Exploits Surface for Windows Flaws
By Ed Oswald | Published August 12, 2005, 3:27 PM
Hackers have been working overtime since Tuesday's disclosure by Microsoft of three critical holes in the Windows operating system. Less than 48 hours after the release of patches for the vulnerabilities, new exploit code turned up for at least two of the flaws.
Microsoft confirmed that code was now public to exploit the vulnerabilities within plug and play technology, and code was also circulating to exploit the Internet Explorer flaws as well. "Microsoft is disappointed that certain security researchers have breached the commonly accepted industry practice of withholding vulnerability data so close to update release and have published exploit code, potentially harming computer users," a company spokesperson said in a statement.
Thank Microsoft Windows Genuine Advantage for this worm. Honestly, I blame Microsoft for this worm, not even the exploit code, simply the reason a worm was created was due to the patch you have to run to prove you have a legit copy of Windows beforing getting updates. Think about it, 2 days after Windows update a worm comes out, targeting vulnurable machines, however this time the only vulnurable people are:
1) Retards who don't run Windows Updates.
2) Pirates.
To me this pathetic worm is nothing more than a warning message from MS. You either buy Windows or you can be infected.
If my crazy theory was right, I would say good job, sounds like a nice idea to get the pirates to go legit, or atleast join the Windows Genuine Advantage.
My point is I feel this worm was created so fast after the updates because of the new twist to Windows Updates this time around. This time the process was different, thus preventing the avg. person from continuing with Updates.
Who know, who cares...regardless this is an eye opener for many.
Score: 0
|Do your research before you start playing the blame game.
I'm getting tired of reminding people about this. Maybe the caps will help you see it better:
CRITICAL UPDATES WILL ALWAYS WORK.
It doesn't matter if your version of Windows is pirated, or if you simply choose not to do WGA. Critical updates are always available. In fact, their almost force-fed now through automatic updates.
Now stop lying, and have a great day.
Score: 0
|Ready to get a free copy a Windows Vista for aaaaall the trouble.
Score: 0
|This is news?
Score: 0
|I make an awsum Cherry Cheese Cake!
Score: 0
|yeah MS policy is to kill the ones who tell you about windows being unsafe (exploitable when new exploits are found)
Score: 0
|Yup. I'm an MS-bounty-hunter. I've sniped many traitors who gave away information about exploits.
It's always more challenging when they see me first, cuz then they start running, and it makes it so much more fun.
Score: 0
|LOL Nice image. :-)
Score: 0
|I see the microsoft PR is at it again. Where's microsoft's monkey boy Ballmer at times like these, repeatedly shouting one word while running around in circles on stage till he's pooped. next word he could use is debug.
Score: 0
|You know, Microsoft is lucky. We all bash MS for such crappy code to begin with but think about it.
They have the best testing program any company could hope for. An entire planet of hackers trying weed out and find every hole. That's actually great. They don't have to pay these guys a dime to get all this testing. The hackers are doing MS a HUGE favor and benefit, not hurting them.
And in another 10 years maybe Windows will finally be this block of concrete so tight and secure not even god himself could find an exploit.
Score: 0
|Titanic
Score: 0
|Lets see, windows xp has been out for how many years now, Four right. Well in four years and 2 service packs Microsoft Still releases patches for patches every single month. I just don't understand what they do with the billions a quater they make. Just to buy out another company I guess, so they can look like they are doing something productive with it. It really is insulting how much they charge simply because they are a monopoly. If linux had the money and backing Windows does, well that would be the end of microsoft as a leader in anything. Without their cash cow products they would be living off that the billions in stash collecting interest in the bank.
Score: 0
|Linux is nothing but a joke...Period.
Score: 0
|Dude. Windows isn't that expensive. When you consider how many devices and software environments it supports, $100 isn't that much. Mac OSX, on the other hand, will cost you $200, and it only supports Mac hardware.
"Well in four years and 2 service packs Microsoft Still releases patches for patches every single month. I just don't understand what they do with the billions a quater they make."
You answered your own question. They spend the billions they make on development of the patches they provide for FREE a full 4 years after the product was released. Show me another software company that does that for free. I dare you.
At least try to be rational in your hate for MS. I don't mind people that don't like MS as long as their logic is reasonable.
Score: 0
|So what you're really saying is that you're just ticked off that Microsoft has all this money to pay their employees and stock-holders and do all sorts of "cool things" that you think Linux *might* do if they had that money instead.
Let me fill you in on a little secret... if Linux had all the support and money that Microsoft has, it would suffer the exact same criticism Microsoft does, and all the Microsoft "lovers" (myself included) would be whining about how it's not fair Microsoft can't impress the right people to gain a realistic foothold like Linux can.
Score: 0
|Which Windows are you talking about? The OEM version of XP Pro is 269AUD here. The retail is nigh-on 400AUD, from memory. From the Apple website, its 199AUD for Tiger, and 299AUD gets you a site license for 5 home PCs.
Yeah, XP is REAL cheap. :P
Score: 0
|Yes, there is ups and downs for both Linux, Mac, and Windows... your vague comment is ignorance!
