Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Windows XP contains massive security hole
The Inquirer ^ | Wednesday 11 September 2002, 11:50 | Paul Hales

Posted on 09/11/2002 1:40:24 PM PDT by HAL9000

Windows XP contains massive security hole

Install the Service Pack and, shush, don't tell anyone...

MICROSOFT'S RUSH to get Windows XP SP1 out and about may have been motivated by a desire to hide a vulnerability afflicting the operating system (cough) that allows hackers to delete files from a computer accessing a tweaked web page.

According to this Spanish-language site, a Googled translation of which is here, "a defect in Windows XP allows that anyone can erase archives of our computer if click becomes on a connection maliciously constructed, as much when visiting a malignant Web site, like a receiving a message with format HTML". Sorry about the language, but you get the picture.

A reader writes a little more clearly that this vulnerability allows the files contained in any specified directory on your system to be deleted if you click on a specially-formed URL. He points to Gibson Research here, where they warn, "This URL could appear anywhere: sent in malicious eMail, in a chat room, in a newsgroup posting, on a malicious web page, or even executed when your computer merely visits a malicious web page. It is likely to be widely exploited soon."

This is a critical vulnerability and one Microsoft has done its best to keep secret, it seems.

Another reader tells us he saw a report on TechTV, the background to which they give here where they state that Microsoft has known about the flaw for some 11 weeks but kept the lid on it because it is so easy to exploit.

Microsoft urges Windows XP users to download the Service Pack and install it as quickly as possible. You can find that here . It's a large file, though, and CD versions are only available on the US and Canada at the moment, according to Microsoft.

The advice from various sources for users unable to install the Service Pack is to find and rename the affected file uplddrvinfo.htm. µ



TOPICS: News/Current Events; Technical
KEYWORDS: lowqualitycrap; microsoft; techindex; windows; xp
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-80 ... 101-120 next last

1 posted on 09/11/2002 1:40:25 PM PDT by HAL9000
[ Post Reply | Private Reply | View Replies]

To: HAL9000
What in heck is wrong with Microsoft? Why are there products so vulnerable to security breaches?
2 posted on 09/11/2002 1:41:39 PM PDT by paulklenk
[ Post Reply | Private Reply | To 1 | View Replies]

To: HAL9000
dont worry all you microsoft xp users just send me your social security number with your name and I will get back to you with a fix for your problem
3 posted on 09/11/2002 1:43:36 PM PDT by TheRedSoxWinThePennant
[ Post Reply | Private Reply | To 1 | View Replies]

To: HAL9000
LOW QUALITY CRAP

LOL! I downloaded SP1 for XP pro, and now my computer reboots whenever it want's to. It's done it 3 times today so far.

4 posted on 09/11/2002 1:44:49 PM PDT by Pern
[ Post Reply | Private Reply | To 1 | View Replies]

To: HAL9000
What a surprise, a Microsoft product with security flaws! < /sarcasm>

5 posted on 09/11/2002 1:45:27 PM PDT by big'ol_freeper
[ Post Reply | Private Reply | To 1 | View Replies]

To: Pern
Gee, my new copy of OS X 10.2 (Jaguar) is running just fine. Installed clean as a whistle, has some fun new features, no need to reboot yet.

Yes, I switched, and I'm a much happier computer user now.

6 posted on 09/11/2002 1:47:59 PM PDT by Billy_bob_bob
[ Post Reply | Private Reply | To 4 | View Replies]

To: redsoxallthewayintwothousand2
dont worry all you microsoft xp users just send me your social security number with your name and I will get back to you with a fix for your problem

Don't you also need my mother's maiden name...to generate by new security key?

7 posted on 09/11/2002 1:48:26 PM PDT by Pearls Before Swine
[ Post Reply | Private Reply | To 3 | View Replies]

To: Billy_bob_bob
Jag is COOL!
8 posted on 09/11/2002 1:50:49 PM PDT by cmsgop
[ Post Reply | Private Reply | To 6 | View Replies]

To: All
wow imagine that...

--erik

9 posted on 09/11/2002 1:52:51 PM PDT by erikm88
[ Post Reply | Private Reply | To 8 | View Replies]

To: HAL9000
I downloaded SP-1 the other night. I couldn't delete any files or folders via the "right click". Found out that I had to set the folders or files for sharing. This is dumb as hell, I'm the owner and only user.
10 posted on 09/11/2002 1:54:44 PM PDT by Capt_Hank
[ Post Reply | Private Reply | To 1 | View Replies]

To: HAL9000
This always reminds about Asimov's Foundation trilogy. The big fat bloated empire with all the resources in the galaxy, building enormous and inefficient spaceships, versus resource constrained Terminous, a planet that was driven to build more and more efficient technology and brainpower. How much longer before the PC OS won't fit on one CD?? And then there is DLL hell and registry bloat too. Just depressing.

