Jul 07, 2009, 03:26 PM // 15:26
|
#1
|
Site Contributor
|
Microsoft warns of serious computer security hole
Quote:
Microsoft warns of serious computer security hole
SAN JOSE, Calif. -
Microsoft Corp. has taken the rare step of warning about a serious computer security vulnerability it hasn't fixed yet.
The vulnerability disclosed Monday affects Internet Explorer users whose computers run the Windows XP or Windows Server 2003 operating software.
It can allow hackers to remotely take control of victims' machines. The victims don't need to do anything to get infected except visit a Web site that's been hacked.
Security experts say criminals have been attacking the vulnerability for nearly a week. Thousands of sites have been hacked to serve up malicious software that exploits the vulnerability. People are drawn to these sites by clicking a link in spam e-mail.
The so-called "zero day" vulnerability disclosed by Microsoft affects a part of its software used to play video. The problem arises from the way the software interacts with Internet Explorer, which opens a hole for hackers to tunnel into.
Microsoft urged vulnerable users to disable the problematic part of its software, which can be done from Microsoft's Web site, while the company works on a "patch" — or software fix — for the problem.
Microsoft rarely departs from its practice of issuing security updates the second Tuesday of each month. When the Redmond, Wash.-based company does issue security reminders at other times, it's because the vulnerabilities are very serious.
A recent example was the emergency patch Microsoft issued in October for a vulnerability that criminals exploited to infect millions of PCs with the Conficker worm. While initially feared as an all-powerful doomsday device, that network of infected machines was eventually used for mundane moneymaking schemes like sending spam and pushing fake antivirus software.
http://tech.yahoo.com/news/ap/200907...osoft_security
|
Okay, the reason this article is hilarious is this paragraph:
"Microsoft urged vulnerable users to disable the problematic part of its software, which can be done from Microsoft's Web site, while the company works on a "patch" — or software fix — for the problem."
So you have to either stop using Windows XP or Internet Explorer. But of course they can't SAY that, I mean how bad would that look for Microsoft to say specifically "Internet Explorer/Windows XP is so bad just don't use it" so instead they try to tone it down with "disable the problematic part of the software." I know it's the Video ActiveX controller that is the problem but for the thousands who just read that and don't have a clue... they're sitting there wondering what they should do.
|
|
|
Jul 07, 2009, 03:35 PM // 15:35
|
#2
|
Ascalonian Squire
Join Date: Feb 2006
Profession: W/
|
MS: "Hey Steve.. I just found this hole in WinXP/IE.."
MS2: "Really? What is it..?"
MS: "Apparently you can use it to take control of the user's PC.. like all the other security holes that exist.."
MS2: "Wow.. that's really bad.. What do we do?"
MS: "I've got it.. let's not do anything and release a statement telling people to either disable the software or buy Windows 7!"
MS2: "Brilliant!"
Last edited by Wesyrine; Jul 07, 2009 at 04:26 PM // 16:26..
Reason: needs moar accurateness
|
|
|
Jul 07, 2009, 03:38 PM // 15:38
|
#3
|
Academy Page
Join Date: Dec 2008
Guild: Whatever Floats Your [Boat]
Profession: A/
|
I loled...
But seriously...who uses IE anyway?
|
|
|
Jul 07, 2009, 03:47 PM // 15:47
|
#4
|
Lion's Arch Merchant
Join Date: Jul 2009
Location: in a quiet little town that i love.
Guild: Ancient Dragoons [AGED]
Profession: W/
|
Quote:
Originally Posted by Wesyrine
MS: "Hey Bill.. I just found this hole in WinXP/IE.."
MS2: "Really? What is it..?"
MS: "Apparently you can use it to take control of the user's PC.. like all the other security holes that exist.."
MS2: "Wow.. that's really bad.. What do we do?"
MS: "I've got it.. let's not do anything and release a statement telling people to either disable the software or buy Windows 7!"
MS2: "Brilliant!"
|
LMFAO!!!! you should work for snl XD
|
|
|
Jul 07, 2009, 03:51 PM // 15:51
|
#5
|
Lion's Arch Merchant
Join Date: Aug 2008
Location: Lots of places~
Profession: D/
|
Quote:
Originally Posted by Roy Frogger
But seriously...who uses IE anyway?
|
I /agree
12chars
|
|
|
Jul 07, 2009, 03:52 PM // 15:52
|
#6
|
Jungle Guide
Join Date: Jun 2005
Guild: None
Profession: Mo/
|
Just don't use IE, like I've been saying for what... 3+years?
|
|
|
Jul 07, 2009, 03:58 PM // 15:58
|
#7
|
Jungle Guide
Join Date: Oct 2007
Guild: Heroes of Elonia [HE]
Profession: W/Rt
|
Lol IE. Nice joke.
|
|
|
Jul 07, 2009, 04:14 PM // 16:14
|
#8
|
Desert Nomad
Join Date: May 2007
Location: living room
Profession: N/
|
You guys don't know anything IE is the leet man, sorry just a bit of sarcasm there. Just use firefox or something IE sucks anyway
|
|
|
Jul 07, 2009, 04:15 PM // 16:15
|
#9
|
Frost Gate Guardian
|
Quote:
Originally Posted by Wesyrine
MS: "Hey Bill.. I just found this hole in WinXP/IE.."
