Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Report: Major Windows Security Update Foiled
ZDNet ^ | 1/28/05 | Robert Lemos

Posted on 01/28/2005 6:24:09 PM PST by 1LongTimeLurker

*

A Russian security company claims it found a way to beat a security measure in Microsoft's Windows XP Service Pack 2, a major update aimed at securing customers' PCs.

The SP2 measure, known as Data Execution Protection, is intended to prevent would-be attackers from inserting rogue code into a PC's memory and tricking Windows into running the program. However, in a paper published Friday, Moscow-based Positive Technologies said two minor mistakes in the implementation of the technology allow a knowledgeable programmer to sidestep the protection.

The company notified Microsoft of the problem Dec. 22, but it apparently decided not to wait for the software giant to patch the flaws.

Neither Microsoft nor Positive Technologies immediately responded to requests for comment Friday.

After several delays, Microsoft began rolling out SP2 in August of last year, at which time company Chairman Bill Gates called the update "a significant step in delivering on our goal to help customers make their PCs better isolated and more resilient in the face of increasingly sophisticated attacks."


TOPICS: News/Current Events
KEYWORDS: computersecurity; insecurity; windows
Navigation: use the links below to view more comments.
first 1-2021-33 next last
For those of you out there running Windows machines with SP2 be aware of this. Fixes for Windows security problems can be found here
1 posted on 01/28/2005 6:24:09 PM PST by 1LongTimeLurker
[ Post Reply | Private Reply | View Replies]

To: 1LongTimeLurker

Do you ever get the feeling that Microsoft doesn't know as much about it's own system and code than these hackers do? If they do know as much as the Hackers they have a serious quality control and supervisory problem. If they don't as much they need to hire these people to help them in securing their obviously porous software.


2 posted on 01/28/2005 6:29:11 PM PST by drt1
[ Post Reply | Private Reply | To 1 | View Replies]

To: 1LongTimeLurker

Maybe if Microsoft weren't so interested in having access to your computer themselves they could prevent others from doing the same thing.


3 posted on 01/28/2005 6:30:44 PM PST by FreePaul
[ Post Reply | Private Reply | To 1 | View Replies]

To: drt1

I haven't updated to SP2, i don't know if i will. I use good antivirus and firewall programs on my pc.

I'm waiting for microsoft to prove that they can have a patch that fixes all their problems before i bother installing Sps after Sps.


4 posted on 01/28/2005 6:31:31 PM PST by 1FASTGLOCK45
[ Post Reply | Private Reply | To 2 | View Replies]

To: 1FASTGLOCK45

I updated to the last fix and got all sorts of trouble so I had to uninstall. There is another one waiting for installation and I am reluctant to do it.


5 posted on 01/28/2005 6:34:36 PM PST by Bahbah
[ Post Reply | Private Reply | To 4 | View Replies]

To: 1FASTGLOCK45
If past is prologue methinks you will have a very long wait before you can install SP2. :-)
6 posted on 01/28/2005 6:35:20 PM PST by drt1
[ Post Reply | Private Reply | To 4 | View Replies]

To: 1LongTimeLurker

better call up bush2000 to defend his employer, bill gates.


7 posted on 01/28/2005 6:36:15 PM PST by ken21
[ Post Reply | Private Reply | To 1 | View Replies]

To: 1LongTimeLurker

Just run a program coded in .Net - DEP is not turned on for .Net programs at all.


8 posted on 01/28/2005 6:37:16 PM PST by ikka
[ Post Reply | Private Reply | To 1 | View Replies]

To: drt1

Total size of team programming SP2: SEVEN. Even figure they pay these guys a million a year and it took 2 years, that is a lousy $14 million. Meanwhile MS pulls in BILLIONS a year.


9 posted on 01/28/2005 6:39:08 PM PST by ikka
[ Post Reply | Private Reply | To 2 | View Replies]

To: Bahbah

That must be fustrating to have an installation not go through smoothly. That's the other reason i was hesistant to even try it because i heard there are issues and some programs don't work after SP2 being installed. I don't blame you for not doing it.


