)
Don't use an animated cursor?


EGeezer
Go Bobcats
Premium
join:2002-08-04
Country!
·Callcentric
·RoadRunner Cable
·AT&T CallVantage

reply to Mele20
Microsoft has its priorities well placed ...

said by Mele20 See Profile :

I have always read my incoming email in OE in Plain Text. That has been excellent protection until this. Alexander Sotirov from Determina recommends reading ALL MAIL with Telnet. That is sure going to be fun.
I use a really old version of Mailwasher (2.0.28 beta) to screen, preview and scrub junk while it's on my ISP's POP server. It's been quite effective and requires minimal effort.

What really gripes me is that Microsoft has not issued a fix for this, but I just saw the second non-patch Tuesday WGA update notification. MS didn't wait for patch Tuesday to issue these "high priority updates".

[sarcasm]
But I'm sure that WGA updates must be a more meaningful priority for users than these insignificant little security holes. But at least I know if my systems become infected, they'll be using "genuine copies" of a vulnerable OS.
[/sarcasm]
--
03:14:07 UTC Tuesday, Jan. 19, 2038 - a date that will live in infamy...
Forums » Up and Running » Security » Securitydinput.dll »
« Pimp my Tinfoil hat  


Tuesday, 01-Dec 23:39:59 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [132] Comcast Releasing Promised Usage Meter
· [67] Baltimore To Ban Lazy Cable Installs
· [56] Broadband Killed The Game Console
· [49] Rogers Unveils The ISP Dream Model
· [49] Latest Consumer Reports Survey Not Kind To AT&T
· [40] Rural Carriers Quickly Embracing Fiber
· [35] Charter Exits Chapter 11
· [35] ACTA: Global Three Strikes
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [24] Midcontinent Socked With Easement Lawsuit
Most people now reading
· Download speeds very slow. [AT&T West]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Windows 7 boot manager editing questions [Microsoft Help]
· Am I the only one that loves to work in IT? [No, I Will Not Fix Your #@$!! Computer]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Data Usage Meter Launched [Comcast HSI]
· Considering Leaving Vonage, who should I Consider? [VOIP Tech Chat]
· 16% packet loss. damn dsl. los angeles [AT&T West]
· Why Criminals (Hackers) Must Not Be Rewarded [Security]
· Need a better layout.. [Home Repair & Improvement]