MS2: "Really? What is it..?"
MS: "Apparently you can use it to take control of the user's PC.. like all the other security holes that exist.."
MS2: "Wow.. that's really bad.. What do we do?"
MS: "I've got it.. let's not do anything and release a statement telling people to either disable the software or buy Windows 7!"
MS2: "Brilliant!"
|
Would have been funny but Bill is no longer in Microsoft. Take a shot at Steve Ballmer instead.
|
|
|
Jul 07, 2009, 04:45 PM // 16:45
|
#10
|
Departed from Tyria
Join Date: May 2007
Guild: Clan Dethryche [dth]
Profession: R/
|
Firefox fulfills all my browser needs.
|
|
|
Jul 07, 2009, 05:33 PM // 17:33
|
#11
|
Desert Nomad
Join Date: Sep 2007
Profession: N/
|
Quote:
Originally Posted by miskav
Just don't use IE, like I've been saying for what... 3+years?
|
Who hasn't been saying this?
|
|
|
Jul 07, 2009, 05:47 PM // 17:47
|
#13
|
So Serious...
Join Date: Jan 2007
Location: London
Guild: Nerfs Are [WHAK]
Profession: E/
|
Quote:
Originally Posted by Inde
Okay, the reason this article is hilarious is this paragraph:
"Microsoft urged vulnerable users to disable the problematic part of its software, which can be done from Microsoft's Web site, while the company works on a "patch" — or software fix — for the problem."
So you have to either stop using Windows XP or Internet Explorer.
|
What Yahoo is saying (not you Inde) is not true, the exact words of MS are here (found via securityfocus): http://www.microsoft.com/technet/sec...ry/972890.mspx
It's a problem with the handling of one specific ActiveX control, which can be disabled due to how IE was reworked during the last few years (it's not entirely sure if this can always be done, but it's working so far), not with IE as a whole.
The main vector of attack seems to be emails, so caution when clicking links from suspicious emails should be used. Don't take for granted your understanding of security behaviour, spread the word around you.
Last edited by Fril Estelin; Jul 07, 2009 at 06:08 PM // 18:08..
|
|
|
Jul 07, 2009, 05:55 PM // 17:55
|
#14
|
Desert Nomad
Join Date: Jul 2008
Profession: A/W
|
rofl another advertisement for windows 7
|
|
|
Jul 07, 2009, 06:04 PM // 18:04
|
#15
|
Site Contributor
|
Quote:
Originally Posted by Fril Estelin
This is not true, the exact words of MS are here (found via securityfocus): http://www.microsoft.com/technet/sec...ry/972890.mspx
It's a problem with the handling of one specific ActiveX control, which can be disabled due to how IE was reworked during the last few years (it's not entirely sure if this can always be done, but it's working so far), not with IE as a whole.
The main vector of attack seems to be emails, so caution when clicking links from suspicious emails should be used. Don't take for granted your understanding of security behaviour, spread the word around you.
|
K Fril, I did say that.
Quote:
Originally Posted by Inde
I know it's the Video ActiveX controller that is the problem but for the thousands who just read that and don't have a clue... they're sitting there wondering what they should do.
|
|
|
|
Jul 07, 2009, 06:23 PM // 18:23
|
#16
|
Krytan Explorer
Join Date: Nov 2006
Location: PA, USA
Guild: [COPY]
Profession: D/
|
Quote:
Originally Posted by Roy Frogger
I loled...
But seriously...who uses IE anyway?
|
I'm on it right now. Personally, I hate Firefox
I'll use Opera from time-to-time
|
|
|
Jul 07, 2009, 06:25 PM // 18:25
|
#17
|
Krytan Explorer
Join Date: Mar 2009
Location: Pawn!
Guild: Who Are You [wAu]
Profession: W/Mo
|
Quote:
Originally Posted by vamp08
I'm on it right now. Personally, I hate Firefox
I'll use Opera from time-to-time
|
well google chrome ftw!
|
|
|
Jul 07, 2009, 09:31 PM // 21:31
|
#18
|
Jungle Guide
Join Date: Apr 2006
Profession: W/R
|
woohoo a bunch of computer will come my way to be fixed all the same ones ive told for 5 or 6 years not to us ie but still do.
|
|
|
Jul 07, 2009, 09:44 PM // 21:44
|
#19
|
Hell's Protector
Join Date: Aug 2005
Location: Canada
Guild: Brothers Disgruntled
|
Geez people, grab a clue. MS is not disabling IE (or WinXP), but simply a small part of IE that's used to play certain types of video. I'm not a big fan of MS or Windows, but I do try to keep it real.
|
|
|
Jul 07, 2009, 10:14 PM // 22:14
|
#20
|
Jungle Guide
Join Date: Apr 2006
Profession: W/R
|
Quote:
Originally Posted by Quaker
Geez people, grab a clue. MS is not disabling IE (or WinXP), but simply a small part of IE that's used to play certain types of video. I'm not a big fan of MS or Windows, but I do try to keep it real.
|
nobody said there were disabling ms or xp inde said a part of which states what you ended up saying over most of the other comments were about not using ie which has been a bad thing for years thats the big reason i have to fix so many computers over the years people using ie when it has vulnerabilities
|
|
|
Thread Tools |
|
Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT. The time now is 05:25 AM // 05:25.
|