Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 12-28-2005, 08:17 PM   #1
dissipate
The Dirty Frenchman
 
dissipate's Avatar
 
Industry Role:
Join Date: Nov 2005
Location: Lost Angeles
Posts: 8,904
Large Windows Security Hole Found

This makes swiss cheese out of previous security patches

http://blogs.washingtonpost.com/secu...t_release.html
dissipate is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-28-2005, 08:25 PM   #2
WhoGivesaShit
Confirmed User
 
Join Date: Sep 2004
Posts: 307
worth the read
bump
WhoGivesaShit is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-28-2005, 08:39 PM   #3
Matt 26z
So Fucking Banned
 
Industry Role:
Join Date: Apr 2002
Location: ¤ª"˜¨๑۩۞۩๑¨˜"ª¤
Posts: 18,481
Yet once again a security company (Symantec) publicly announces a hole instead of going to MS behind closed doors so it can be quietly fixed.

Ironically, the security companies are the worse threat to computer security. If these threats are not made public, then hackers can't exploit them. If hackers are not exploiting them, then nobody needs to buy their security products.
Matt 26z is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-28-2005, 08:43 PM   #4
WhoGivesaShit
Confirmed User
 
Join Date: Sep 2004
Posts: 307
wthin minutes after a hack is found they spread the word on their boards.
their latest is to go after the security software instead of microsoft exploits.
WhoGivesaShit is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-28-2005, 08:45 PM   #5
crockett
in a van by the river
 
crockett's Avatar
 
Industry Role:
Join Date: May 2003
Posts: 76,806
Quote:
Originally Posted by Matt 26z
Yet once again a security company (Symantec) publicly announces a hole instead of going to MS behind closed doors so it can be quietly fixed.

Ironically, the security companies are the worse threat to computer security. If these threats are not made public, then hackers can't exploit them. If hackers are not exploiting them, then nobody needs to buy their security products.
I think M$ has had a past history of ignoring security holes when reported behind closed doors. Releasing them publicly forces them to have to fix it.
__________________
In November, you can vote for America's next president or its first dictator.
crockett is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-28-2005, 08:46 PM   #6
Screaming
I can change this!!!!!
 
Join Date: Feb 2004
Posts: 18,972
Good read.
__________________
Screaming is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-28-2005, 09:08 PM   #7
bjjb
Have laptop will travel
 
Join Date: Mar 2004
Location: 145201426
Posts: 13,074
Its called the ON button lol If i had the money I might consider going to a Mac. My Dutch partner swears by em. He has pc's but I bet theyre in the basement or attic gathering dust and mice droppings
bjjb is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-28-2005, 09:16 PM   #8
Spunky
I need a beer
 
Spunky's Avatar
 
Industry Role:
Join Date: Jun 2002
Location: ♠ Toiletville ♠
Posts: 133,949
Quote:
Originally Posted by Matt 26z
Yet once again a security company (Symantec) publicly announces a hole instead of going to MS behind closed doors so it can be quietly fixed.

Ironically, the security companies are the worse threat to computer security. If these threats are not made public, then hackers can't exploit them. If hackers are not exploiting them, then nobody needs to buy their security products.
I agree with that 100% but it makes their product very attractive if they can find a fix very quickly..Norton always seems to
__________________
Spunky is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-28-2005, 09:18 PM   #9
Harmon
( ͡ʘ╭͜ʖ╮͡ʘ)
 
Harmon's Avatar
 
Industry Role:
Join Date: Mar 2004
Posts: 20,010
This EXACTLY WHAT I HAD for the last 2 days!!!

Luckily I know how to delete this shit without waiting for a fix
__________________
[email protected]
Harmon is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-28-2005, 09:18 PM   #10
dissipate
The Dirty Frenchman
 
dissipate's Avatar
 
Industry Role:
Join Date: Nov 2005
Location: Lost Angeles
Posts: 8,904
Quote:
Originally Posted by bjjb
Its called the ON button lol If i had the money I might consider going to a Mac. My Dutch partner swears by em. He has pc's but I bet theyre in the basement or attic gathering dust and mice droppings

i <3 my mac
dissipate is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-28-2005, 09:48 PM   #11
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
i tested it last week , it installs spysheriff funny virus , easy to kill
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-28-2005, 09:53 PM   #12
Harmon
( ͡ʘ╭͜ʖ╮͡ʘ)
 
Harmon's Avatar
 
Industry Role:
Join Date: Mar 2004
Posts: 20,010
Quote:
Originally Posted by SmokeyTheBear
i tested it last week , it installs spysheriff funny virus , easy to kill
bullshit.