10 posted on 01/28/2005 6:39:35 PM PST by 1FASTGLOCK45
[ Post Reply | Private Reply | To 5 | View Replies]

To: drt1

Your right. LOL, i figured as much, computers will be reinvented before microsoft figures out they need to go back to basics. They have the ability to go back to basics and remake windows even better. it doesn't have to be fancy, all we want is good connectivity and program reliablity.


11 posted on 01/28/2005 6:41:03 PM PST by 1FASTGLOCK45
[ Post Reply | Private Reply | To 6 | View Replies]

To: FreePaul

I think you have hit the nail on the head.

Microsoft is like the monkey holding the datenut in the jug. Until the monkey lets go, it will never escape.

Microsoft is trying to keep its back doors open for its future pay every month or your computer will not work system.

Also there are more than enough easter eggs in the microsoft system for those interested in looking. I am sure SOMEBODY here has a few of them.


12 posted on 01/28/2005 6:41:28 PM PST by longtermmemmory (VOTE!)
[ Post Reply | Private Reply | To 3 | View Replies]

To: 1LongTimeLurker

My next machine will be either Linux based or a Mac, I'm tired of all the patches ,updates and BS that comes with a MS product.


13 posted on 01/28/2005 6:43:28 PM PST by blastdad51 (Proud father of an Enduring Freedom vet, and friend of a soldier lost in Afghanistan)
[ Post Reply | Private Reply | To 1 | View Replies]

To: 1FASTGLOCK45
That must be fustrating to have an installation not go through smoothly.

Especially if you are technologically challenged. I will say, however, that everything I have learned about computers I leaned here on FR. I read through all the threads on compter issues, understand maybe 1%, but still pick up tons of information. ;-)

14 posted on 01/28/2005 6:43:54 PM PST by Bahbah
[ Post Reply | Private Reply | To 10 | View Replies]

To: FreePaul
"Maybe if Microsoft weren't so interested in having access to your computer themselves they could prevent others from doing the same thing."

Exactamundo! These "Flaws", presented as inadvertent, unintentional bugs, are really back doors that were purposely engineered into the software for the benefit of MS and other Entities to use in tracking clients usage. IMO they deserve to have their A$$es sued off.

15 posted on 01/28/2005 6:44:03 PM PST by drt1
[ Post Reply | Private Reply | To 3 | View Replies]

To: 1LongTimeLurker

The problem with Bill Gates' "Conquer the World" strategy is that there is always another young protege in the wings preparing to take it from him.

Such are the liabilities and travails of being a Sith Lord.


16 posted on 01/28/2005 6:45:30 PM PST by Imal (Let us trim our hair in accordance with Socialist lifestyle.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: drt1

drt1 wrote:
Exactamundo! These "Flaws", presented as inadvertent, unintentional bugs, are really back doors that were purposely engineered into the software for the benefit of MS and other Entities to use in tracking clients usage. IMO they deserve to have their A$$es sued off.

* Bullseye, i think you hit the nail right on the head.


17 posted on 01/28/2005 6:46:46 PM PST by 1FASTGLOCK45
[ Post Reply | Private Reply | To 15 | View Replies]

To: Phsstpok

ping for later


18 posted on 01/28/2005 6:49:13 PM PST by Phsstpok ("When you don't know where you are, but you don't care, you're not lost, you're exploring.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: 1LongTimeLurker

As usual, there will be an update. I've never had a virus. I just update whenever there is one and use a hub with a firewall. No problem.


19 posted on 01/28/2005 6:51:00 PM PST by Poser (Joining Belly Girl in the Pajamahadeen)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ikka

I have a hard time believing MSFT only had 7 developers working a major upgrade to, by far, their most important product. Do you have a source for this or are you just some disgruntled Mac-geek talking trash? Seven managers maybe.


20 posted on 01/28/2005 6:52:53 PM PST by StockAyatollah
[ Post Reply | Private Reply | To 9 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-33 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson