1. SPS Accounts:
    Do you find yourself coming back time after time? Do you appreciate the ongoing hard work to keep this community focused and successful in its mission? Please consider supporting us by upgrading to an SPS Account. Besides the warm and fuzzy feeling that comes from supporting a good cause, you'll also get a significant number of ever-expanding perks and benefits on the site and the forums. Click here to find out more.
    Dismiss Notice
Dismiss Notice
You are currently viewing Boards o' Magick as a guest, but you can register an account here. Registration is fast, easy and free. Once registered you will have access to search the forums, create and respond to threads, PM other members, upload screenshots and access many other features unavailable to guests.

BoM cultivates a friendly and welcoming atmosphere. We have been aiming for quality over quantity with our forums from their inception, and believe that this distinction is truly tangible and valued by our members. We'd love to have you join us today!

(If you have any problems with the registration process or your account login, please contact us. If you've forgotten your username or password, click here.)

New Windows exploit

Discussion in 'Techno-Magic' started by khaavern, Dec 29, 2005.

  1. khaavern Gems: 14/31
    Latest gem: Chrysoberyl


    Joined:
    Feb 7, 2004
    Messages:
    675
    Likes Received:
    0
    Apparently, there is a nasty new Windows vulnerability out there; more details can be found at this blog Security fix.

    This looks to be pretty ugly; if I understand correctly, it is enough to visit a web page to get infected; you don't need to actually download anything (if you use IE; if you use firefox, you can still get infected by actively downloading stuff). As a consequence, the malicious site can install keyloggers/rootkits on your computer (although it seems that what they install so far is only spyware/adware). There is no patch for this vulnerability (a potential workaround is mentioned on the page linked above, but is not clear that actually fixes everything). Probably the best defense for now is to exercise some care with your surfing ;)

    I thought I should give you guys a heads-up.
     
  2. Erod Gems: 14/31
    Latest gem: Chrysoberyl


    Veteran

    Joined:
    May 21, 2005
    Messages:
    652
    Likes Received:
    3
    True and there are already many web pages that exploit this vulnerability. Just need to be more careful until Microsoft will release a fix.
     
  3. JiggaJay Gems: 10/31
    Latest gem: Zircon


    Joined:
    Oct 17, 2005
    Messages:
    395
    Likes Received:
    0
    Oh crap... *looks at window with pr0n*

    I'm screwed...
     
  4. Harbourboy

    Harbourboy Take thy form from off my door! Veteran Pillars of Eternity SP Immortalizer (for helping immortalize Sorcerer's Place in the game!)

    Joined:
    May 29, 2003
    Messages:
    13,354
    Likes Received:
    99
    What's a "pr0n"? Sounds like gibberish "leet" talk to me.
     
  5. kuemper Gems: 31/31
    Latest gem: Rogue Stone


    Joined:
    Jun 19, 2005
    Messages:
    8,926
    Likes Received:
    8
    Porn, HB. Yes, it is.

    Hmm, it says XP is affected. Is it just XP or do I need to worry with my 2K? :hmm: Not that I d/l much, mostly surfing.
     
  6. Erod Gems: 14/31
    Latest gem: Chrysoberyl


    Veteran

    Joined:
    May 21, 2005
    Messages:
    652
    Likes Received:
    3
    The following OS's are affected:

    Windows 98 / 98 SE
    Windows ME
    Windows 2000 SP 4
    Windows XP (Original, SP1, SP2 and x64 Edition)
    Windows 2003 (Original, SP1, x64 Edition, Itanium)

    So that includes about every version of Windows that is in wide use. Also remember that with IE it is enough to just visit a malicious site.
     
  7. Sydax Gems: 19/31
    Latest gem: Aquamarine


    Joined:
    Apr 16, 2003
    Messages:
    1,166
    Likes Received:
    0
    I use Firefox and I have Zone Alarm that asks me everytime something wrong is trying to access my computer, so, ZA helps?
     
  8. Taza

    Taza Weird Modmaker Veteran

    Joined:
    Oct 23, 2002
    Messages:
    1,447
    Likes Received:
    25
    Firefox helps against this problem.

    ZoneAlarm doesn't. At all.

    Firefox doesn't automatically open the filetype that is used in this exploit. Downloading image files may still get you infected, though.

    EDIT: Note, the NEWEST Firefox helps. And not much.

