Worm hole found in Windows 2000

mubs

Storage? I am Storage!
Joined
Nov 22, 2002
Messages
4,908
Location
Somewhere in time.
News.com

A serious flaw has been discovered in a core component of Windows 2000, with no possible work-around until it gets fixed, a security company said.

The vulnerability in Microsoft's operating system could enable remote intruders to enter a PC via its Internet Protocol address, Marc Maiffret, chief hacking officer at eEye Digital Security, said on Wednesday. As no action on the part of the computer user is required, the flaw could easily be exploited to create a worm attack, he noted.

What may be particularly problematic with this unpatched security hole is that a work-around is unlikely, he said.

"You can't turn this (vulnerable) component off," Maiffret said. "It's always on. You can't disable it. You can't uninstall."

<snip>

The vulnerabilities affect Windows 2000, but Maiffret noted eEye is still conducting tests, and he anticipates other versions of Microsoft's OS will likely be affected.

<snip>
 

tazwegion

Learning Storage Performance
Joined
Jul 29, 2005
Messages
207
Location
Victoria, Australia
No wonder MicroSoft hate all other forms of OS... it makes them feel even MORE inferior LMAO :lol:

Seriously you'd have to think that a company with the resources they have... could manage to create a reliable, dependable & secure product :roll:
 

CougTek

Hairy Aussie
Joined
Jan 21, 2002
Messages
8,728
Location
Québec, Québec
tazwegion said:
Seriously you'd have to think that a company with the resources they have... could manage to create a reliable, dependable & secure product.
They don't want to : that's how they make money. If they ship something which would be close to flawless, how could they taunt people to upgrade to something else later? They are still having misery to make a large portion of their customers update their Win98 operating system!
 

tazwegion

Learning Storage Performance
Joined
Jul 29, 2005
Messages
207
Location
Victoria, Australia
Yeah... I'm one of them :roll: seriously though, the only reason I got Win 2K pro & XP pro was because despite Abit claiming 98SE support for the Nf7-s, in reality it was easier to get a newer OS ;)

All of my distributed computing systems use 98SE (lite) and for humourous reasons the desktop image claims to be 50% MicroSoft free! :lol:
 

Fushigi

Storage Is My Life
Joined
Jan 23, 2002
Messages
2,890
Location
Illinois, USA
As long as you NAT and have a decent firewall, it would appear the only real threat would be from those who already have access to your LAN. Otherwise, they can't route to your PC as your IP address is hidden, and even if guessed, can't be routed to..

And you can work around it by disabling the TCP stack. Pretty severe considering how much we rely on it, but to say it can't be avoided is false. Too bad SNA is dying. :lol:
 
Top