Reply to topic  [ 7 posts ] 
Google engineer publishes XP exploit 
Author Message
I haven't seen my friends in so long
User avatar

Joined: Thu Apr 23, 2009 7:10 pm
Posts: 5490
Location: just behind you!
Reply with quote
clicky


Quote:
the exploit is a classic drive-by attack that only requires a Windows XP user to visit it.


Quote:
The flaw was first revealed by Tavis Ormandy, a security engineer at Google. He revealed the flaw only five days after reporting it to Microsoft. He said that he revealed the flaw because Microsoft would not commit to fixing the bug in 60 days, and even posted sample exploit code.


interesting action by a Google employee (was it sanctioned by Google?), are we going to see a new section at MS dedicated to finding and publishing exploits for Google products now?

_________________
johnwbfc wrote:
I care not which way round it is as long as at some point some sort of semi-naked wrestling is involved.

Amnesia10 wrote:
Yes but the opportunity to legally kill someone with a giant dildo does not happen every day.

Finally joined Flickr


Wed Jun 16, 2010 10:44 am
Profile
What's a life?
User avatar

Joined: Fri Apr 24, 2009 10:21 am
Posts: 12700
Location: The Right Side of the Pennines (metaphorically & geographically)
Reply with quote
That would be good in a way. If they know about bugs, they can fix them.

_________________
pcernie wrote:
'I'm going to snort this off your arse - for the benefit of government statistics, of course.'


Wed Jun 16, 2010 11:56 am
Profile WWW
I haven't seen my friends in so long
User avatar

Joined: Thu Apr 23, 2009 7:10 pm
Posts: 5490
Location: just behind you!
Reply with quote
l3v1ck wrote:
That would be good in a way. If they know about bugs, they can fix them.


It would be if there wasnt all ready exploits out in the wild. Publishing after 5 days is just unbelievable.

_________________
johnwbfc wrote:
I care not which way round it is as long as at some point some sort of semi-naked wrestling is involved.

Amnesia10 wrote:
Yes but the opportunity to legally kill someone with a giant dildo does not happen every day.

Finally joined Flickr


Wed Jun 16, 2010 12:07 pm
Profile
What's a life?
User avatar

Joined: Fri Apr 24, 2009 10:21 am
Posts: 12700
Location: The Right Side of the Pennines (metaphorically & geographically)
Reply with quote
Yeah, he could have given them a month or so to fix it.

_________________
pcernie wrote:
'I'm going to snort this off your arse - for the benefit of government statistics, of course.'


Wed Jun 16, 2010 12:47 pm
Profile WWW
Spends far too much time on here
User avatar

Joined: Thu Apr 23, 2009 11:36 pm
Posts: 3527
Location: Portsmouth
Reply with quote
I agree.

Rather than just making it public after they don't agree to fix it within 60 days, he should have told them that if it isn't fixed within 60 days he will make it public.

_________________
Image


Wed Jun 16, 2010 2:20 pm
Profile
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
The tech podcasts were all over him last week, as was the tech press. Now, on Tuesday, they have been reporting that there is now an active exploit in the wild and people should use the Microsoft hot-fix - which basically kills the help system on Windows XP machines (it removes registry entries and you can delete / rename the affected DLL, but then no applications will be able to display help).

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Thu Jun 17, 2010 6:37 am
Profile ICQ
Legend
User avatar

Joined: Fri Apr 24, 2009 2:02 am
Posts: 29240
Location: Guantanamo Bay (thanks bobbdobbs)
Reply with quote
bobbdobbs wrote:
Publishing after 5 days is just unbelievable.

And all because they would not commit to fixing within 60 days.

_________________
Do concentrate, 007...

"You are gifted. Mine is bordering on seven seconds."

https://www.dropbox.com/referrals/NTg5MzczNTk

http://astore.amazon.co.uk/wwwx404couk-21


Thu Jun 17, 2010 7:18 am
Profile
Display posts from previous:  Sort by  
Reply to topic   [ 7 posts ] 

Who is online

Users browsing this forum: No registered users and 9 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
cron
Powered by phpBB® Forum Software © phpBB Group
Designed by ST Software.