Try telling that to your ISP, and your webhost, chances are much higher that they are using linux/unix for their servers. Also tell that to casinos, chances are they have a couple unix servers too, of course, a windows server too.
yeah, it might not be as great for a home workstation for the average user.
Also, say, for a childrens computer, it is very hard for them to destroy linux like they can windows, plus Linux can come with 40 + free games.
Score: 0
|"They spend the billions they make on development of the patches they provide for FREE a full 4 years after the product was released. Show me another software company that does that for free."
Well, I don't know about spending billions of dollars, but how about "the development of the patches they provide for FREE" forever, on top of being free (other than time and internet, ofcourse) to obtain:
http://www.mozilla.org/
http://www.gimp.org/
http://www.openoffice.org/
http://gaim.sourceforge.net/
http://www.apache.org/
http://www.vorbis.com/
is that enough? I could go on...
http://www.skype.com/
http://www.kde.org/
http://filezilla.sourceforge.net/
........
Score: 0
|No, dude. Mac OS X sells for $129 retail and you can even find if from places like macwarehouse.com or macsales.com for $99. It's never been higher that $129.
Windows XP Pro on the other hand costs $209 on sites like newegg for a full retail version and you get get an OEM version for $146.
Yeah you have to get a mac to use the mac software and OS but it goes the same if mac users want to use PC software by using a PC. Or I can just get Virtual PC to run the software (except for games).
Score: 0
|"$129 retail" Is for the single-user version. The multi-user version (which Windows XP is by default) is $200. I didn't just pick a number and post it.
As far as XP Pro being $209, that's a ripoff. It doesn't take much looking to find copies for sub-$100 prices, and yes, they are legal (not from those e-mails that say CH34p3st! OEM S0ftw4r3s!!)
"Yeah you have to get a mac to use the mac software and OS but it goes the same if mac users want to use PC software by using a PC."
That's totally different. Macintosh will only let their software run on THEIR hardware. Windows doesn't have any hardware except for mice and keyboards and other miscellaneous peripherals. They let you use any PC hardware out there, and it's *almost* definitely supported.
"Or I can just get Virtual PC to run the software (except for games)."
So... you can spend more money on extra software that emulates an operating environment so that you can use "Virtual" Windows software? Wouldn't it just be a lot easier to buy a PC (for a lot less), buy Windows (again less), and run the programs in their native environment?
Score: 0
|You're funny. Try listing a company that SELLS the original product. Open-source doesn't count.
Score: 0
|Yeah. I work with three different distros of Linux on about 8 different servers at the ISP I work for.
Score: 0
|So which is better: Having your MS operating system invalidated when you upgrade your processor and memory or switch motherboards, or not being able to upgrade your processor or motherboard? I think MS just shot a big hole in the generally accepted ease of upgradability of Wintel machines!
Score: 0
|OK let me point something out. I just bought a new CPU and motherboard. I did a repair to remove all my old drivers and had to reactivate. No biggy. I then bought a new hard drive and had to reactivate, again no biggy. I have reformatted after making sure that my beta was over and had to reactivate I just formatted again for a new beta that I am doing and MS still has not had a problem with my activation. Now I didn't list every time here but in all told it have been at least 10 times. Most from hardware upgrades that I have activated this copy of XP Pro never had a problem. I use ghost but when you update hardware you still have to reactivate.
Score: 0
|what's your point? That MS isn't ONLY about the money?
musicmatch.com - $20 for the program plus one-time payment of $40 to get "all future versions"
I'm not insterested in searching for pay-for programs, and you are mostly right, as far as that goes, payware usually doesn't provide free updates, but i would think that if there was a security hole in their programs, they would fix and provide for free, just as MS does. I would consider a free update being from windows 98 to windows xp
Score: 0
|You sir, have no idea what you're talking about.
Score: 0
|"what's your point? That MS isn't ONLY about the money?"
That's exactly my point. Thanks for seeing it =)
"are mostly right, as far as that goes, payware usually doesn't provide free updates"
Well thanks.
"I would consider a free update being from windows 98 to windows xp"
If they did that, there wouldn't be anymore MS... which may or may not be a bad scenario.
Score: 0
|Just another whiner who won't or can't survive the learning curve to become proficient with a different system. Linux works and works well, if you're willing to learn to use it.
Score: 0
|Actually, I can think of quite a few companies that provide free updates for bought programs - Corel, Novell, Apple are a few examples. Also, if MS is spending billions on security patches, they're overpaying for them.
Score: 0
|it's not just abt a free firewall or a free anti virus ... it abt f*#@ing underlying system it self .... microsoft has be threatened so many times ( to no avail as we all know ) legally & via hate mail ( atleast i send it ;) ) abt not beta testing their products properly ...
every time a new s/w is announced .. a quarter of the features r droped or 'will be developed at a later date' n it creates a hole bigger than width of grand canyon.....
solution to this prob is proper beta testing ... n like every other company in mainland us .. microsoft also outsources this to it's 'testing partners' ... who as we all know r doin a very gud job ...
it's abt time that beta releases like community previews etc must be released to general public also ...
atleast we will know wht contraption we r goin to handle ...