A) I don't believe you

B) Not easy by any means.

You just like to think you are the resident "hack" around here and people like to feed your ego for some reason. That's all I have to say about that...
__________________
[email protected]
Harmon is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-28-2005, 11:12 PM   #13
MrJackMeHoff
Confirmed User
 
Join Date: Mar 2004
Location: LOLLIPOP ISLAND =-=-=-=-=-=-=-=-=-=-= =-=-=-=-=-=-=-=-=-=-= =-=-=-=-=-=-=-=-=-=-= =-=-=-=-=-=-=-=-=-=-= =-=-=-=-=-=-=-=-=-=-= =-=-=-=-=-=-=-=-=-=-= =-=-=-=-=-=-=-=-=-=-= =-=-=-=-=-=-=-=-=-=-= =-=-=-=-=-=-=-=-=-=-= =-=-=-=-=-=-=-=-=-=-=
Posts: 4,569
it says firefox users wont have to worrry about it at least (if they know about it) ;)
__________________
MrJackMeHoff is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-28-2005, 11:50 PM   #14
eMonk
Confirmed User
 
Industry Role:
Join Date: Aug 2003
Location: Canada
Posts: 2,310
Quote:
Originally Posted by SmokeyTheBear
i tested it last week , it installs spysheriff funny virus , easy to kill
that's funny i JUST rebooted my system after cleaning this annoying spyware out of my system.
eMonk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-28-2005, 11:52 PM   #15
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,382
Quote:
Originally Posted by Harmon
bullshit.

A) I don't believe you

B) Not easy by any means.

You just like to think you are the resident "hack" around here and people like to feed your ego for some reason. That's all I have to say about that...


exactly. plus there are still a few IE6 SP2 and IE7 bugs still out that ms has ignored.
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-28-2005, 11:52 PM   #16
eMonk
Confirmed User
 
Industry Role:
Join Date: Aug 2003
Location: Canada
Posts: 2,310
this spyware got into my system after searching the net for a serial number for one of adobe's products.

http://www.google.ca/search?hl=en&q=...toshop+7&meta=
eMonk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-29-2005, 01:03 AM   #17
woj
<&(©¿©)&>
 
woj's Avatar
 
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
Quote:
Originally Posted by MrJackMeHoff
it says firefox users wont have to worrry about it at least (if they know about it) ;)
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000
Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager
Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager
woj is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-29-2005, 01:39 AM   #18
Ron Bennett
Confirmed User
 
Join Date: Oct 2003
Posts: 1,653
A copy and paste from a security forum on a security work-around ... it works, but breaks some things ... but the work-around is reversable, so it's no biggie in the longrun...

According to iDefense, Windows users can disable the rendering of WMF files using the following hack:

1. Click on the Start button on the taskbar.
2. Click on Run...
3. Type "regsvr32 /u shimgvw.dll" to disable.
4. Click ok when the change dialog appears.

iDefense notes that this workaround may interfere with certain thumbnail images loading correctly, though I have used the hack on my machine and haven't had any problems yet. The company notes that once Microsoft issues a patch, the WMF feature may be enabled again by entering the command "regsvr32 shimgvw.dll" in step three above.


Fully enabling software DEP (Data Execution Prevention) for all programs on your computer in some instances may offer sufficient protection alone negating the need for the above work-around, in particular computers that also have hardware based DEP enabled.

In short, for most people, the easiest thing to do is to temporarily disable shimgvw.dll, as explained above, until MS releases a patch - after which, the shimgvw.dll can then, at least one hopes, be re-enabled as per instructions above.

Ron
__________________
Domagon - Website Management and Domain Name Sales
Ron Bennett is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-29-2005, 01:40 AM   #19
Juicy D. Links
So Fucking Banned
 
Industry Role:
Join Date: Apr 2001
Location: N.Y. -Long Island --
Posts: 122,992
Bump

Juicy D. Links is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-29-2005, 01:48 AM   #20
Ron Bennett
Confirmed User
 
Join Date: Oct 2003
Posts: 1,653
Oh another thing ... deleting the WMF file association and/or filtering WMF files offers NO protection due to how Windows treats file extensions; could be disguised as a .gif, .jpg, etc.

