Microsoft fixes '19-year-old' bug with emergency patch
bbc.com
bbc.com
I'm confused... The article says this research relates to the SChannel vulnerability being patched this month and cites IBM Researchers[1] finding it, but the link to the blog post showing the work is towards OLE and not SChannel. Also, Microsoft has mentioned that they found[2] the SChannel vulnerability through an internal audit. To me, it seems the research is talking about CVE-2014-6332[3], which shows the patch as MS14-064. MS14-066 is the patch for the SChannel vulnerability.
Either BBC is confused on which patch they're trying to report on, or I am.
Anyone similarly confused as I am?
[1] http://securityintelligence.com/ibm-x-force-researcher-finds...
[2] http://blogs.technet.com/b/srd/archive/2014/11/11/assessing-...
[3] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-633...
Does it happen only when activeX is enable?
"In computer security, a drive-by attack typically means making users download malicious software."
That's really not clear. It means that you'll get infected by simply passing by [a website] rather than actively doing anything.
A 'drive-by-download' attack is a malware delivery technique that is triggered simply because the user visited a website. Traditionally, malware was only 'activated' as a result of the user proactively opening an infected file (for example, opening an email attachment or double clicking on an executable that had been downloaded from the Internet).
Source: https://www.comodo.com/resources/home/newsletters/nov-10/ask...
https://technet.microsoft.com/library/security/MS14-066
https://technet.microsoft.com/library/security/ms14-064
Full list of updates: https://technet.microsoft.com/library/security/ms14-nov
Of significant importance too are the Flash Player updates released: http://helpx.adobe.com/security/products/flash-player/apsb14...
Another long-lived bug that someone finally managed to discover and exploit.
I wonder if it's related to this one 4 years ago: http://www.cvedetails.com/cve/CVE-2010-2566/
When the Blaster worm hit in 2003, the Unix people laughed, because they were immune. The Morris worm was ancient history, because it had been 15 years since that hit.
XP is almost ancient history. You shouldn't be running it, any more than you should've been running something vulnerable to the Morris worm in 2003.
edit 'omh makes a good point below
I also know of people running XP because it's incredibly stable now and they don't see anything in newer versions of Windows they really want or need.
It's big, but it's not that big, fifth or sixth largest employer in the world according to Wikipedia:
http://en.wikipedia.org/wiki/List_of_largest_employers#Large...
Plus DoD is several branches so that's a bit of a push.
Maybe they should standardise on a particular UI for specific applications - maybe with desktop icons in specific locations for launching those apps. Then they remove the OS from user view entirely - any OS or version of an OS that will present the particular applications with the required views would then be appropriate.
That way when determining if they can upgrade to Windows 10 they just need to ask "will our current apps run, with largely coterminous views and function? Can the OS login direct to our launch icon layout?".
Most users use applications rather than OS, especially in a work setting I'd warrant.
They don't need security updates? Aren't they connected to the internet?
I am currently creating an application that has "runs on Windows XP" as part of the requirements list.
XP was the newest possible version of Windows as recently as 2007, and since most people ignored Vista it was the default install for many (most?) people up until Windows 7, which was only 5 years ago. SP3 came out in 2008 and significantly improved the features and security.
Combined with some odd licenses and old PC stock in stores there were plenty of people buying new laptops in 2010 with XP installed.
Yes, it's old. But more like 5-6 years than 13.
Of course they are under no obligation to.
And some might argue that giving people updates so they can continue to use IE6 is as bad as giving an alcoholic a double G&T to help keep withdrawal symptoms at bay...
Anyone who is still running Windows XP has this coming.
(Technical details: If the client offer one of the suites, the server is accepting it in the ServerHello, but then RSTing the connection after the client sends their encrypted handshake, and the event log says "none of the cipher suites supported by the client application are supported by the server". Browser and curl don't use that suite, but Amazon ELB does.)
I was able to fix this by reconfiguring the available cipher suites within IIS. Downloaded the IIS Crypto tool https://www.nartac.com/Products/IISCrypto/Default.aspx and applied their "Best Practices" which removed a bunch of insecure ciphers. After that the AWS ELB and IIS happily communicated.
redim preserve arrayname( newsizeinelements ) ... For VBScript, exploitation of this bug could have been avoided by invalidating the common “On Error Resume Next” VBScript code when the OleAut32 library returns with an error."
Always thought there was something shady about VB and redimming -- and On Error Resume Next. ;^) But that explains why it's as old as VB itself.