LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Non-*NIX Forums > General
User Name
Password
General This forum is for non-technical general discussion which can include both Linux and non-Linux topics. Have fun!

Notices


Reply
  Search this Thread
Old 12-25-2001, 10:13 PM   #1
anoop_chandran
Member
 
Registered: Nov 2001
Distribution: Redhat 7.0 ,mandrake 8.0 ,Redhat 7.2
Posts: 99

Rep: Reputation: 15
UPnP vulnerability in XP


Microsoft Corp. said its new Windows XP operating system, which it had touted as a "secure and private" computing experience, has an unprecedented flaw.

In a security bulletin issued to customers yesterday, Microsoft said the "serious vulnerability" could allow hackers to commandeer all the computers in a neighborhood or company in a single attack

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS01-059.asp

happy patching winDOZZZ
bye

Last edited by anoop_chandran; 12-25-2001 at 10:17 PM.
 
Old 12-26-2001, 07:16 AM   #2
Aussie
Senior Member
 
Registered: Sep 2001
Location: Brisvegas, Antipodes
Distribution: Slackware
Posts: 4,590

Rep: Reputation: 58
windows is a security hole....and this latest one has been around since win98.
 
Old 12-26-2001, 11:58 AM   #3
FuriousGnu
LQ Newbie
 
Registered: Dec 2001
Location: Canada
Distribution: Red Hat 7.2
Posts: 25

Rep: Reputation: 15
I actually used XP a little bit before I installed Linux because I found it more stable than Win ME. I did that security update thing for XP last week and I found it a bit annoying. It MADE me use IE (even though Netscape is my default browser), and then it forced me to turn on all kinds of ActiveX stuff just to download the patches.

Oh well, I haven't booted XP since.
 
Old 01-03-2002, 12:51 AM   #4
Half_Elf
LQ Guru
 
Registered: Sep 2001
Location: Montreal, Canada
Distribution: Slackware; Debian; Gentoo...
Posts: 2,163

Rep: Reputation: 46
Lol
Microgoat sucks my friend lol.

They (try to) teach me Win2k at school (well if you need windows its a good system if you know how to secure it... if you do not... it's a fu**ing hole). But its funny, all holes/exploit I found in 2k also work in XP.
So well xp is maybe a not too bad system but you will need to FIX IT lol
 
Old 01-03-2002, 11:30 PM   #5
FuriousGnu
LQ Newbie
 
Registered: Dec 2001
Location: Canada
Distribution: Red Hat 7.2
Posts: 25

Rep: Reputation: 15
I have no intention of letting it connect to the Internet anymore - I wouldn't trust it as far as I could throw it.
 
Old 01-04-2002, 12:40 AM   #6
anoop_chandran
Member
 
Registered: Nov 2001
Distribution: Redhat 7.0 ,mandrake 8.0 ,Redhat 7.2
Posts: 99

Original Poster
Rep: Reputation: 15
do u guys know of the con/con vulnerability with win98/95...well i tried at home ,and lol...my screen went blue..(yup ,thing most people see in windos ) it went blue again and again and again...lol

i had to restart the machine ....i think they've corrected the problem in win2k and up...or is it stilll available ?...

think twice before trying it..if there's anything valuble in ur win box (esp if it's ur off machine)..nobody can say what it'll do..

BTB i do not know abt the technical details of this...anyone?
 
Old 01-04-2002, 12:40 AM   #7
Half_Elf
LQ Guru
 
Registered: Sep 2001
Location: Montreal, Canada
Distribution: Slackware; Debian; Gentoo...
Posts: 2,163

Rep: Reputation: 46
The only thing you can do to have a safe and stable computer when you use winduz is to stop booting it
 
Old 01-04-2002, 05:14 AM   #8
anoop_chandran
Member
 
Registered: Nov 2001
Distribution: Redhat 7.0 ,mandrake 8.0 ,Redhat 7.2
Posts: 99

Original Poster
Rep: Reputation: 15
u said it...
 
Old 01-04-2002, 01:19 PM   #9
FuriousGnu
LQ Newbie
 
Registered: Dec 2001
Location: Canada
Distribution: Red Hat 7.2
Posts: 25

Rep: Reputation: 15
Hmm, haven't heard of that one.... what exactly is the con/con vulnerability?
 
