take that crap out
ZXNet echo conference «zxnet.pc»
From Kirill Frolov → To All 13 February 2003
================================================================================
* Area : su.cm (su.cm)
* From : RedArc, 2:5020/400 (06 Feb 03 19:06)
* To : All
* Subj: Serious danger: Windows XP has completely lost its weight
================================================================================
From: "RedArc"
http://www.vokruginfo.ru/news/news2977.html
Serious danger: Windows XP is completely worn out
In order for the attacker to gain full control of the machine,
the user just needs to move the mouse cursor across the screen
Just move the cursor to the file icon - and your computer will be completely
in the hands of an attacker
Updated: 12/20/2002
Microsoft products have never been particularly secure:
news about another error discovered in the most “friendly” operating room
system of the world, appeared with enviable regularity. But there is a hole in Windows protection
XP, discovered the other day, claims first place in the list of the most ridiculous and
dangerous vulnerabilities. The fact is that she is literally in front of
through the eyes of 100% of computer users. The vulnerability has been assigned critical
threat rating because it allows an attacker to execute on the machine
victims of arbitrary program code.
According to Compulenta, the hole is contained in the Windows Shell component and is associatedwith the possibility of buffer overflow when reading non-standard attributes
(custom attributes) audio files in mp3 and Windows Media Audio formats.
Attributes are read when you hover the mouse over the file icon,
as well as when opening network folders with files and downloading files from the Internet. B
In some cases, Windows Shell reads the attributes of files attached to
emails when previewing or opening the latest ones. in other words,
the vulnerability can be exploited even if the user does not open
file. To carry out an attack, a hacker must place a music file with
incorrect attributes on a website or network drive, and then lure there
user.
Microsoft emphasizes that the vulnerability is relevant for all versions of Windows XP, including
including with Service Pack 1 installed. Other versions of Windows do not have such a hole
contain. All Windows XP users are advised to download immediately
appropriate patch. Patch option for 32-bit version of Windows XP
can be found here. More information about the hole is included in the bulletin.
security MS02-072.
mailto: redarc@trojan.ru Internet: http://redarchomepage.chat.ru
-+- ifmail v.2.15dev5
+ Origin: FidoNet Online - http://www.fido-online.com (2:5020/400)
================================================================================
Press RESET immediately, All!