...I know, I know, but I've never seen a mac in any (about 20-30) corporate finance/accounting settings since an old Classic was used as a foot rest back in 1993. I'll change when they change, I gotta eat.

11 posted on 09/11/2002 1:54:53 PM PDT by evolved_rage
[ Post Reply | Private Reply | To 1 | View Replies]

To: HAL9000
indexing
12 posted on 09/11/2002 1:55:04 PM PDT by meadsjn
[ Post Reply | Private Reply | To 1 | View Replies]

To: HAL9000
...Microsoft urges Windows XP users to download the Service Pack and install it as quickly as possible. You can find that here . It's a large file, though...

Only took my system 2.5 hours to download and install on a 10 MB net connection.

13 posted on 09/11/2002 1:58:10 PM PDT by SGCOS
[ Post Reply | Private Reply | To 1 | View Replies]

To: Pern
By default XP is set to restart anytime you would have gotten a BSOD in a previous version of Windows. Stupid design decision.

If you can stay running long enough, you can change the behavior by right clicking My Computer, Advanced, Startup and Recovery Settings, and uncheck Automatically Restart.

It doesn't resolve the error condition, but at least you get a chance to figure out what's causing the error condition.

Here’s the release notes ("errata" list) for SP1-
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q324722
14 posted on 09/11/2002 1:59:28 PM PDT by Slainte
[ Post Reply | Private Reply | To 4 | View Replies]

To: HAL9000
GRC.com is a site you should book mark and check from time to time.

For those of you running Windows 9x (Windows 95/98) he has a very good trick to significantly increase you on line security.

GRC Link Here to Windows 9x security fix

Excerpt from the site on this subject (95/98 security):

Network Bondage
Discipline your network bindings in the privacy of your own home.

Microsoft's networking technology is only required for sharing files and printer services with other Microsoft-based PC's. It is not needed for connecting to the Internet or for using any Internet services. Using it in wide area networking (WAN - like the Internet) situations, dramatically lowers your security by divulging information about you and your computer, exposing Microsoft's weak password protection system to password crackers over the Internet, bringing your machine to the attention of Internet scanners and intruders and making you a target for attack.

When going through the process, if you do, print out the instructions, read through them once. Don't be intimidated. It is very step by step. Then have the instructions next to you as you work through the changes.

15 posted on 09/11/2002 2:02:44 PM PDT by BJungNan
[ Post Reply | Private Reply | To 1 | View Replies]

To: Pern
That's not a flaw, it's a feature (smirk)
16 posted on 09/11/2002 2:05:27 PM PDT by IsItTimeYet
[ Post Reply | Private Reply | To 4 | View Replies]

To: HAL9000
A massive security hole in Windows XP? Didn't Bill Gates say that Windows XP was the most secure OS ever? Wasn't their a memo passed to all Microsoft staff saying security was job #1? None of this makes since. Maybe Bush2000 can explain it. He seems to know all of the Microsoft marketing excuses.

Guess its time to switch or sort of switch.

17 posted on 09/11/2002 2:08:03 PM PDT by toupsie
[ Post Reply | Private Reply | To 1 | View Replies]

To: Billy_bob_bob
Gee, my new copy of OS X 10.2 (Jaguar) is running just fine. Installed clean as a whistle, has some fun new features, no need to reboot yet. Yes, I switched, and I'm a much happier computer user now.

Good for you! I installed Jaguar on my work Mac and haven't shut it down or rebooted it since. Sixteen days, 6 hours and 53 minutes of uptime so far and I run all kinds of alpha and beta quality software for work. Flawless performance. As a bonus, Apple gave me a cool program yesterday called, iCal. A really nice calendar application--for free!

18 posted on 09/11/2002 2:11:47 PM PDT by toupsie
[ Post Reply | Private Reply | To 6 | View Replies]

To: SGCOS
Only took my system 2.5 hours to download and install on a 10 MB net connection.

Too bad that was 2.4 hours more than the hacker needed to steal data off your hard drive! :P

19 posted on 09/11/2002 2:13:16 PM PDT by toupsie
[ Post Reply | Private Reply | To 13 | View Replies]

To: SGCOS
If you download the service pack, does that completely take care of the security problem?
20 posted on 09/11/2002 2:13:31 PM PDT by my_pointy_head_is_sharp
[ Post Reply | Private Reply | To 13 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-80 ... 101-120 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson