Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Fear, Uncertainty and Doubt, Inc.
Tim Mullen, 2001-12-31

Everyone from the FBI to the L.A. Times has something scary to say about the new XP vulnerability. Here's why they all have it wrong.

Comments Mode:
Fear, Uncertainty and Doubt, Inc. 2001-12-31
Anonymous (1 replies)
Fear, Uncertainty and Doubt, Inc. 2002-01-03
Patrik Birgersson (3 replies)
Autoupdate in XP 2002-01-04
jpostel
Fear, Uncertainty and Doubt, Inc. 2002-01-07
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-07
Anonymous
Fear, Uncertainty and Doubt, Inc. 2001-12-31
ALI ABOLFATHI
RE: Fear, Uncertainty and Doubt, Inc. 2001-12-31
J Horner <jjhorner@bellsouth.net> (2 replies)
RE: Fear, Uncertainty and Doubt, Inc. 2001-12-31
Anonymous (1 replies)
RE: Fear, Uncertainty and Doubt, Inc. 2002-01-03
Anonymous (1 replies)
Fear, Uncertainty and Doubt, Inc. 2001-12-31
Anonymous (2 replies)
Fear, Uncertainty and Doubt, Inc. 2001-12-31
Anonymous (1 replies)
Fear, Uncertainty and Doubt, Inc. 2002-01-05
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-02
Anonymous
Fear, Uncertainty and Doubt, Inc. 2001-12-31
Anonymous
No worm? Tim, lay off the meds 2001-12-31
Anonymous (9 replies)
No worm? Tim, lay off the meds 2001-12-31
Anonymous
No worm? Tim, lay off the meds 2001-12-31
Anonymous
No worm? Tim, lay off the meds 2002-01-01
Anonymous
A lesson in comprehension... 2002-01-02
Anonymous (1 replies)
A lesson in... Comprehend this: MS has 36+Billion in Liquidity (4x next on list) 2002-01-06
gained by monopoly + inferior product = superior pricing (does this compute?) (1 replies)
No worm? Tim, lay off the meds 2002-01-02
Anonymous
No worm? Tim, lay off the meds 2002-01-02
Anonymous
A great article, but ... 2002-01-13
Der HexXer (@gmx.net)
In your bias opinion. 2002-01-01
Carnivore Knows
Fear, Uncertainty and Doubt, Inc. 2002-01-01
Mike Bunyard
Fear, Uncertainty and Doubt, Inc. 2002-01-01
Anonymous
Exploit out it appears 2002-01-02
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-02
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-02
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-02
Anonymous
Huh? 2002-01-03
guest@netpixies.net
Interesting article 2002-01-03
keydet89@yahoo.com
First off, let me just post this...someone I know has been receiving quite a lot of the following on their BID:

"9,2002-01-02 04:25:16,2004303,UPNP NOTIFY
overflow,10.100.3.107,,239.255.255.250,,length=96&location=h
ttp://10.
100.3.107:2869/upnphost/udhisapi.dll?content%3Duuid:38a5581b
-432a-
49ed-9f8e-1eca1ab25585,30,,1900,1900,00000411"

Regarding Tim's comment on the SANS NewsBytes email...well, it's from SANS...SANS is a commercial organization, and things must be presented in a unique manner in order to differentiate the organization.

Regarding Tim's comment on a worm using this vulnerability...honestly, I'd like to hear the reasoning behind that one. After all, sadmin/IIS was followed by Code Blue and Nimda...all using the same directory transversal exploit. Code Red exploited a vulnerability that could have been obviated at installation time by simply disabling the script mapping (falls under "unnecessary services or functionality" for most sites). Yet these worms were still prolific. So why don't you think we'll see this in a worm?

Sadly, too many folks who come to SF to read Tim's stuff are just looking for something to pick at...while themselves neither revealing their own names, nor writing their own articles.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/50/9642#9642
I know this is not the place, but 2002-01-03
Demostenes
Fear, Uncertainty and Doubt, Inc. 2002-01-03
Nighthawk
Fear, Uncertainty and Doubt, Inc. 2002-01-04
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-04
Anonymous (2 replies)
Fear, Uncertainty and Doubt, Inc. 2002-01-04
Anonymous
Fear, Uncertainty and Doubt, Inc. 2002-01-04
Anonymous
Reduced to perpetual apologist 2002-01-04
Paul Lembo
UPnP, an old vulnerability 2002-01-04
Alberto Cozer
Here you go Tim, the exploit is out ! 2002-01-04
Chad Cyrisse (1 replies)
Exploit for another vuln! 2002-01-15
Der HexXer (1 replies)
Exploit for another vuln! 2002-01-17
JHendo
Give me a break 2002-01-08
Burleyman (1 replies)
Give me a break 2002-01-08
aSteve (1 replies)
Give me a break 2002-01-09
Burleyman
Fear, Uncertainty and Doubt, Inc. 2002-01-11
Anonymous
I love you 2002-01-16
bill.gates@microsoft.com
The bottom line... 2002-01-19
Carnivore knows (1 replies)
Re: The bottom line... 2006-02-24
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus