• HEXUS
  • HEXUS.tv
  • channel
  • gaming
  • lifestyle
  • trust
  • community
  • ESReality
  • HEXUS.community discussion forums

    Welcome to the HEXUS.community discussion forums forums.

    You are currently viewing our boards as a guest which gives you limited access to view most discussions and other features. By joining our free community you will have access to post topics, respond to polls and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

    Go Back   HEXUS.community discussion forums > HEXUS.channels > General discussion

    General discussion Chatter, desires, jokes & rants; some threads are banter some are serious - please show respect for others Add RSS Feed

    Reply
     
    LinkBack Thread Tools
    Old 24-07-2003, 04:46 PM   #1 (permalink)
    Hmmm bed
     
    Join Date: Jul 2003
    Posts: 427
    Thanks: 0
    Thanked 0 Times in 0 Posts
    'Critical' flaw found in Windows

    Just a bit of news for ya. Thought was interesting ....

    Linky: http://news.bbc.co.uk/1/hi/technology/3092399.stm

    Microsoft has issued a warning about a critical security flaw that affects most versions of its Windows software.
    The flaw involves DirectX, an extensive collection of programming add-ons for Windows used by computer games.

    If exploited, the flaw could allow a malicious hacker to run their own specially crafted computer code to plant a virus or even take over a machine.

    Microsoft has given the flaw its highest severity rating.

    Music mayhem

    The flaw affects a large number of the versions of Microsoft Windows in use.

    Embarrassingly for Microsoft one of the products affected is Windows Server 2003.

    This was supposed to be much more secure as it was one of the first products to go through Microsoft's improved systems for weeding out bugs and security problems.

    On Windows Server 2003 the bug is only rated as "important" by Microsoft because the default settings would not allow such a program to be run.

    The vulnerability comes about because of the way that a part of DirectX, called DirectShow, handles MIDI or music files.

    MIDI, or Musical Instrument Digital Interface, defines a standardised way of swapping music information between computers, music keyboards and synthesisers.

    The flaw, found by eEye Security, would allow a specially crafted MIDI instruction to swamp the cache, or buffer, in DirectX and allow a hidden program within it to run on the target machine.

    Such buffer overflow bugs are quite a common way for malicious programs to infect a machine.

    Microsoft has issued an alert about the flaw and a patch to close the loophole. It said that currently there were no known exploits of the bug.

    The instruction could get into a computer by being put on a webpage.

    It can also be put into an e-mail message that uses web formatting.

    The DirectX flaw is the latest in a series of security problems that Microsoft has warned about over the last few weeks.
    Basher is offline   Reply With Quote
    Old 24-07-2003, 04:54 PM   #2 (permalink)
    Cable Guy
     
    Jonny M's Avatar
     
    Join Date: Jul 2003
    Location: Loughborough Uni
    Posts: 4,274
    Thanks: 0
    Thanked 4 Times in 1 Post
    Thanks for the heads-up, getting my updates now.
    Jonny M is offline   Reply With Quote
    Old 24-07-2003, 05:00 PM   #3 (permalink)
    Administrator
     
    Join Date: Jul 2003
    Location: Internet
    Posts: 15,998
    Thanks: 373
    Thanked 696 Times in 483 Posts
    Blimey - you get them in everything from MS these days !

    Agent is offline   Reply With Quote
    Old 24-07-2003, 05:04 PM   #4 (permalink)
    Jigsawing Menace
     
    Join Date: Jul 2003
    Location: Bracknell / Brighton
    Posts: 300
    Thanks: 0
    Thanked 0 Times in 0 Posts
    Its such a mission having to continually test this updates with the software that runs on the systems to ensure that everything will continue to work after the update.

    *cries*


    Nimrod is offline   Reply With Quote
    Old 24-07-2003, 05:11 PM   #5 (permalink)
    Team HEXUS.net
     
    joshwa's Avatar
     
    Join Date: Jul 2003
    Location: Liverpool, UK
    Posts: 4,546
    Thanks: 65
    Thanked 50 Times in 48 Posts
    joshwa's system
    View joshwa's Twitter Profile
    this is a major pain in the bum for people who run windows servers, becuase every week or 2 you're having to update the server, reboot etc, to keep it updated.

    joshwa is offline   Reply With Quote
    Old 24-07-2003, 05:11 PM   #6 (permalink)
    Member
     
    Join Date: Jul 2003
    Posts: 160
    Thanks: 0
    Thanked 0 Times in 0 Posts
    TBH i've just come to accept that MS products have more holes than swiss cheese, the patches are so regular i have resorted to awaiting the service pack releases, having said that, i do have a NAT router and a decent firewall setup and my IP changes every 2 hours so i am not too worried about hackers, expliots are the worst but I usually don't run anything without knowing where it has come from and only 5 people have my proper email address all emails on my normal account are usually just flushed every few days. I've never had any problems yet...


    LoopyJuice is offline   Reply With Quote
    Old 24-07-2003, 06:46 PM   #7 (permalink)
    Administrator
     
    Join Date: Jul 2003
    Location: Internet
    Posts: 15,998
    Thanks: 373
    Thanked 696 Times in 483 Posts
    Originally posted by LoopyJuice
    TBH i've just come to accept that MS products have more holes than swiss cheese, the patches are so regular i have resorted to awaiting the service pack releases, having said that, i do have a NAT router and a decent firewall setup and my IP changes every 2 hours so i am not too worried about hackers, expliots are the worst but I usually don't run anything without knowing where it has come from and only 5 people have my proper email address all emails on my normal account are usually just flushed every few days. I've never had any problems yet...
    Yup, the best weapon in computer security is usualy common sence
    Agent is offline   Reply With Quote
    Old 24-07-2003, 07:24 PM   #8 (permalink)
    If your 5555...
     
    Swafe's Avatar
     
    Join Date: Jul 2003
    Location: Then I'm...
    Posts: 6,666
    Thanks: 0
    Thanked 0 Times in 0 Posts
    sheesh another?

    i might as well buy a giant patch these days instead of windows, i dont think much of windows is left, everythings been patched

    Originally Posted by Knoxville
    As I find big muff's to be a bit of an aquired taste
    AMD Athlon 4400X2 @ 2.565PenisextentionMhz
    Dual Layer, Gold Plated, LED Power,Dual Golden OMG IT MAKES MY CodPiece BIGGER 1-1-1-1 DDR62.3 @ 1222.3433Mhz
    5 X 400GB Porn Array
    X1800XT Dildo enchanged 3D Version, 512MegaLongJohn
    Oh, did I mention.....I like sheep.....


    WWW.MrsBurley.CO.UK
    now updated
    Swafe is offline   Reply With Quote
    Old 25-07-2003, 03:49 AM   #9 (permalink)
    By-Tor with sticks
     
    spikegifted's Avatar
     
    Join Date: Jul 2003
    Location: still behind the paddles
    Posts: 910
    Thanks: 0
    Thanked 0 Times in 0 Posts
    See, this is the problem with dominance... When your product has a near monopoly in the market, everyone (and I mean anyone who can) will take a shot at it... If enough people take enough pot-shots at it, someone, somewhere will find cracks in the armor!

    www.spikegifted.net | BOINC SETI@Home stats | BOINC CPDN stats | eBay.co.uk feedback
    So you want to know something about SMP? Try here...
    Caution: Cape does not enable user to fly. - Batman costume warning label (Rolfe, John & Troob, Peter, Monkey Business (Swinging Through the Wall Street Jungle), 2000)

    spikegifted is offline   Reply With Quote
    Reply

    Breadcrumb
    Go Back   HEXUS.community discussion forums > HEXUS.channels > General discussion


    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Trackbacks are On
    Pingbacks are On
    Refbacks are On




    All times are GMT. The time now is 03:28 PM.

    Any representations/statements made on the HEXUS.community discussion forums are the representations/statements of the author i.e. the person/organisation making them. If any such representations/statements are disputed they are a matter between the parties concerned.
    HEXUS Limited accepts no responsibility for any misrepresentations, inaccurate or false statements made by any person/organisation other than HEXUS Limited employees.
    For more information please read HEXUS Limited's terms, conditions and privacy policy.

    Hosted Exchange

    Powered by vBulletin® Version 3.8.4
    Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
    Content Relevant URLs by vBSEO 3.3.2
    © Copyright 2009 HEXUS® Limited. All rights reserved. Unauthorised reproduction strictly prohibited.