Score: 0
|That has absolutely nothing to do with this article.
...?
Score: 0
|I agree with you 100 percent. Too bad microsoft doesn't spend a few more billion on research and development or at just dump their swiss cheese ie, and os altogether. I mean I can't believe all this is possible and these hackers, crackers and worm writers don't even have the source code for Windows. Imagine what would happen then the world would not be safe, period. With over 90 percent of every computer running windows, its all over man, all over.
Score: 0
|Fine hate MS and whatever else you want to hate, but be realistic here. MS is hacked so often: 1) MS makes their product really user friendly;
2) MS adds great features the makes using their product easier and more productive in a world where most people don't even know how to back their car up without hitting something.;
3) They make Windows to help millions of people not to cater to MS haters.
Score: 0
|Seriously.... you sound like you have no idea what you are talking about.
Have you ever programmed?
Anything?
Score: 0
|Everyone just stop complaining. Get a free firewall like zonealarem, get a free antivirus like avast or avg and use an alternative browser like Opera, Netscape, FireFox, until IE7 is released and dont download stupid $h*t and install it.
Score: 0
|Know what would be news, a headline that reads,
"Microsoft Windows Operating Environment revealed no new holes today"
Like someone else said about this "news" Same old song and dance since windows 3.0.
No OS is perfect but I am getting so tired of hearing on one hand, microsoft whining because someone found some OTHER back door MS intentionally left in windows and on the other hand people whining about when will they get it right.
Looking UPWARDS at the title bar I thought the name of this website was "BETA NEWS" meaning news about betas, not about already released software and other non-beta related news. if I wanted THAT news there are tons of outlets for it. How about sticking to betas, ya know, what this site is SUPPOSED to be about?
Score: 0
|I'm sure that they appreciate you dictating to them what their news website is about!
Score: 0
|Also, before you start spreading FUD about MS intentionally "leaving holes in their OS", please post the evidence you have to support these claims. I seriously doubt, in this day and age, that a software vendor would purposely put a hole in their software. Yes, there might be holes that have been open for a while, but I am almost positive they are working to patch their software. As said before by many users, until the day comes where you write an OS (or any piece of software that does some considerable function for that matter), and get it used by millions of users, and then see what bugs arise, dont start whining because a piece of software isnt perfect.
Also, read the TOS for betanews, its spelled out clearly in their liability disclaimer
"IF YOU ARE DISSATISFIED WITH THIS WEB SITE, OR ANY PORTION THEREOF, YOUR EXCLUSIVE REMEDY SHALL BE TO CEASE USING THE WEB SITE."
I suggest you follow it if you are so unhappy with the news being posted here ;-)
Score: 0
|That's awesome. I'm going to remember that quote from the TOS.
Score: 0
|Has it ever occured to you MS windows IS beta software?
Is their software just that bad, or is it so great that people make it look bad? Just some food for thought on that note. Its been over 4 years sense windows xp was released, may as well have been in beta and we are all the testers paying hundreds of dollars per copy.
Score: 0
|OMFG, like are you all drunk, The exploits came about because someone released the code that explained the flaws, as a result someone decided it was fun to use that info to attack the countless ignorent who don't update their OS.
Yet you still blame MS.
Why don't you write an OS that is perfect and has no security hole or simply shut up.
Score: 0
|Agreed :)
Score: 0
|Go mooose go!
Score: 0
|if someone else found the code it would be the same thing.
Score: 0
|INDEED!
Score: 0
|Wow what a supprise. At least this time the patches didn't break something else though....they just were useless.
Score: 0
|"Exploits surface for Windows Flaws"
Same damn headline I've seen every week since Windows 3.0.
Big friggin' deal. Must be a slow news day.
Score: 0
|Cue the ignorant haters.
Score: 0
|how about you do it right the first time MS. Looks like you're half assing it so stop whining and start getting the job done the first time.
Score: 0
|You obviously did your research. Thank you for that informed opinion.
/sarcasm
Score: 0
|Four down and two to go!
Score: 0
|As #1 said all you complainers should try writimg kernel code to address 2GB of RAM and support every sh1tty driver\device\app out there. When you finally finish, sell it to a million people and see how many bugs are found.
Score: 0
|With no one to force MS to patch up their code ... they would never do it by themselves.
Score: 0
|umm... they want to make a profit? Of course they would still patch by themselves. If they want people to buy their OS in the future, they're going to make sure that the OS's their prospective customers currently have stay working.
Score: 0
|I suppose if by "force" you mean wrote viruses and worms and the like... then the following would be true----
With no one to force MS to patch up their code ... they would never NEED to do it by themselves.
Score: 0
|geez some of you guys sound like linux fanboyz and whatnot. like you to try and make a peace of software that you think is not full of holes when billions of people are trying to look for holes in it. I mean, get out of your parents dark basements and get some sun.
Score: 0
|