Added on 24 Oct 2008(853 Views)
In an article posted the other day, we were announcing the fact that Microsoft will break the Update Tuesday cycle in order to address the MS08-067 security issue which affects several Windows-based operating systems. Now that the fix has been released and the users have patched their systems, it is time to see what all the fuss was about.Bas Alberts from Immunity Security says that the flaw refers to the manner in which Windows Server handles RPC requests. If an attacker chooses to send malicious messages to a system running on Windows OS, the security flaws within Windows Server could allow that attacker to gain control of the machine. Do you know how much time it took Immunity Security researchers to come up with an exploit code? Just 120 minutes from the time the patch was released. They did not need any specific details; the clues within the patch were enough.
Two things must be noted. The first one is that due to the nature of the flaw (RPC request), no user interaction is required in exploiting it. Secondly, the MS08-067 flaw which dates back to Windows NT also affects the brand spanking new Windows 7 (the Beta version of it). It does not affect it as badly as it would XP for example, but it does affect it, which for some is a worrisome matter.
This is what computer security specialist Dave Aitel has to say on the matter: “What a great bug! I'm not going to spoil the fun for people still working on it, but it's very cute, like a new puppy, or an angry toddler!” Now isn’t that a plastic description that will put things in perspective. The main question is this: How come it took Microsoft so long to find this bug? Was it that well hidden, or where they simply not looking?
Don't forget to:
RSSTags: Windows, Microsoft, Windows Vista, Windows Update
Link to this article:
Add comment:
Software News
Chromium OS Goes Open-Source
This summer Google let the world know that it is working on a new operating system meant for the user that spends most of his time online. The operating system – aptly named Chrome OS because it is a natural extension...
20 Nov 2009
Office 2010 Beta Downloads Available to the Public
Earlier this week Redmond-based software giant Microsoft announced that Office 2010 became available for download as a Beta. The catch was that only ...
20 Nov 2009
Mozilla Releases: Firefox 3.6 Beta 3
The development process of the Firefox 3.6 browser is moving along rapidly. The first Beta version was released at the start of the month; Beta 2 was released about two weeks after Beta 1. About a week has passed since...
20 Nov 2009
New Labs Feature for Gmail: Green Robot!
The software developers at Google have announced the release of a new Gmail Labs offering called Green Robot! This new offering is meant to improve the Gmail Chat user experience by letting the ...
20 Nov 2009
Opera Mobile 10 Beta for Windows Mobile Is Out Also
Opera Software, the company that we all know for making the innovative and feature rich Opera web browser, has released Opera Mobile 10 Beta for Windows Mobile-powered devices. This release follows in the...
19 Nov 2009
Beta Testing is Over, Stable Version of Trillian for iPhone Released
The focus so far has been on desktop version of this multiprotocol instant messaging software application, Trillian Astra (version 4.1). Today is time to switch focus away from the desktop version and onto something a bit more...
19 Nov 2009
Recommended Tools
Registry Booster 2010 Enhanced, deeper and faster error scan performance. Now also in 5 languages! Free Scan
Driver Scanner 2009
Fast and easy, it boosts performance by scanning for, downloading & installing driver updates
Fast and easy, it boosts performance by scanning for, downloading & installing driver updates
SpeedUpMyPC 2009
How fast is your PC really running? Turbo-charge your Internet and PC performance here
How fast is your PC really running? Turbo-charge your Internet and PC performance here



