Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Windows Update flaw 'left PCs open' to MSBlast

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU
 
Andy_Stephenson Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 11:39 AM
Original message
Windows Update flaw 'left PCs open' to MSBlast
flaw in Windows Update caused some organisations - including the US Army - to wrongly believe they were protected from MSBlast, according to a researcher

A flaw in Windows Update -- Microsoft's online tool that lets customers update their operating system with patches and fixes -- enabled the MSBlast worm to infect computers that apeared to have already been patched, according to a security expert.

The flaw led to a US Army server, among others, falling victim to MSBlast, according to Russ Cooper, chief scientist at security company TruSecure.

http://news.zdnet.co.uk/0,39020330,39115732,00.htm


Printer Friendly | Permalink |  | Top
curlyred Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 11:44 AM
Response to Original message
1. Microsoft sucks
This is outrageous......do everything "they" tell you to, and it STILL doesn't work?
Printer Friendly | Permalink |  | Top
 
AntiCoup2K4 Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 11:49 AM
Response to Original message
2. Looks like I picked a great time to move to Linux
Was thinking about Windows as a "backup" system, but maybe I'll just leave it off the machine altogether.
Printer Friendly | Permalink |  | Top
 
soup Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 12:05 PM
Response to Reply #2
3. You sure did, but please don't gloat.
I'm near tears of total frustration trying getting the sin of a botch off of my son's computer.
Got the repair from Norton, and the patch from Microsoft, and apparently, that didn't do it.
Did a system restore, and it's still there?!-
Now frantically trying to go through the steps for the manual stuff before the system shuts itself down in .59 - .58 -
Taking a break right now to calm myself down.

They're also warning that this was a crude and amateurish 'code' (is that the correct word?) and the clones will be much nastier.
Ah, something to look forward to.
Printer Friendly | Permalink |  | Top
 
TLM Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 01:41 PM
Response to Reply #3
9. Heh I had to reinstall my OS yesterday...

and I did not even get infected.

I was DLing the update from windows update and one of the DOS attacks hit in the middle of my download, my computer crashed and the partial update files tried to run and fucked up my whole OS.

Printer Friendly | Permalink |  | Top
 
soup Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 01:56 PM
Response to Reply #9
12. passing the kleenex.
sorry to hear that TLM. :-(

Hope everything is up and running fine, now.

My son is sitting on terminal 'switch and hold' with HP Support right now. We may end up having to do the same as you did.

apologies to all for side-tracking the thread.
Carry on.
Printer Friendly | Permalink |  | Top
 
denverbill Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 02:18 PM
Response to Reply #3
13. Dammit. There is a code you can enter to stop that countdown.
And I can't remember it right now. You go to start/run and type in something like 'shutdown -a' and it keeps your computer from shutting down in 60 seconds so you have time to apply the fix. Arrgh. Somebody here must know it.
Printer Friendly | Permalink |  | Top
 
slackmaster Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 12:08 PM
Response to Original message
4. Has anyone actually read the Windows license agreement?
If you have, please explain why you believe Microsoft has done anything wrong, legally speaking.
Printer Friendly | Permalink |  | Top
 
Andy_Stephenson Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 01:44 PM
Response to Reply #4
11. MS may not be "legally wrong"
But they are definately wrong.
Printer Friendly | Permalink |  | Top
 
sybylla Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 02:20 PM
Response to Reply #4
14. Legally Wrong?
I would call it bait and switch... or better yet, outright fraud. They continually sell these systems claiming, with each new OS that it is secure - "trust us." If average Joe Acme renting business space in your dying downtown tried to pass off a product that was safe, secure and reliable only to find out after purchasing it and using it that it wasn't, the FTC and any similar state and federal entities would fine them into bankruptcy.

MicroShaft has been given a free ride on a pack of lies for far too long.
Printer Friendly | Permalink |  | Top
 
slackmaster Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Aug-18-03 09:17 AM
Response to Reply #14
18. If you think you have been defrauded then sue Microsoft
Or get a class action suit going. All this talk but without accompanying legal action is just talk.
Printer Friendly | Permalink |  | Top
 
Terwilliger Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 12:10 PM
Response to Original message
5. as far as I know...
Win 98 and lower are not susceptible to this virus. Something about the NT nature of the later OSes?
Printer Friendly | Permalink |  | Top
 
alfredo Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 01:27 PM
Response to Reply #5
8. their distrust of the customer is part of the reason. They want access
to your drive to make sure you are not pirating anything of their software. Also, the 'good enough, get it to the market quick' mentality makes for bad products.
Printer Friendly | Permalink |  | Top
 
ArkDem Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 12:21 PM
Response to Original message
6. ANY operating system can be exploited. The reason
Microsoft gets nailed so often is percentage of people using Microsoft.
Printer Friendly | Permalink |  | Top
 
AndyTiedye Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 01:18 PM
Response to Reply #6
7. All OS's have Bugs, But MicroSquash has More Bugs than the Others
Printer Friendly | Permalink |  | Top
 
ArkDem Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 01:42 PM
Response to Reply #7
10. I guess thats why they have the huge market share.
.
Printer Friendly | Permalink |  | Top
 
sendero Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 02:41 PM
Response to Reply #6
15. that...
... is utter nonsense. Linux/Unix simply does not have all of the easily exploitable holes in security that MS does.

Sorry, I've used both for 18 years, I'm not buying it.

The problem with MS is that NT was written with little regard for security. It is very very hard to add security to a large piece of software, just as it is very very hard to add quality after the fact.

This particular hole is so stupid as to boggle the mind, essentially a wide open IP port.

MS is a great marketing company but don't be fooled, technically they are strictly bush league.
Printer Friendly | Permalink |  | Top
 
ArkDem Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Aug-18-03 08:24 AM
Response to Reply #15
16. I've been a Unix administrator since 1980
I think I know what I'm talking about.
Printer Friendly | Permalink |  | Top
 
Cronus Protagonist Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Aug-18-03 09:18 AM
Response to Reply #16
19. You do.
Printer Friendly | Permalink |  | Top
 
Desperadoe Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Aug-18-03 09:11 AM
Response to Original message
17. Of My 8 Computers
Only one was infected. The one that my daughter has that hadn't had the patch from WU in July. This was her fault for being careless but it was easily repaired because I knew what it was immeadiatly and I knew how to remove it.

All the others were protected with the original patch that MS issued back in July. The people that were infected were to blame for their own stupidity and carelessness. The security patches for XP are free and available from WU. Good virus protection from various sources is an absolute must in today's environment. Regular maintenance is the responsiblity of the owner/user and not MS's.

I have my share of differences with Microsoft and I will not defend them when they are to blame but, in this instance, it is the irresponsiblilty of the computer owners/ users/ IT managers that has all the blame. There is no excuse for laziness or carlessness on the part of users and owners and IT techs and managers in todays internet environment.
Printer Friendly | Permalink |  | Top
 
slackmaster Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Aug-18-03 09:18 AM
Response to Reply #17
20. Of the nearly 100 Windows machines I'm responsible for...
ZERO got infected.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri Dec 27th 2024, 06:29 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC