Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Fear, Uncertainty and Doubt, Inc.
Tim Mullen, 2001-12-31

Everyone from the FBI to the L.A. Times has something scary to say about the new XP vulnerability. Here's why they all have it wrong.

Comments Mode:
Fear, Uncertainty and Doubt, Inc. 2001-12-31
Anonymous (1 replies)
Fear, Uncertainty and Doubt, Inc. 2002-01-03
Patrik Birgersson (3 replies)
Autoupdate in XP 2002-01-04
jpostel
Fear, Uncertainty and Doubt, Inc. 2002-01-07
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-07
Anonymous
Fear, Uncertainty and Doubt, Inc. 2001-12-31
ALI ABOLFATHI
RE: Fear, Uncertainty and Doubt, Inc. 2001-12-31
J Horner <jjhorner@bellsouth.net> (2 replies)
RE: Fear, Uncertainty and Doubt, Inc. 2001-12-31
Anonymous (1 replies)
RE: Fear, Uncertainty and Doubt, Inc. 2002-01-03
Anonymous (1 replies)
Fear, Uncertainty and Doubt, Inc. 2001-12-31
Anonymous (2 replies)
Fear, Uncertainty and Doubt, Inc. 2001-12-31
Anonymous (1 replies)
Fear, Uncertainty and Doubt, Inc. 2002-01-05
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-02
Anonymous
Fear, Uncertainty and Doubt, Inc. 2001-12-31
Anonymous
No worm? Tim, lay off the meds 2001-12-31
Anonymous (9 replies)
No worm? Tim, lay off the meds 2001-12-31
Anonymous
No worm? Tim, lay off the meds 2001-12-31
Anonymous
No worm? Tim, lay off the meds 2002-01-01
Anonymous
A lesson in comprehension... 2002-01-02
Anonymous (1 replies)
A lesson in... Comprehend this: MS has 36+Billion in Liquidity (4x next on list) 2002-01-06
gained by monopoly + inferior product = superior pricing (does this compute?) (1 replies)
No worm? Tim, lay off the meds 2002-01-02
Anonymous
No worm? Tim, lay off the meds 2002-01-02
Anonymous
A great article, but ... 2002-01-13
Der HexXer (@gmx.net)
In your bias opinion. 2002-01-01
Carnivore Knows
Fear, Uncertainty and Doubt, Inc. 2002-01-01
Mike Bunyard
Fear, Uncertainty and Doubt, Inc. 2002-01-01
Anonymous
Exploit out it appears 2002-01-02
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-02
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-02
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-02
Anonymous
Huh? 2002-01-03
guest@netpixies.net
> Steve Gibson jumped on the bandwagon with a page
> dedicated to saturating the issue with his own special
> blend of FUD that is almost elevated to an art form. In a
> complete exit from anything security related, Gibson goes
> as far as to charge Microsoft with purposefully
> withholding an advisory and patch for this vulnerability
> so that Christmas sales would not be affected.

You yourself say that a personal firewall is a viable
workaround. Why did MS not notice this for months? Do
they assign virtually no capable staff to the problem?
This would be one of the first things a competent security
person would look at, yet they left hundreds of thousands
of people exposed for almost 2 months without bothering to
try this and see, or so we are to believe. No matter what
the answer is, this reflects extremely badly on MS.

> My issue is that so many people have rushed to be
> authorities on this bug that many didn't bother to get
> their facts straight before posting fixes and writing
> articles about it. The NIPC advisory gives people
> specific instructions on how to disable the "UPnP
> Device Host" on XP and has been widely linked to by
> many. Unfortunately, this does absolutely nothing.

Hmm, it sounds like what you're saying is that people
like the FBI and NIPC and even MS themselves can't figure
out security issues well at all. Had these things been
posted on vuln-dev and bugtraq, we would have known more
than this within a day or two. This does not bode well
for MS's disclosure policy, which limits discussion to
people like the FBI, NIPC, MS and their associates, does
it?

You see, I speak from experience. I have had to fix bad
code that was being dissected in newsgroups. Bugs which
had been brought up by security staff many months before
were left unfixed, somehow there was never a programmer
available to assign to the problem. Then it hit the
mailing lists. The security folks looked it over and came
up with a fix the same day. Still no programmer was
assigned to the job. Finally the bug hit the mainstream
press, the VPs and CEO demanded action, and it was fixed
within 24 hours. That is just how things work at most
companies, I'm sorry to say.

My profound thanks to those who advocate "responsible
disclosure" ala RFP's policy. Having a little advance
notice is great for those at the company who care, and
the negative publicity that accompanies neglect is a great
motivator for those who don't.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/50/9631#9631
Interesting article 2002-01-03
keydet89@yahoo.com
I know this is not the place, but 2002-01-03
Demostenes
Fear, Uncertainty and Doubt, Inc. 2002-01-03
Nighthawk
Fear, Uncertainty and Doubt, Inc. 2002-01-04
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-04
Anonymous (2 replies)
Fear, Uncertainty and Doubt, Inc. 2002-01-04
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-04
Anonymous
Reduced to perpetual apologist 2002-01-04
Paul Lembo
UPnP, an old vulnerability 2002-01-04
Alberto Cozer
Here you go Tim, the exploit is out ! 2002-01-04
Chad Cyrisse (1 replies)
Exploit for another vuln! 2002-01-15
Der HexXer (1 replies)
Exploit for another vuln! 2002-01-17
JHendo
Give me a break 2002-01-08
Burleyman (1 replies)
Give me a break 2002-01-08
aSteve (1 replies)
Give me a break 2002-01-09
Burleyman
Fear, Uncertainty and Doubt, Inc. 2002-01-11
Anonymous
I love you 2002-01-16
bill.gates@microsoft.com
The bottom line... 2002-01-19
Carnivore knows (1 replies)
Re: The bottom line... 2006-02-24
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus