Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Neolithic Windows security hole alive and well in Windows 7
IT World ^ | January 2010 | sjvn

Posted on 01/21/2010 11:31:58 AM PST by ShadowAce

click here to read article


Navigation: use the links below to view more comments.
first 1-2021-37 next last

1 posted on 01/21/2010 11:31:58 AM PST by ShadowAce
[ Post Reply | Private Reply | View Replies]

To: rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

2 posted on 01/21/2010 11:32:19 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

I wish I could run a copy of the old DOS game called F-29 Retaliator ( i think) it was way too fun


3 posted on 01/21/2010 11:33:56 AM PST by Mr. K (This administration IS WEARING OUT MY CAPSLOCK KEY!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

x64 OK?


4 posted on 01/21/2010 11:35:18 AM PST by paulycy (Demand Constitutionality.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Mr. K

Not to mention Space Goose!


5 posted on 01/21/2010 11:36:26 AM PST by willgolfforfood
[ Post Reply | Private Reply | To 3 | View Replies]

To: paulycy

I haven’t heard about x64 systems one way or the other.


6 posted on 01/21/2010 11:36:48 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 4 | View Replies]

To: ShadowAce

Thanks. The article implies it’s only 32 bit but...? I’m not overly worried about this one.


7 posted on 01/21/2010 11:39:12 AM PST by paulycy (Demand Constitutionality.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: ShadowAce
Windows (32bit, 64bit, et al) was, is, and always will be fundamentally insecure due to the design decisions baked into the MS ecosystem and their emphasis on shiny new features over security and stability.

I am not saying this as a home hobbyist, but as a professional, degreed, computer scientist.

8 posted on 01/21/2010 11:48:56 AM PST by SecondAmendment (Restoring our Republic one Post at a Time)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce
I call BS.

There are no such services as "CMDLINE" or "WOWCMDLINE" in Windows, nor any reasonable variations that I could think of.

9 posted on 01/21/2010 11:51:00 AM PST by TChris ("Hello", the politician lied.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: TChris

I’m running Windows XP SP3, and the keys are there as listed in the post above.


10 posted on 01/21/2010 11:56:35 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 9 | View Replies]

To: ShadowAce

“I’m Janet Napolitano, and Windows 7 was my idea!”

Mark


11 posted on 01/21/2010 11:56:44 AM PST by MarkL (Do I really look like a guy with a plan?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: TChris
OK, I blame the author's misuse of the term "service". In Windows, that word has a very specific meaning, and what he was talking about is NOT it.

The VDM (Virtual DOS Machine) is NOT a Windows Service, it's a subsystem. The two "service" names he lists are actually Windows registry values in the WOW key, as described.

I'm not buying that this is a huge security hole, else every Windows machine would be compromised by now, and (all jokes aside) they are not.

Smells like another Windows-bashing rant to me.

12 posted on 01/21/2010 11:56:49 AM PST by TChris ("Hello", the politician lied.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: ShadowAce

The article starts with “One of the reasons I’ve never liked Windows “ so you know its a hit piece. Article is hogwash to sell copies of their software.

Unless of course you are still running msdos or 16 bit apps.


13 posted on 01/21/2010 11:57:45 AM PST by driftdiver (I could eat it raw, but why do that when I have a fire.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: driftdiver
Article is hogwash to sell copies of their software.

Except that he never tries to sell anything, but does show the reader step-by-step how to fix it--without buying anything.

14 posted on 01/21/2010 11:58:48 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 13 | View Replies]

To: ShadowAce

I’m running windows xp sp3 and the keys are not there and the services are not running.

Of course I’m not running a terminal server or archaic software.


15 posted on 01/21/2010 11:59:17 AM PST by driftdiver (I could eat it raw, but why do that when I have a fire.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: TChris

“Smells like another Windows-bashing rant to me. “

Its also an attempt to hawk this loser company.


16 posted on 01/21/2010 12:00:09 PM PST by driftdiver (I could eat it raw, but why do that when I have a fire.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: ShadowAce
Yes, the key and string values are there. They just aren't services, as the author described.

I first looked at all the services in the Services Manager and in the Registry before I got to the end of the article. :-/

At any rate, I really doubt that this is as big of a problem as he describes. It's very typical of the "you're all idiots and I'm the smartest guy in the room" kind of thing we IT geeks are sometimes known for.

17 posted on 01/21/2010 12:00:56 PM PST by TChris ("Hello", the politician lied.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: ShadowAce

“A security company called Immunity has already released an add-on to its program Canvass that can be used to show if your computer is vulnerable to attacks using this method.”

NOT an attempt to sell anything????? Wanna rethink that?


18 posted on 01/21/2010 12:01:20 PM PST by driftdiver (I could eat it raw, but why do that when I have a fire.)
[ Post Reply | Private Reply | To 14 | View Replies]

To: TChris
I call BS.

There are no such services as "CMDLINE" or "WOWCMDLINE" in Windows, nor any reasonable variations that I could think of.

It's not a Windows service itself, but a built in part of the ntvdm subsystem. It was built in as part of MS-DOS compatibility mode.

Mark

19 posted on 01/21/2010 12:02:34 PM PST by MarkL (Do I really look like a guy with a plan?)
[ Post Reply | Private Reply | To 9 | View Replies]

To: TChris

“I blame the author’s misuse of the term “service”. In Windows, that word has a very specific meaning, and what he was talking about is NOT it.”

You would think this “expert” would realize this, unless of course he’s trying to stir up fear and sell more software.


20 posted on 01/21/2010 12:02:47 PM PST by driftdiver (I could eat it raw, but why do that when I have a fire.)
[ Post Reply | Private Reply | To 12 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-37 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson