Are you secure? Check again.

Status
Not open for further replies.

Osiris

Golden Master
Messages
36,817
Location
Kentucky
Are you secure? Check again.
Microsoft is scrambling to stomp a new armada of nasties, including a killer flaw in XP/Vista that exposes your innards to miscreants by simply going online. The plot stinks: a hacker simply broadcasts rogue TC/IP packets to a stream of addresses (including yours). That's the usual modus operandi, but it goes a step further. These rogue packets then ventures on to trick their way into your Windows core and hijack your PC, transforming it into a mindless zombie for a gargantuan botnet. Before you know it, your innocent PC is churning out spam to viagra sites. Or manufacturing self-replicating worms. ****.
According to news I've read, one programmer demonstrated the proof-of-concept at a community college on a fully patched XP system. Defenses crumbled in a flash. Scary?
Don't fret. Windows already has a patch to address this solution. If you value your security, I suggest you grab it now:

VISTA DOWNLOAD:
http://www.microsoft.com/downloads/details.aspx?FamilyID=23c0e03a-db66-4618-bce0-af55e5c1b067&displaylang=enhttp://www.microsoft.com/technet/security/bulletin/ms08-001.mspx
XP DOWNLOAD:
http://www.microsoft.com/downloads/details.aspx?FamilyID=0a766242-2342-4fa0-9b66-8953c54a2211
Here's a snippet of Microsoft warning:
Executive Summary

This critical security update resolves two privately reported vulnerabilities in Transmission Control Protocol/Internet Protocol (TCP/IP) processing. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
This is a critical security update for all supported editions of Windows XP and Windows Vista, an important security update for all supported editions of Windows Server 2003, and a moderate security update for all supported editions of Microsoft Windows 2000. For more information, see the subsection, Affected and Non-Affected Software, in this section.
This security update addresses the vulnerability by modifying the way that the Windows kernel processes TCP/IP structures that contain multicast and ICMP requests. For more information about the vulnerability, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information.
Recommendation. Microsoft recommends that customers apply the update immediately.

Warning: Rouge Packets About To Pounce You! | Connected Internet

 
It is currently affecting only some systems. If your update client hasn't detected it (after running a check for updates also) chances are it dosen't apply to you.

Best pratice though to download the fix anyway to be on the safe side. The installer will just tell you it dosent apply if you don't need it.

Cheers,

~ Tkey
 
Hello,

I jsut tried it and the update doesnt apply to any system running SP3 on XP. Will check Vista later.

Cheers,
Mak
 
I have Vista SP1, diddn't apply to me either ;)

Best to download the patch if you haven't already though guys. It's not going to do and harm if it dosent ;)

Cheers,

~ Tkey
 
If it doesn't apply to any machine running xp sp3 then how did it get into a college xp network that was fully patched? If it was fully patched it would have had sp3..
 
If it doesn't apply to any machine running xp sp3 then how did it get into a college xp network that was fully patched? If it was fully patched it would have had sp3..

That shows me that they are not running XP SP3. Go start>run>winver to see what SP they are running. If this patch was applied then they do not have SP3. I have tested this on several machines already.;)
 
Ah yes, this patch is only appliciable to Service Pack 2 and before XP users Naphtali14. You will find this located in the "System Requirements" section on the Microsoft Download page.

supported_os.png


Cheers,

~ Tkey
 
Status
Not open for further replies.
Back
Top Bottom