In addition, WMF based exploits can execute in ways that one wouldn't expect - such as when viewed in file manager, etc; unexpected executed by various applications on one's system ... some of Google's tools can execute WMFs! This is a real nasty exploit all around.

Ron
__________________
Domagon - Website Management and Domain Name Sales
Ron Bennett is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-29-2005, 01:52 AM   #21
pornpf69
Too lazy to set a custom title
 
pornpf69's Avatar
 
Join Date: Jun 2004
Location: Brasil
Posts: 15,782
what is new about security holes and windows?
__________________
pornpf69 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-29-2005, 02:01 AM   #22
fetishblog
Confirmed User
 
Join Date: Sep 2005
Location: Your mom is my favorite pornstar!#%
Posts: 5,995
Who the fuck is still running Windows? Goddamn.
__________________

Fling.com doesn't steal your traffic and sales unlike some other dating companies. I promote them, and so should you!
fetishblog is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-29-2005, 02:04 AM   #23
reynold
Too lazy to set a custom title
 
Join Date: Oct 2002
Location: Global Traveler
Posts: 51,271
good read man, thanks for sharing.
reynold is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-29-2005, 02:19 AM   #24
MattOT
Confirmed User
 
Join Date: Nov 2005
Posts: 901
yeah i had this a few weeks ago, it did install spysheriff and locked the wallpaper to that one you can see in the link,and popups kept saying that my system was infected with skyware grr ....... i just reformatted my pc was about time to anyway
__________________
Matt

www.onlytease.com / www.onlymelanie.com / www.onlycarla.com/
Sponsor program at www.otcash.com

ICQ: 235015328
MattOT is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-29-2005, 03:36 AM   #25
The Sultan Of Smut
Confirmed User
 
The Sultan Of Smut's Avatar
 
Join Date: Dec 2004
Location: Vancouver
Posts: 4,325
Quote:
Originally Posted by Matt 26z
Yet once again a security company (Symantec) publicly announces a hole instead of going to MS behind closed doors so it can be quietly fixed.

Ironically, the security companies are the worse threat to computer security. If these threats are not made public, then hackers can't exploit them. If hackers are not exploiting them, then nobody needs to buy their security products.
Well if Symantec can find the hole why can't Microsoft? What happened to that trustworthy computing initiative crap?
The Sultan Of Smut is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-29-2005, 03:37 AM   #26
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
Quote:
Originally Posted by Harmon
bullshit.

A) I don't believe you

B) Not easy by any means.

You just like to think you are the resident "hack" around here and people like to feed your ego for some reason. That's all I have to say about that...
huh ? dont get your ego in a bunch batman. what do i think again ? huh ..

i installed it to test and removed it .. whats so hard to believe about that ? i can even tell you where its at in the wild ( besides the disclosed places )

If anyone else removed it knows it installs spysherrif , changes your desktop to some stupid error about your system being compromised

p.s. can you quote me some instance where i " think im a resident hack " ? not to rain on your parade but i'm not a "hack" dont claim to be , never did , never will.. lots of people know more than me , lots dont..

it disguises itself as winlogin to run the backend.. trust me i had it and removed it.. its not super easy but not the hardest i have come across
__________________
hatisblack at yahoo.com

Last edited by SmokeyTheBear; 12-29-2005 at 03:39 AM..
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-29-2005, 03:48 AM   #27
baddog
So Fucking Banned
 
Industry Role:
Join Date: Apr 2001
Location: the beach, SoCal
Posts: 107,089
Quote:
Originally Posted by bjjb
Its called the ON button lol If i had the money I might consider going to a Mac. My Dutch partner swears by em. He has pc's but I bet theyre in the basement or attic gathering dust and mice droppings

he has mice?
baddog is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-29-2005, 03:49 AM   #28
baddog
So Fucking Banned
 
Industry Role:
Join Date: Apr 2001
Location: the beach, SoCal
Posts: 107,089
Quote:
Originally Posted by Harmon
This EXACTLY WHAT I HAD for the last 2 days!!!

Luckily I know how to delete this shit without waiting for a fix

We need to talk please.
baddog is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.