Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Zero-day holiday
Kelly Martin, 2006-01-04

A few hundred million Windows XP machines lay vulnerable on the Web today, a week after a zero-day exploit was discovered. Meanwhile, new approaches and ideas from the academic world - that focus exclusively on children - may give us hope for the future after all.

Comments Mode:
Zero-day holiday 2006-01-04
Anonymous (2 replies)
Re: Zero-day holiday 2006-01-05
Kelly Martin (4 replies)
Re: Re: Zero-day holiday 2006-01-05
Jack
Re: Re: Zero-day holiday 2006-01-05
assurbanipal
Immoral, etc. 2006-01-05
Andrew Jones
Re: Re: Zero-day holiday 2006-01-06
Anonymous
Re: Zero-day holiday 2006-01-05
Anonymous
Zero-day holiday 2006-01-04
Nick
Zero-day holiday 2006-01-04
Anonymous
I really don't understand why folks are saying this vulnerability is bigger than the RPC vuln that led to Blaster - or the issue that led to Sasser. The WMF bug cannot propagate by itself. No amount of social engineering is going to cause an infection rate as high (or propagation as swift) as a bug in a network service that's listening by default.

Windows users ALREADY had huge problems with spyware. Okay, this might be an easy way to get machines infected - but it's only one more way to do that. Not a particularly new way. Not a qualitatively different way.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/377/32882#32882
Zero-day holiday 2006-01-05
Matthew Murphy (1 replies)
incorrect 2006-01-05
Kelly Martin (2 replies)
Re: incorrect 2006-01-05
Not the original poster
Re: incorrect 2006-01-07
Matthew Murphy (1 replies)
thanks 2006-01-12
Kelly Martin
Zero-day holiday 2006-01-05
Anonymous
Zero-day holiday 2006-01-05
hhhobbit
Zero-day holiday 2006-01-05
horror_vacui
Zero-day holiday 2006-01-05
Anonymous
Zero-day holiday 2006-01-05
M. Amos
Zero-day holiday 2006-01-05
Anonymous
Zero-day holiday 2006-01-05
Anonymous
Not a real solution 2006-01-05
Mike Warot (1 replies)
Re: Not a real solution 2006-01-06
Khem C (1 replies)
Re: Re: Not a real solution 2006-01-07
Anonymous
Zero-day holiday 2006-01-12
Nicolas Falliere







 

Privacy Statement
Copyright 2008, SecurityFocus