Go Back  PPRuNe Forums > Misc. Forums > Computer/Internet Issues & Troubleshooting
Reload this Page >

Windows and file sharing vulnerability


Notices
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

Windows and file sharing vulnerability

Old 19th August 2010 | 07:27
  #1 (permalink)  
Thread Starter
Per Ardua ad Astraeus
 
Joined: Mar 2000
Posts: 18,575
Likes: 4
From: UK
Windows and file sharing vulnerability

Last week Apple fixed an I-Tunes vulnerability involving the loading of "safe" file types from remote network locations. A company called Acros Security says this vulnerability works when a remote attacker plants a malicious DLL with a specific name on a network share and get the user to open a media file from this network eg using I-Tunes, requiring minimal effort by the attacker.

Microsoft Windows and about 40 applications that run on it are vulnerable to this form of attack and M$ are 'investigating'. As always, Facebook/Twitter etc users beware?
BOAC is offline  
Reply
Old 19th August 2010 | 07:53
  #2 (permalink)  
 
Joined: Aug 2002
Posts: 3,663
Likes: 0
From: Earth
BOAC,

Much as your vulnerability warning efforts are admirable, I would think you're putting yourself in a risky situation where people might start relying on you to issue the advisories ?

Given the number of combinations of different software and different vulnerabilities you're going to have to start doing a lot more posting than you are at the moment to keep up with them all.

Personally I would think the mods would do better to put a sticky at the top of the C&I forum giving links to well known sites that activley maintain lists of current security vulnerabilities (or "security advisories" as the software developers prefer to call them) .... as well as a set of FAQs which seem to come up time and time again here on C&I.
mixture is offline  
Reply
Old 19th August 2010 | 08:29
  #3 (permalink)  
Thread Starter
Per Ardua ad Astraeus
 
Joined: Mar 2000
Posts: 18,575
Likes: 4
From: UK
A good idea and you should PM the mod?

people might start relying on you to issue the advisories
- would hope not, but that they would perhaps Google 'Acros' and see what it is all about? There are plenty of links.

Better forewarned than forlorn?
BOAC is offline  
Reply
Old 19th August 2010 | 09:33
  #4 (permalink)  
 
Joined: Aug 2002
Posts: 3,663
Likes: 0
From: Earth
A good idea and you should PM the mod?
Maybe.... but then I do know mod Saab is regularly sighted in this dark and dingy corner of PPRuNe.

Better forewarned than forlorn?
Don't misunderstand my point, I was being genuine when I said your efforts were admirable....only wanted to put forward my 2 <currency> worth of thoughts......
mixture is offline  
Reply
Old 19th August 2010 | 13:35
  #5 (permalink)  
 
Joined: Aug 2000
Posts: 436
Likes: 0
From: Patterson, NY
BOAC:

Many of these "vulnerabilities" are, IMHO, over-exaggerated in that the majority of users would never suffer from these security lapses. As long as one is careful/cautious/paranoid about what one does on the Interweb then the chances of suffering from one of these security issues is somewhat mitigated.
rgbrock1 is offline  
Reply
Old 19th August 2010 | 13:41
  #6 (permalink)  
Thread Starter
Per Ardua ad Astraeus
 
Joined: Mar 2000
Posts: 18,575
Likes: 4
From: UK
RG - agreed, but how many Faceb o o k/Twitter/I-Tunes/whatever users fit that spec?
BOAC is offline  
Reply
Old 19th August 2010 | 16:02
  #7 (permalink)  
 
Joined: Aug 2000
Posts: 436
Likes: 0
From: Patterson, NY
Correct BOAC. I've seen people do some very troubling things on sites like Facebook or Twitter. (Both of which I will never have an account on. NEVER.)

iTunes, on the other hand, is virtually problem-free.
rgbrock1 is offline  
Reply
Old 20th August 2010 | 07:42
  #8 (permalink)  
Thread Starter
Per Ardua ad Astraeus
 
Joined: Mar 2000
Posts: 18,575
Likes: 4
From: UK
I'll write this very small, but it now looks as if at least 200 Windows applications are affected. There is a temporary fix if anyone is interested.
BOAC is offline  
Reply
Old 24th August 2010 | 08:20
  #9 (permalink)  
Thread Starter
Per Ardua ad Astraeus
 
Joined: Mar 2000
Posts: 18,575
Likes: 4
From: UK
Microsoft information on 'the issue' and fixes

Microsoft Security Advisory (2269637): Insecure Library Loading Could Allow Remote Code Execution

Microsoft Security Advisory 2269637 Released - The Microsoft Security Response Center (MSRC) - Site Home - TechNet Blogs

and the 'fix'

A new CWDIllegalInDllSearch registry entry is available to control the DLL search path algorithm

Over to the gurus now to decide if this is REALLY a problem or should we ignore it.
BOAC is offline  
Reply
Old 25th August 2010 | 08:46
  #10 (permalink)  
Thread Starter
Per Ardua ad Astraeus
 
Joined: Mar 2000
Posts: 18,575
Likes: 4
From: UK
First 3 apps named:

uTorrent BitTorrent client
PowerPoint
Firefox
BOAC is offline  
Reply

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Thread Tools
Search this Thread

Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.