This is topic Still Four More Microsoft Critical Flaws In Their Windows Software. in forum Film-Yak at Film-Tech Forum ARCHIVE.


To visit this topic, use this URL:
https://ft-forum.com/ft/cgi-bin/ubb/ultimatebb.cgi?ubb=get_topic;f=8;t=002604

Posted by Paul G. Thompson (Member # 655) on 10-15-2003, 07:03 PM:
 
This is so frustrating. From the Assiciated Press AP Technology Writer Ted Bridis.

WASHINGTON -- Microsoft Corp. warned consumers Wednesday about four critical new flaws in its popular Windows software as the company shifted to monthly alerts for serious problems that could let hackers break into computers.

In particularly embarrassing disclosures, Microsoft acknowledged problems in its technology to authenticate software publishers over the Web and in its Windows help and support system. Microsoft also announced a fifth, less serious Windows vulnerability.

The company said it did not believe hackers were yet exploiting any of the vulnerabilities it announced.

Microsoft said last week it will begin issuing monthly warnings and software patches, responding to frustration from technology managers who must apply sporadic patches each week across hundreds of computers inside corporations.

The company said it expects to release future warnings on the second Tuesday or Wednesday of each month. It has promised to rush out an emergency patch midmonth if it determines hackers are actively breaking into computers using a flaw it can repair immediately.

Separately, Microsoft began offering Windows XP users a single, convenient patch that combines 22 previous updates. It was aimed at customers who haven't diligently applied every software patch or who recently bought a new computer or recently installed Windows from scratch.

All four of the most dangerous new vulnerabilities affect versions of Windows 2000, which is commonly used by corporations and government agencies. Three of them also affect other Windows versions, including Microsoft's flagship Windows XP software, popular among home users, and Windows Server 2003 for businesses.

Microsoft shares rose 55 cents to close at $29.07 in Wednesday trading on the New York Stock Exchange.
 
Posted by Shane Hoffmann (Member # 1620) on 10-15-2003, 07:38 PM:
 
Come to the MAC side!!! [thumbsup]
 
Posted by Phil Hill (Member # 371) on 10-15-2003, 09:04 PM:
 
Oh boy....Shane. If you ***ONLY*** knew what you may have started here... [evil]

>>> Phil
 
Posted by Shane Hoffmann (Member # 1620) on 10-15-2003, 09:07 PM:
 
Don't worry, I went right ahead with it and made a new thread [thumbsup]
 
Posted by Daryl C. W. O'Shea (Member # 1303) on 10-15-2003, 11:52 PM:
 
Microsoft's not the only one patching holes in their operating system... they just get the most press. Oh well.

Their recent move to monthly updates, instead of weekly updates on Wednesday, is actually a good thing since nearly all exploits come on the heals of a patch or update, very rarely beforehand.

There will still be exploits written based on patches that Microsoft releases, but at least we'll only have to deal with them monthly, rather than weekly.

Further, with the upcoming release of SUS 2.0, administrators in the corporate environment should have it easier when deploying network wide system security policies and deploying relevant patches to uphold them.

Really though, what would you rather Microsoft do? They can't win no matter what they do. They could go back to the days of release an operating system and leaving it. They'd then be bashed for not supporting it / not fixing security issues with it. Or they can release more and more patches to fix the security issues and be bashed about the constant stream of security patches. They just can't win.

Here's where they're at fault though... combining the desktop OSes and the server OSes. This is the single reason why Microsoft server software vulnerabilities are on the rise (well that and its rising market share). It makes writing an exploit even more enticing... not only can you target the billion (or whatever) desktop OS users, you can also target the server OSes with little of no modifications to your exploit. But what can I say, combining the OSes DID bring a better OS to the desktop user.

The root of the problem... complacent or downright incompetent or un-qualified system administrators. Not unlike the advent of platters and automations which led to concession staff and ushers running projection booths, Microsoft has developed a server OS that has unfortunately led to the company's receptionist, or even idiot QC guy, running the company's server OSes.

Just wait, I guarantee that as Redhat and others make their server OSes more and more user friendly and graphically pretty, there will be more and more unqualified network administrators running Linux based networks (desktops, workstations and servers included) that are full of security holes which are exploited as much as Microsoft's OSes are today.
 
Posted by Phil Hill (Member # 371) on 10-16-2003, 12:00 AM:
 
quote:
...I guarantee that as Redhat and others make their server OSes...
Josh has an OS server? [thumbsup]

OBTW Shane, I don't "worry" about anything anymore... life's too short... [Big Grin]

>>> Phil
 
Posted by Gordon McLeod (Member # 33) on 10-16-2003, 09:04 AM:
 
Microsoft is a security threat [evil]
 




Powered by Infopop Corporation
UBB.classicTM 6.3.1.2