    [ December 30, 2005, 13:08: Message edited by: Taza ]
     
  9. Morgoth

    Morgoth La lune ne garde aucune rancune Veteran

    Joined:
    Jul 21, 2002
    Messages:
    3,652
    Media:
    8
    Likes Received:
    86
    Gender:
    Male
    I temporarily removed the flawed dll which is supposed to handle the infected images, so I guess that makes me safe for this bug(I'm not really sure, so I don't dare to tell you how I did it, less I get you all infected), now just the other 3.243 x 10^12 bugs that Windows has..

    @Erod, every Windows version since 3.0 is affected :)
     
  10. Erod Gems: 14/31
    Latest gem: Chrysoberyl


    Veteran

    Joined:
    May 21, 2005
    Messages:
    652
    Likes Received:
    3
    Microsoft released the patch for this yesterday.
     
  11. Morgoth

    Morgoth La lune ne garde aucune rancune Veteran

    Joined:
    Jul 21, 2002
    Messages:
    3,652
    Media:
    8
    Likes Received:
    86
    Gender:
    Male
    Actually they released it tuesday, but AFAIK that is only for the XP and 2003 systems, not for anything older, and many companies still work with NT4 systems.

    Edit: Oops, I'm wrong again, they released it yesterday(thursday) instead of the originally planned tuesday. But still, only for XP and 2003.
     
  12. Erod Gems: 14/31
    Latest gem: Chrysoberyl


    Veteran

    Joined:
    May 21, 2005
    Messages:
    652
    Likes Received:
    3
    It was also released for Windows 2000.

    Apparently Windows 98/ME (no one should be using these anyway) will not get any official patches as they are so old that Microsoft will only release critical updates for them (if this is not critical then what is...?).
     
  13. Blackthorne TA

    Blackthorne TA Master in his Own Mind Staff Member ★ SPS Account Holder Adored Veteran Pillars of Eternity SP Immortalizer (for helping immortalize Sorcerer's Place in the game!) New Server Contributor [2012] (for helping Sorcerer's Place lease a new, more powerful server!) Torment: Tides of Numenera SP Immortalizer (for helping immortalize Sorcerer's Place in the game!)

    Joined:
    Oct 19, 2000
    Messages:
    10,414
    Media:
    40
    Likes Received:
    232
    Gender:
    Male
    Well, I'll be using Windows 98 until Vista comes out :)
     
  14. Ziad

    Ziad I speak in rebuses Veteran

    Joined:
    Aug 3, 2004
    Messages:
    4,088
    Media:
    57
    Likes Received:
    47
    Microsoft has ceased any and all support for anything pre-Win2000, including NT, 98 and ME. So, no update, regardless of how critical they are.

    But, Win98SE has its nice side :)
     
  15. Kitrax

    Kitrax Pantaloons are supposed to go where!?!?

    Joined:
    Apr 19, 2002
    Messages:
    7,899
    Media:
    74
    Likes Received:
    96
    Gender:
    Male
    BTA...I hope you have a high end computer to run Windows Vista. From what I've read, it's going to take a lot of RAM, CPU, and GPU power to run. :eek:

    Does anyone have the actual link to the patch. I haven't wasted my time with Windows Update for a long time, and there are just so many "critical updates" to sort through, finding the right one will take forever. :bang: :rolling:
     
  16. Blackthorne TA

    Blackthorne TA Master in his Own Mind Staff Member ★ SPS Account Holder Adored Veteran Pillars of Eternity SP Immortalizer (for helping immortalize Sorcerer's Place in the game!) New Server Contributor [2012] (for helping Sorcerer's Place lease a new, more powerful server!) Torment: Tides of Numenera SP Immortalizer (for helping immortalize Sorcerer's Place in the game!)

    Joined:
    Oct 19, 2000
    Messages:
    10,414
    Media:
    40
    Likes Received:
    232
    Gender:
    Male
    I plan to build a new computer next year when Vista and the new Conroe architecture from Intel are due...
     
Sorcerer's Place is a project run entirely by fans and for fans. Maintaining Sorcerer's Place and a stable environment for all our hosted sites requires a substantial amount of our time and funds on a regular basis, so please consider supporting us to keep the site up & running smoothly. Thank you!

Sorcerers.net is a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for sites to earn advertising fees by advertising and linking to products on amazon.com, amazon.ca and amazon.co.uk. Amazon and the Amazon logo are trademarks of Amazon.com, Inc. or its affiliates.