Old 01-04-2002, 03:14 PM   #10
ratface
LQ Newbie
 
Registered: Dec 2001
Location: Wiltshire UK
Distribution: SuSE 7.2 / Slackware 8
Posts: 25

Rep: Reputation: 15
Well to add another insult to MS users, another hole has been found in IE5.5 / 6

See links below, oh and there is no patch for it either

http://www.guninski.com/getob3.html

http://www.theregister.co.uk/content/55/23557.html
 
Old 01-05-2002, 01:18 PM   #11
Ruckuss
LQ Newbie
 
Registered: Dec 2001
Posts: 15

Rep: Reputation: 0
Popular OS's

Just wait when Linux finally comes out of the cave and knocks out Microsoft, all the hackers will be exploiting Linux. It has started already......
 
Old 01-05-2002, 07:24 PM   #12
Half_Elf
LQ Guru
 
Registered: Sep 2001
Location: Montreal, Canada
Distribution: Slackware; Debian; Gentoo...
Posts: 2,163

Rep: Reputation: 46
Yeah of course it will. But linux have many advantage versus windows.

1-Files Permission. Try to infect a computer with a virus if you don't have any right on the hard drive. Of course windows NT/XP have fs rights but you need to enable it... So most win computer can still be infected by virus or anything requiring to write something on the HD. (And I try yesterday to enable fs rights on a friend computer running XP... But something was buggy, preventing us to enable it so we finally reinstalled win)

2-Open Source. When Bill "Cash" Gates find a new hole/bug/exploit on his new baby OS, he write on his agenda a reminder to fix it in the nex version or if it's really dangerous they give people a patch. (But never inform them about real fact.... they say win media players is now safe with the new patch... DONT TRUST THEM.) On Linux, when a bug is found, hundred (thousand) of programmer try to fix it by them selve, for free. Plus,they provide the real information on web about the bugs. "Yes this part of gna gna prog have been badly coded so it can result in... to fix it you can try this prog or this version etc etc..." AND ITS FREE. Bill Gates blame hackers when they find an holes... But they just exploit a bad system.

3- Flexibility. Some times ago, I found on a security web site a bad and dangerous exploit attacking the "send mail" prog in linux. It was a bad hole cuz the send mail start with the system. So I enter my rc.d folders (something like autoexec in winduz) I found the command lines calling send mail and I stopped it. In Windows, if a hole with the dimension of Moon start with your system,good luck... Find a prog to black this port, or good download a microgoat patch (if they fix it yet). You CANT edit your system by your self (or very hardly).

So... Dunno how much hacker will attack linux in the future (in fact a lot of them attack winduz only cuz they hates micro$oft... ) but they will find it harder to find holes and people will find it easier to fix it.
 
Old 01-06-2002, 12:40 AM   #13
anoop_chandran
Member
 
Registered: Nov 2001
Distribution: Redhat 7.0 ,mandrake 8.0 ,Redhat 7.2
Posts: 99

Original Poster
Rep: Reputation: 15
con/con

well i dunno the exact technical things, but yes if u trying running this in win98/95 the fatal error screen comes up

start>run>con/con "enter"

and u get the blue screen..
let me tell u that if ur at home or office ,before trying this think twice or thrice or more...b'coz only windOS knows what's going to happen next....lol..if u have some very imp docs or something like that ,and it disappears...(well,that didn't happen to me...)...but u might have to use ctrl+alt+del...lol.don't blame me...

if u r trying to save a file as con.txt (i used notepad )u get this error message...:this file name is a reserved device name,please choose another name.

try searching the google groups for this .. i think i heard abt it from there...
 
Old 01-08-2002, 12:01 AM   #14
FuriousGnu
LQ Newbie
 
Registered: Dec 2001
Location: Canada
Distribution: Red Hat 7.2
Posts: 25

Rep: Reputation: 15
Warning noted. If I ever boot into Windows again, I will give it a try.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to let fedora support UPnP 80mail Linux - Networking 4 11-19-2005 10:59 PM
UPnP on Linksys Router brokenflea Linux - Security 2 08-22-2004 01:54 AM
uPnP Question mawdryn Linux - Networking 2 07-22-2004 11:07 AM
Snort. NETBIOS, and SCAN UPNP troworld Linux - Security 4 08-07-2003 12:09 PM
Upnp on Linux (redhat 9) psterr Linux - Security 1 06-08-2003 01:07 AM

LinuxQuestions.org > Forums > Non-*NIX Forums > General

All times are GMT -5. The time now is 03:41 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration