Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Fear, Uncertainty and Doubt, Inc.
Tim Mullen, 2001-12-31

Everyone from the FBI to the L.A. Times has something scary to say about the new XP vulnerability. Here's why they all have it wrong.

Comments Mode:
Fear, Uncertainty and Doubt, Inc. 2001-12-31
Anonymous (1 replies)
Fear, Uncertainty and Doubt, Inc. 2002-01-03
Patrik Birgersson (3 replies)
Autoupdate in XP 2002-01-04
jpostel
Fear, Uncertainty and Doubt, Inc. 2002-01-07
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-07
Anonymous
Fear, Uncertainty and Doubt, Inc. 2001-12-31
ALI ABOLFATHI
RE: Fear, Uncertainty and Doubt, Inc. 2001-12-31
J Horner <jjhorner@bellsouth.net> (2 replies)
RE: Fear, Uncertainty and Doubt, Inc. 2001-12-31
Anonymous (1 replies)
RE: Fear, Uncertainty and Doubt, Inc. 2002-01-03
Anonymous (1 replies)
Fear, Uncertainty and Doubt, Inc. 2001-12-31
Anonymous (2 replies)
Fear, Uncertainty and Doubt, Inc. 2001-12-31
Anonymous (1 replies)
Fear, Uncertainty and Doubt, Inc. 2002-01-05
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-02
Anonymous
Fear, Uncertainty and Doubt, Inc. 2001-12-31
Anonymous
No worm? Tim, lay off the meds 2001-12-31
Anonymous (9 replies)
No worm? Tim, lay off the meds 2001-12-31
Anonymous
No worm? Tim, lay off the meds 2001-12-31
Anonymous
No worm? Tim, lay off the meds 2002-01-01
Anonymous
A lesson in comprehension... 2002-01-02
Anonymous (1 replies)
A lesson in... Comprehend this: MS has 36+Billion in Liquidity (4x next on list) 2002-01-06
gained by monopoly + inferior product = superior pricing (does this compute?) (1 replies)
No worm? Tim, lay off the meds 2002-01-02
Anonymous
No worm? Tim, lay off the meds 2002-01-02
Anonymous
A great article, but ... 2002-01-13
Der HexXer (@gmx.net)
In your bias opinion. 2002-01-01
Carnivore Knows
Actually, it's 3 vulnerabilities associated with the hole 2002-01-01
Anonymous
I read Mr. Mullens article via a link on the Register. It seemed to be a valid article until I reached the end of the article and saw "related links". One was entitled "MS warns of severe universal plug & play security hole". ( link ).

It turns out that there's three security vulnerabilities associated with the UPnP: a buffer overflow vulnerability, a denial of service hazard, and a zombie-like remote attack hazard. Two of these vulnerabilities are avoidable if UPnP is turned off (contrary to what Mr. Mullen's article states).

As for the supposed FUD: Gee, people scream loudly when the sewer flows in the opposite direction. Who was it that classified open-source *nix's (except the one they borrowed IP stack code from) as viral?

My stance: there's not an OS out there that doesn't have problems. None is the end-all-to-be-all. Each does something better than the other. ALL of them require constant patching/updating. Get over it, fix the hole, move on to the next problem (there will always be another one).

Mr. Mullen: you need to do better research before posting such an article. With this one, you give the impression of a hidden motive (angry because someone had "gored your ox"?).



[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/50/9596#9596
Fear, Uncertainty and Doubt, Inc. 2002-01-01
Mike Bunyard
Fear, Uncertainty and Doubt, Inc. 2002-01-01
Anonymous
Exploit out it appears 2002-01-02
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-02
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-02
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-02
Anonymous
Huh? 2002-01-03
guest@netpixies.net
Interesting article 2002-01-03
keydet89@yahoo.com
I know this is not the place, but 2002-01-03
Demostenes
Fear, Uncertainty and Doubt, Inc. 2002-01-03
Nighthawk
Fear, Uncertainty and Doubt, Inc. 2002-01-04
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-04
Anonymous (2 replies)
Fear, Uncertainty and Doubt, Inc. 2002-01-04
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-04
Anonymous
Reduced to perpetual apologist 2002-01-04
Paul Lembo
UPnP, an old vulnerability 2002-01-04
Alberto Cozer
Here you go Tim, the exploit is out ! 2002-01-04
Chad Cyrisse (1 replies)
Exploit for another vuln! 2002-01-15
Der HexXer (1 replies)
Exploit for another vuln! 2002-01-17
JHendo
Give me a break 2002-01-08
Burleyman (1 replies)
Give me a break 2002-01-08
aSteve (1 replies)
Give me a break 2002-01-09
Burleyman
Fear, Uncertainty and Doubt, Inc. 2002-01-11
Anonymous
I love you 2002-01-16
bill.gates@microsoft.com
The bottom line... 2002-01-19
Carnivore knows (1 replies)
Re: The bottom line... 2006-02-24
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus