Page 3 of 3 FirstFirst 123
Results 33 to 36 of 36

Thread: XP SP2 : List of programs that need "tweaking" to work.

  1. #33
    Comfortably Numb directhex's Avatar
    Join Date
    Jul 2003
    Location
    /dev/urandom
    Posts
    17,074
    Thanks
    228
    Thanked
    1,026 times in 677 posts
    • directhex's system
      • Motherboard:
      • Asus ROG Strix B550-I Gaming
      • CPU:
      • Ryzen 5900x
      • Memory:
      • 64GB G.Skill Trident Z RGB
      • Storage:
      • 2TB Seagate Firecuda 520
      • Graphics card(s):
      • EVGA GeForce RTX 3080 XC3 Ultra
      • PSU:
      • EVGA SuperNOVA 850W G3
      • Case:
      • NZXT H210i
      • Operating System:
      • Ubuntu 20.04, Windows 10
      • Monitor(s):
      • LG 34GN850
      • Internet:
      • FIOS
    so an IE vulnerability allowing you to execute code remotely, and a firewall vulnerability which is only affected by executed code are COMPLETELY unrelated?

  2. #34
    Ex-MSFT Paul Adams's Avatar
    Join Date
    Jul 2003
    Location
    %systemroot%
    Posts
    1,926
    Thanks
    29
    Thanked
    77 times in 59 posts
    • Paul Adams's system
      • Motherboard:
      • Asus Maximus VIII
      • CPU:
      • Intel Core i7-6700K
      • Memory:
      • 16GB
      • Storage:
      • 2x250GB SSD / 500GB SSD / 2TB HDD
      • Graphics card(s):
      • nVidia GeForce GTX1080
      • Operating System:
      • Windows 10 x64 Pro
      • Monitor(s):
      • Philips 40" 4K
      • Internet:
      • 500Mbps fiber
    As far as the OS and service pack are concerned, the IE security enchancements, Windows firewall, data execution prevention, etc. are distinct.

    The priority for security is to protect against intrusion originating from the outside world - there is an almost limitless number of possible exploits for any system, given the user's access level, if we assume that they have to perform some action in order to affect their system.

    If you can have code executed on a system through some user action (running an email attachment, running a malicious script, being told to type in a command at a CLI prompt) then potentially any application on that system is "vulnerable".

    You could equally say that your MP3 collection can be rendered useless with a simple "ren [path]\*.mp3 *.omg" command, if you get the user to type it, for example.
    ~ I have CDO. It's like OCD except the letters are in alphabetical order, as they should be. ~
    PC: Win10 x64 | Asus Maximus VIII | Core i7-6700K | 16GB DDR3 | 2x250GB SSD | 500GB SSD | 2TB SATA-300 | GeForce GTX1080
    Camera: Canon 60D | Sigma 10-20/4.0-5.6 | Canon 100/2.8 | Tamron 18-270/3.5-6.3

  3. #35
    Comfortably Numb directhex's Avatar
    Join Date
    Jul 2003
    Location
    /dev/urandom
    Posts
    17,074
    Thanks
    228
    Thanked
    1,026 times in 677 posts
    • directhex's system
      • Motherboard:
      • Asus ROG Strix B550-I Gaming
      • CPU:
      • Ryzen 5900x
      • Memory:
      • 64GB G.Skill Trident Z RGB
      • Storage:
      • 2TB Seagate Firecuda 520
      • Graphics card(s):
      • EVGA GeForce RTX 3080 XC3 Ultra
      • PSU:
      • EVGA SuperNOVA 850W G3
      • Case:
      • NZXT H210i
      • Operating System:
      • Ubuntu 20.04, Windows 10
      • Monitor(s):
      • LG 34GN850
      • Internet:
      • FIOS
    so it's secure? you say on your own website that spyware can be installed into IE without any user interaction - either it's secure or it isn't.

  4. #36
    Ex-MSFT Paul Adams's Avatar
    Join Date
    Jul 2003
    Location
    %systemroot%
    Posts
    1,926
    Thanks
    29
    Thanked
    77 times in 59 posts
    • Paul Adams's system
      • Motherboard:
      • Asus Maximus VIII
      • CPU:
      • Intel Core i7-6700K
      • Memory:
      • 16GB
      • Storage:
      • 2x250GB SSD / 500GB SSD / 2TB HDD
      • Graphics card(s):
      • nVidia GeForce GTX1080
      • Operating System:
      • Windows 10 x64 Pro
      • Monitor(s):
      • Philips 40" 4K
      • Internet:
      • 500Mbps fiber
    Quote Originally Posted by directhex
    so it's secure? you say on your own website that spyware can be installed into IE without any user interaction - either it's secure or it isn't.
    "It"?
    I was questioning the assertion that the firewall in SP2 is "full of holes" out of professional interest as I thought myself aware of all the known issues with the networking aspects of SP2 (so IE security is outside of my area of expertise).

    Given the number of versions of IE out there, on different OSs, I don't think it is possible to make a sweeping statement about it.
    Is something secure if only in its default state it is hardened? That question would likely generate opposing points of view depending on who you asked.

    The principle of SP2 has been to chiefly increase the base level of security for the the majority of XP users that install it and accept the defaults, it cannot impact on the default operation of the OS too radically or it would break the majority of PCs beyond the users' ability to figure out and fix it.
    (See the list of applications "affected" or "broken" by SP2 and imagine what that might be if it, say, blocked outbound traffic by default as some people have claimed it should.)

    Is any OS or application "totally secure"? Nope.

    Would a widespread application of XP SP2 decrease the probability of users getting hit by malware? I would say certainly.


    That particular part of my site was written pre-SP2, but is not specifically XP-only so is still relevant to some - I need to review and update it, thanks
    ~ I have CDO. It's like OCD except the letters are in alphabetical order, as they should be. ~
    PC: Win10 x64 | Asus Maximus VIII | Core i7-6700K | 16GB DDR3 | 2x250GB SSD | 500GB SSD | 2TB SATA-300 | GeForce GTX1080
    Camera: Canon 60D | Sigma 10-20/4.0-5.6 | Canon 100/2.8 | Tamron 18-270/3.5-6.3

Page 3 of 3 FirstFirst 123

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. SP2 help - Hangs on Boot
    By Devilbod in forum Software
    Replies: 17
    Last Post: 24-01-2007, 02:35 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •