AplusWebMaster
Topic Starter
FYI…
- http://www.techweb.com/article/printableAr…_section=700028
September 16, 2004
"…Less than 24 hours after Microsoft released details of the latest vulnerability in Windows, hackers were sharing details and eager to get their hands on exploit code, said Ken Dunham, the director of malicious code research for Reston, Va.-based security intelligence provider iDefense…The most likely attack avenue…is an HTML e-mail that includes or links to a hostile .jpg image, although links to malicious Web sites or even instant messages could be used as attack vectors…Worse, even patched systems can be later turned into vulnerable computers, added Weafer, if applications with the flawed image processing .dll are later installed on made-safe PCs. "That could 'undo' the patch," said Weafer, "and makes the 'stickiness' of the more difficult than normal." In addition, Dunham concluded, not even the massive Service Pack 2 (SP2) update for Windows XP completely protects against the bug, since "other products may also need to be patched to fully protect against this vulnerability."
>>> http://www.microsoft.com/technet/security/…n/MS04-028.mspx
.
- http://www.techweb.com/article/printableAr…_section=700028
September 16, 2004
"…Less than 24 hours after Microsoft released details of the latest vulnerability in Windows, hackers were sharing details and eager to get their hands on exploit code, said Ken Dunham, the director of malicious code research for Reston, Va.-based security intelligence provider iDefense…The most likely attack avenue…is an HTML e-mail that includes or links to a hostile .jpg image, although links to malicious Web sites or even instant messages could be used as attack vectors…Worse, even patched systems can be later turned into vulnerable computers, added Weafer, if applications with the flawed image processing .dll are later installed on made-safe PCs. "That could 'undo' the patch," said Weafer, "and makes the 'stickiness' of the more difficult than normal." In addition, Dunham concluded, not even the massive Service Pack 2 (SP2) update for Windows XP completely protects against the bug, since "other products may also need to be patched to fully protect against this vulnerability."
>>> http://www.microsoft.com/technet/security/…n/MS04-028.mspx
.