Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Feast of Egos
Tim Mullen, 2004-09-07

Eager to tarnish Microsoft's shiny new Service Pack 2, the security press managed to spin the most thin and marginal issues into "gaping holes" and "security craters."

Comments Mode:
Feast of Egos 2004-09-07
Beryllium Sphere LLC (1 replies)
Feast of Egos 2004-09-13
Anonymous
Feast of Egos 2004-09-08
Todd Knarr (2 replies)
I have to agree with you about most of the coverage of SP2 "holes" being overblown. Much of the hoopla boils down to the firewall doing it's job. It blocks incoming connections by default. It's supposed to do that. The problem isn't that it's doing it, it's that there's so many critical applications that depend on arbitrary incoming connections to desktop machines.

I don't agree with you about things like the shell prompt "not ZoneID aware" hole. That's a hole. It may be a hole by design, but it's still a hole. When SP2 was released, the programmers KNEW we have people willing to jump through the hoops neccesary to run malware inside a password-protected Zip file. When they introduced zones, they should've extended them to all parts of the system. As it stands, they've extended them just far enough to convince ordinary non-clued users that they're protected by the new security zones but not far enough to actually handle all the things we know users are willing to do.

Ditto for the security center spoofing hole. If we're supposed to depend on the security center, then it SHOULD NOT BE POSSIBLE for anything other than us to change the security center's settings. If outside software can diddle with the settings, then we're reduced to asking ourselves whether, at this point, after what we've done, we can trust the security center. If the average Windows user could answer that reliably, we wouldn't need the security center in the first place.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/265/28366#28366
Feast of Egos 2004-09-09
Troll (2 replies)
Feast of Egos 2004-09-10
Todd Knarr (2 replies)
Feast of Egos 2004-09-13
Anonymous
Feast of Egos 2004-09-14
Angus (1 replies)
Feast of Egos 2004-09-16
Anonymous
Feast of Egos 2004-09-13
Ed
Feast of Egos 2004-09-14
Anonymous
Feast of Egos 2004-09-08
Anonymous
Feast of Egos 2004-09-08
Mat, CISSP
Feast of Egos 2004-09-08
Anonymous (1 replies)
Feast of Egos 2004-09-08
Anonymous
Feast of Egos 2004-09-08
Problem Updates (1 replies)
Feast of Egos 2004-09-14
Anonymous
I Agree 2004-09-08
Lucas
Feast of Egos 2004-09-09
Some Hacker (3 replies)
Feast of Egos 2004-09-14
Anonymous (1 replies)
Feast of Egos 2004-09-19
Anonymous
Feast of Egos 2004-09-14
Brutal Dictator
Feast of Egos 2004-09-14
Angus (1 replies)
Feast of Egos 2004-09-19
AWKz
SP2 = MS-hyped Snake Oil 2004-09-14
Matthew Murphy
Feast of Egos 2004-09-14
Anonymous
Feast of Egos 2004-09-17
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus