Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Feast of Egos
Tim Mullen, 2004-09-07

Eager to tarnish Microsoft's shiny new Service Pack 2, the security press managed to spin the most thin and marginal issues into "gaping holes" and "security craters."

Comments Mode:
Feast of Egos 2004-09-07
Beryllium Sphere LLC (1 replies)
Feast of Egos 2004-09-13
Anonymous
Feast of Egos 2004-09-08
Todd Knarr (2 replies)
Feast of Egos 2004-09-09
Troll (2 replies)
Feast of Egos 2004-09-10
Todd Knarr (2 replies)
Feast of Egos 2004-09-13
Anonymous
There's a very good reason for the CMD program to not use the new file execution APIs (the ones that check origin of files) : if they did, the majority of administrative scripts in use today would be broken. Admins use these scripts counting on them to run unattended (either as a scheduled job, or a login script, or what have you). Most of them make use of third-party utilities, usually downloaded form the Internet with Internet Explorer. If CMD used the new APIs, these scripts would start popping up prompts and not work any more.

Breaking everyones' batch files would hardly be in the best interest of Microsoft's customers.





[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/265/28419#28419
Feast of Egos 2004-09-14
Angus (1 replies)
Feast of Egos 2004-09-16
Anonymous
Feast of Egos 2004-09-13
Ed
Feast of Egos 2004-09-14
Anonymous
Feast of Egos 2004-09-08
Anonymous
Feast of Egos 2004-09-08
Mat, CISSP
Feast of Egos 2004-09-08
Anonymous (1 replies)
Feast of Egos 2004-09-08
Anonymous
Feast of Egos 2004-09-08
Problem Updates (1 replies)
Feast of Egos 2004-09-14
Anonymous
I Agree 2004-09-08
Lucas
Feast of Egos 2004-09-09
Some Hacker (3 replies)
Feast of Egos 2004-09-14
Anonymous (1 replies)
Feast of Egos 2004-09-19
Anonymous
Feast of Egos 2004-09-14
Brutal Dictator
Feast of Egos 2004-09-14
Angus (1 replies)
Feast of Egos 2004-09-19
AWKz
SP2 = MS-hyped Snake Oil 2004-09-14
Matthew Murphy
Feast of Egos 2004-09-14
Anonymous
Feast of Egos 2004-09-17
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus