Microsoft Discloses Security Flaws in XP and WMPlayer
An anonymous reader writes: "Salon is running a story on Microsoft's disclosure of a number of security flaws in WinXP and Windows Media Player, versions 6.4 and 7.1. The story also states that there are 2 critical vulnerabilities in Commerce Server 2000. Will I ever get the bang for my MS buck?"
After seeing holes in OpenBSD and Apache recently, I guess it's Microsoft's turn again. ;)
The article implies that these vunerabilities haven't been patched. Funnily enough, I downloaded the patches from Windows Update last night, thanks to XP's auto-update feature.
Every Operating System and application has bugs. If there were security bugs in Linux or Freeamp, would it warrant front page news?
Not wishing to be Flamebaity at all. MS have a lot of things severely wrong with them. For once they've dealt with an issue in timely fashion. This is not the Anti-MS rhetoric you're looking for.
"Why did they cancel my favorite Sci-Fi show? I downloaded ALL the episodes!"
Nearly 6 Months and only #ERROR# root exploits in the default install...
"Will I ever get the bang for my MS buck?"
If they don't treat you right the first time, buy buy again.
http://www.microsoft.com/technet/treeview/default. asp?url=/technet/security/bulletin/MS02-032.asp
Would it have killed ya to post this as well Timmy? =P
This is most certainly not the way to get microsoft to donate $750 million to them.
Everything will be taken away from you.
If only real player didn't tank out a few years back (my window stills says it's buffering) and if quicktime was widely supported, this wouldn't even be an issue. Everyone seems to get forced into supporting the windows option for lack of a better option (and i'm talking about the masses here). i know all the linux buffs here can point out a million other options on a non-windows OS, but that's not gonna help my friends mother, who needs to read the instructions written on the sticky pad about how to check her yahoo mail.
my last sig was too controversial... now, a new and improved useless sig!
INT, STORE, NIGHT. CUSTOMER walks into a near empty store, he steps through the doors cautiously, peering around curious as to where the hell the clerks are.
Customer: Hello..? uh... hello...? I want ta get a copy of Windows XP. Is anybody here?
CLERK, unseen: Is it safe?
Customer: Is what safe?
Clerk: Is it safe?
Customer, preturbed: Yes... It's safe. It's very safe...
Clerk: Is it safe?
Customer: Lissen! Are you going to come out, or what?
Clerk: Is it safe?
Customer: THIS ISN'T FUNNY!
Clerk 2: It puts the lotion on its skin and puts it in the basket.
Clerk: Shut up man. Is it safe? Is it safe? IS IT SAFE?
Customer: STOP IT! I JUST WANT A COPY OF WINDOWS XP! (Customer breaks down to the floor, sobbing) I just want a copy of XP...
Clerk: Is it safe?
Customer screams and runs out of the store, climbs into his car, which immediatley spins out and slams into a fire hydrant. The car bursts into flame. The customer bails from the car and runs down the darkened, abandoned street. He gets a half dozen steps from the car, and then he, illogically and without reason, bursts into flame himself.
Clerk 1: Thirty seconds, You owe me five bucks.
Clerk 2: I don't have five bucks.
Clerk 1: Take it from the register.
On-topic discussion part.
THEY TOLD ME IT WAS SAFE! I TRUSTED YOU MICROSOFT! I TRUSTED YOOOOOOOOOOOOOOU! YOU BLEW IT UP, YOU MANIACS YOU BLEW IT UP!
"PokeySteve, are you drunk?"
"Yes, but on love.
And whisky.
But mainly whisky."
Why is it when I hit ^R that ZSH calls me a cocksucker?
You may laugh, but xmms is often installed suid so it can up it's priority. :)
Additionally it's GL spectrum analyser has frozen my system on occasions.
I don't think XMMS has had any remotely activatable flaws though.
-Yarn - Rio Karma: Excellent
Microsoft has also anounced that this is to be the last free patch. All subsequent security patches will be available only to registered users at $14.95 per user licence. Very fair price, after all you can't have programmers working for nothing, that would be unamerican.
Most software is expected to have bugs. But when it comes to OS great care should be taken into removing these, especially those involving security. But bug tracking is an art form. You can never remove bugs 100% as the difficulty in finding the bug increases dramatically as you approach 100%.
When it comes to software like the media player, this is much more serious. This goes into much more than just one single OS. I run Win95, Win98 and Win2000, and all these may be affected. On top of that the media player keep posting me to update the software. Wouldn't it be nice if the system gave me the option to update to the most stable and secure version or the latest version? You might think I have that option, as I may choose not to download the latest, but make my way through the download jungle to find an earlier version. But this jungle is impossible to move through for ordinary people.
I understand that Microsoft wait with disclosure of the bug until they have a patch. This is often criticized, but in some cases it make sense.
-:) Oh no - not again.
www.rednebula.com
...don't the Linux vendors (especially IBM) flog this issue for all it's worth? I really think this is where the fight for market share should be.
However, the fact that it isn't makes me think that the vendors aren't entirely confident with the Linux security offer.
Perhaps it's too technical - there are plenty of security patches for GNU/GPL/Linux - I use that title advisedly, as they are rarely in the kernel (at least one a week AFAICS) - but they are generally on a faster turnaround than MS. But it's still not brilliant....hmmmm. Must think about this some more.
Funny, a few days ago, i was having to do the ole ./configure , make , make install with openssh 3.4. Tonight i had to hit windowsupdate and grab the various fixes (flame away, i run win xp pro on my desktop, but at least i redeem myself by running my backup, dns, and dhcp on redhat 7.3). Any OS can have bugs and issues. But i still much prefer linux/open source for stuff that needs security. I patch my linux box a LOT less often then i have to run windows update. And i dont have to reboot my damn linux box every time i update samba or openssh or bind.
Lawyers, MBA's, RIAA? A jedi fears not these things!
Umm...I think you've just been banged for your MS buck. :)
"In mathematics, it's not enough to read the words -- you have to hear the music"
Will I ever get the bang for my MS buck?
I don't know about you, but I've paid $0 in my lifetime for MS software, so you could say I've gotten at least my share of bang. But I wouldn't say that. I'd say that MS owes me for forcing their way into an OS monopoly, therefore forcing me to use their Piece of Crap in order to use lots of apps I want to use (ie, games).
Love and kisses,
Jeff
Property is theft.
Maybe Cringley's right ...
Given the revenue stream of say Win-XP compared to that of commercial Linux distributions, I am very surprised that MS still makes code with so many holes. If XP ius too big for MS to manage the development and support, then they should simplify it.
Will I ever get the bang for my MS buck?
Oh please, when was the last time you actually bought a microsoft product?
I know I'm going to hell, I'm just trying to get good seats.
now if they only allowed us poor windoze users to remove wmp in the first place, but no, it's a part of the os now
Remember: If you buy anything from spammers, you have a small penis.
--
Seeing is believing; You wouldn't have seen it if you didn't believe it.
You may laugh, but xmms is often installed suid so it can up it's priority. :)
Additionally it's GL spectrum analyser has frozen my system on occasions.
GL SA frozed yer system only because your OGL implementation is written out of someones ass. GL SA doesn't run as root, OGL implementation (parts) are. So go and blame someone else.
And yes, I know what I'm talking about, I wrote an XMMS visual plugin myself, it has never been able to freeze my system, It uses SDL, which is sane.
fucktard is a tenderhearted description
After a week in which I spent hours remotely updating apache and openssh on my colocated boxes, it's hard to get worked up about another Microsoft patch.
"Why on earth would there be a bug in Media player that allows uncontrolled access to the system. What we have here folks is a very good example of what a horribly designed OS Windows is..."
Why on earth would there be a bug in OpenSSH/Sendmail/Apache/BitchX that allows uncontrolled access to the system. What we have here folks is a very good example of a troll posting before it thinks, going with the crowd in its 'M$ sucks! Linux rules! Muahahha' mindset.
Software has bugs. Sometimes exploitation of those bugs, if they're severe enough, can allow an attacker to run code on the target system. This is not a flaw unique to Windows.
Please, think before you post.
Janie took my gun...
Digital Rights Management (Security). You agree that in order to protect the integrity of content and software protected by digital rights management ("Secure Content"), Microsoft may provide security related updates to the OS Components that will be automatically downloaded onto your computer. These security related updates may disable your ability to copy and/or play Secure Content and use other software on your computer. If we provide such a security update, we will use reasonable efforts to post notices on a web site explaining the update.
Security update? Who's security are they protecting? There is no option to uninstall media player. Your choices (if you wish to continue using Windows) areA: Leave your system open to bugs that give system level access to the next worm (imagine nimda with a malicious /default.htm)
B: Bite the bullet and install the patches. But if Microsoft releases an update that silently and without notification installs itself and 'disable(s) your ability to ... use other software', you're SOL. But hey, it's ok. Don't you know Microsoft is supporting 'Trustworthy Computing'?
"Will I ever get the bang for my MS buck?"
No
If something is so important that you feel the need to post it on the internet... It probably isn't that important.
Actually, it's the other way around. There is/was a bug in XFree86 that makes it crash when requested a redicoulously large font size by Mozilla (or anything else).
Make even shorter URLs - 8LN.org
M$ announces bug. Everybody required to download a critical update...
What's the bug?
DRM doesn't work... turns out you can hear copyrighted MP3s. This is a big security vulnerability and you mush download this patch, otherwise the finanical security of the RIAA will be at stake, and that's unamerican.
[Note: This is intended as a joke and as food for thought. This is not fact.]
Make even shorter URLs - 8LN.org
This morning windows updater had already downloaded the patches, all I had to do was confirm the installation.
People can whine all they want about that there are security flaws and ofcourse it's sad these still pop up, but the patches are there, the system to install them is VERY easy (just click one single button) so in the end, the end-user is not that much hurt by them, simply because the patches are installed so easily.
The discussions about 'security flaw free' software are endless and allthough they should be held, are nowhere near consensus: as long as there are humans involved in hammering out code and as long as the computer/software based checkinglogic is not up to par as where it should be, these flaws WILL be there, possibly in every tool written by man. Until computer science reaches the point where a compiler can proof that software is security flaw free, we should be grateful that the FIXES for security flaws are installed using the most easiest way: by simply clicking one single button.
Never underestimate the relief of true separation of Religion and State.
i'm waiting for someone to do a dns hijack of update.microsost.com and load a
nice new trojan on everyone's box that their av software doesn't detect. if
these morons were serious about security, they'd use ssh, not http, for
updates (and let you turn off html rendering in your email client).
thank God the internet isn't a human right.
Sounds like your friend needs to take that sticky pad and write a script. Then create a big icon for the script and call it "Get Yahoo Mail, Click Here".
I have no idea if that can be done in windows. I know that it can be done with most, if not all, Linux desktop enviroments.
Linux on the desktop does not need to be "difficult". Linux remains the better option over Windows, you just have to get over being lazy. The bad news is you have to learn something new. The good news is you're gonna learn something new, and it's going to work.
So what if your friends mom can't/won't write scritps to automate her computing tasks. You do it for her for a fee (even if it's just chocolate chip cookies). You set up a Linux desktop for her once. Give her one button access to the things she wants to do and she'll be out of your hair. She damn sure won't be calling you to come fix her computer because of the daily BSOD.
. Quit playing Monopoly with Bill. Switch to one of many non-Microsoft products today.
I sent them this:-
I know what BSA fears most,
It's the possibility that the communists have built up a huge arsenal of
keygens (before thecrack.net went down a couple of weeks ago.) and they
are planning to release a worm that generates everyone a new random
license, making it impossible to tell which software is pirated and which
is not. This will of course be the end on the BSA, probably through the
madness of running round in circles if nothing else.
But don't tell them I know these things, or I might gave a knock on the
door tomorrow asking why I have no licence for my Linux boxen.
thank God the internet isn't a human right.
From http://www.microsoft.com/technet/treeview/default
Never confuse volume with power.
Well, the entire point that windows servers are expected to be protected entirely by a non-Windows system to be secure says something right there. They ship with bugs that result in security issues, which is ok since they offer patches, but the issue is the same one that most linux distros had until recently, leaving things too wide open by default, in the name of making it easier to use them, whether you want to or not. Windows Media Player does not necessarily belong on a Server or a restricted professional workstation, but there it is, happily ready to be exploited to allow a normal user to escalate privs.
/etc/exports, smb.conf, and/or swat. Admittedly not as easy as Windows, but still....
Anyway, what you say about ease of use has a grain of truth in it, but the situation is not nearly so drastic. Connecting to a network is trivial under either OS, and takes about the same time, either through command line or gui utilities offered by Mandrake and RedHat. Installing binary software typically takes less time under package managed systems than it does under Windows, same for uninstall. I don't see how rpm -i is harder than setup, you can even click on an icon and install it, unlike downloading most zips from the internet where you unpack, then hunt down setup to run.
Now stuff like sharing files currently does take a bit longer typically (of course providing that the user installed File and Print Sharing, otherwise they get stumped under Windows too), since the file managers typically do not offer shortcuts to samba/nfs sharing configuration, but RedHat and Mandrake again provide 'wizards' to set this stuff up if you can't deal with
The bottom line is that thanks to projects like KDE and Gnome (though 2.0 seems to be a step backward in usability to me, it's like Sun's usability input screwed things up) and companies like Mandrake and RedHat, Linux distributions are becoming easier to use constantly, while distributions like gentoo and debian exist for the power users, and they all are mostly binary compatible, and completely source compatible, so it is a great deal more variety of choice than say 'Home', Professional, Server, etc... Which are all basically the same thing with a few extra things tossed in at every level, with nothing ever removed nor more power given over the system to more advanced users.
XML is like violence. If it doesn't solve the problem, use more.
One thing that's always bugged me about these kinds of updates? What do you do if the machines don't have internet access? I know that that invalidates most of the vulnerabilities (except inside the lan), but what happens someday in the future when the machine finally goes online and tries to download 3000 security updates?
Maybe vendors should have to release these updates on CD as well.
NOTE: I'm not focusing on MS here, other vendors should be asked to do the same.
t'nera semordnilap
Since no one else has answered:
The bug is really only a technical one. In practice, it's really like that "Perrun" hoax virus, in that it requires a huge amount of setup and complete access to the system in order to gain... well, to gain complete access to the system, which an attack would already need in order to use this bug maliciously. Basically, Windows Media Player can remotely open up the system if the attacker has found a way to get a malicious executable file into IE's cache and then convinces their victim to go to a maliciously constructed website that they've setup. When the victim goes to the maliciously constructed website, Windows Media Player could then give out information that could be used to get into the system through the IE cache.
The problem lies in the specific executable file that has to be placed into the cache. In order to get the executable file into the cache, the attacker would have to have full access to the machine or trick the user into accepting it and running it. But if they could get the user to do that, they would have full control of the system anyway, just like they would if the victim was running any OS other than Windows.
So really, it's just a small, stupid bug that's being blown out of proportion. It can't do anything other than redundantly take over a computer after it has already been taken over in a different way.
Will I ever get the bang for my MS buck?
Timothy, you do every day. What would /. be without the daily "M$ sucks! Lets all post about how horrible M$ is!" story to increase those page loads?
Why, /. might actually have to talk about things of interest to geeks!
"Seven Deadly Sins? I thought it was a to-do list!"
I also think the article forgot to mention you can install Critical Update Notification in Windows 98/ME/2000/XP that automatically flags you about security and other important updates whenever you log onto the Internet.
Yes, but it's no different from similar cases in other operating systems. Buffer overflows happen in both Windows and Linux, and in both cases they can allow the mallicious data to execute arbitrary machine code as the current user. In both systems, this is usually sufficient to cause severe damage.
"Think before YOU post--you clearly demonstrate the common mindset of finding someone with an exposed problem and attacking it like a shark in order for a much needed ego-boost."
Yes, except that you don't appear to have the slightest clue as to what you're talking about. Anyone who's done more than a cursory look at computer security and exploits would be aware as to how prevalent buffer overflows are. It's not a problem specific to any type of program.
So I just don't see where XP even comes into the picture. You made an absurd, hand-waving claim, someone called bullshit on you, and now you're going on a tirade about how it's this vicious shark attack.
Oh, and you threaded your post incorrectly, as your reply seems to be targetted specifically at Zeddicus_Z, but you replied to your own post.
I think it was supposed to read "Re:So who actually read the technical rite up...front"
>Perhaps it's too technical
*Exactly*.
In a world where we cannot convince people that MHz don't matter, and people believe that security is a product, attempting to convince them of the security issues with MS will prove fruitless.
MS will just release statistics and compare their OS with the number of security holes found in OS + Applications and people will believe it to show that Linux is less secure. They will turn up their marketing engines and hype that Open Source means Lower Security and people will believe it.
True Story: I was attempting to convince a certified MS XP technician that MS didn't understand security. Keep in mind this is someone deep within the ranks of the Microsoft Heresy (like the Cainite Heresy, but more Hideously Evil(TM)).
I cited Scheiner, cDc, L0pht, and a half-a-dozen others. I talked about how open source was a good thing, the reply I got back can be summarized:
1) Security is a product ("A firewall will make you secure")
2) He thought the only reason you would want to secure your system was to keep people from browsing the pr0n there (and seeing the other files).
3) The threat level is minimal--no one would want to break into *your* system.
4) Believing that security was a real issue was like believing everything anyone told you (down to "three headed big foots in Utah").
Of course this is absolutely absurd, but thats what he believed. While you may not be able to sell the general public on all of that, it gives an impression on how MS treats security and how their marketing department would convince their users to treat it.
Sad, but true.
Integrate Keynote and LaTeX
Unfortunately, I want to exploit the applications on my machine. I could just buy a pocket calculator and get rid of my computer - that would be secure too.
If security is paramount, to exclusion of all else,
Which it never is. If security is paramount to the exclusion of all else you simply leve the computer switched off.
I'm computing in the real world, you are clearly computing in the MacWorld.
TWW
"Encyclopedia" is to "Wikipedia" what "Library" is to "Some people at a bus stop"
GreyWolf3000 wrote:
> Why on earth would there be a bug in Media player
> that allows uncontrolled access to the system.
> What we have here folks is a very good example of
> what a horribly designed OS Windows is...
XP isn't Palladium (yet), but it is a/the DRM OS. Microsoft's Media player is like a trap door that leads down to the core of the system. In the center of the OS, behind that trapdoor, sits a huge spider called DRM. Every file loaded, whether a document or media file, an application, or a driver, has to pass DRM's inspection. DRM checks to see that those documents and media files are legally licensed, and those drivers and applications are approved by Microsoft (don't want any of that cancerous GNU goop around). Anything that smells even slightly fishy to DRM gets pounced on and eaten. Anything that passes muster, gets passed on to the OS and applications for use.
In unix-speak, that DRM spider would be the god of root, able to tell even root what they can and cannot do. If you try to work around DRM and do what you want with the idiot box you paid for, DRM calls on his old bud DMCA, and DMCA sends the nice folks from the FBI to cart you and your PC off to separate jail cells.
Since everything the media player plays goes through DRM, it is easy to see how a media player bug could affect the whole system. And since DRM is relatively new, it will have bugs itself. And since DRM is potentially updated everytime you download a song (check your XP EULA), the potential for disaster is high. Yes it is horrible design. Then again, DRM is a horrible concept.
That's the price one pays for doing business with a company that treats their customers like potential criminals. The ironic thing is that Microsoft is the one convicted of breaking the law.
What happens when you embrace and extend Godzilla? Nuclear heartburn!
See "Godzilla 2000" (released in Japan as "Godzilla 2000 Millenium") for details.
and their repeated use of backward IN-compatibility to force people to upgrade or lose access to their old data, this phrase from "Cringely's Pulpit" scared the fuckin' crap out of me: "then encrypting the data EVEN INSIDE YOUR COMPUTER PROCESSOR."
... I'm a loss to find words to describe the enormity of the evil.
Its the ultimate in Big Brother technology. The eradication of memory or of access to memory.
Ever seen people with disorders of the hipo-thalamus? They can't form short term memories. Their lives are hard and extremely confusing since the world is a new mystery every damn day. They are extremely vulnerable to being scammed from one minute to the next.
Whoever proposed this inside of M$ is an absolute diabolical monster. A human being (given the events of the last two centuries and the incredible slaughter perpetrated on each other, that is NOT a compliment,) with delusions of god-hood. One that looks bad even compared with the most the megalomaniacal tyrant to slaughter people in order to change their minds about something.
At least when you kill people, you're show for the sub-simian scum you are and/but your victims a're well and truly safe from further predation.
But this deliberate creation of the potential for maiming of the aggregate memory of an entire culture makes the death camps is so utterly base, so vile, so despicable, so
And M$ will find enough "Judas Goats," enough imbeciles to plunge mankind into a second dark ages. Would that the road to the coming Hell was not paved with moot intentions and banal disregard.
Slavering drooling monsters and utter despicable despots, we can overthrow. But our doom will come in the form of some utterly reasonable man in a suit who's just doing his job.
There are a hundred million graves prematurely filled by the victims of some utterly reasonable men in some (uni)form of suit, who's just doing his job.
The ultimate triumph of Voltaire's bastards will be even more thorough and degrading than the patrician nightmare of the religious maniacs who merely preach evil and bring subjugation and death.
MSBPodcast.com The opinions expressed here are my own. If you don't like 'em... Think up your own stuff.
A bug always seems small and stupid until someone finds a way to easily exploit it. The recent Apache bug is a great example. At first announced as unexploitable on non-Windows 32 bit systems, some freak had a ready-to-run root exploit for it in less than 3 days. The process of locating a security issue and the subsequent process of developing an exploit for it are two different processes and two different disciplines.
maru
This is true, NVidia drivers, but a lot of people use them.
-Yarn - Rio Karma: Excellent
Why do we stand for this?
Why do you, whoever you happen to be, stand for this?
The only way this can truly change is through market intervention: legal solutions will be iffy and likely do more harm than good; internal forces certainly won't cut it; and petitioning is useless.
Support Apple, Support Linux, Support OpenBSD, but don't support Microsoft!
Integrate Keynote and LaTeX
Software has bugs. Sometimes exploitation of those bugs, if they're severe enough, can allow an attacker to run code on the target system. This is not a flaw unique to Windows.
OpenBSD has bugs.
Microsoft Windows has bugs.
One remote hole in the default install, in nearly 6 years.
Exploit of the week, with things like gopher holes never closed.
The email was from Thomas Greene of The register fame.
So I better give him the credit.
thank God the internet isn't a human right.
The problem lies in the specific executable file that has to be placed into the cache.
Not a problem. The system will dump ANYTHING it is given into the cache. Take a virus.exe file and rename it to banner.jpg or something. The browser drops it in the cache with a randomized the name and sub-folder. Since it's not actually a jpg or whatever it may be silently ignored. If an attacker can discover the randomized name and location in the cache he can tell the OS to run it as an EXE. It isn't simple, but all the required steps HAVE been worked out and are available on the net.
So no, this is not "a small, stupid bug that's being blown out of proportion".
-
- - You can't take something off the Internet! That's like trying to take pee out of a swimming pool.
Will I ever get the bang for my MS buck?
Just remember, YOU'RE the bang-ee.
--
"Outlook not so good." That magic 8-ball knows everything! I'll ask about Exchange Server next.
Look at that EULA again:
These security related updates may disable your ability to copy and/or play Secure Content and use other software on your computer.
WinAmp is one of those "other software on your computer" which may be disabled. Duh.
Essentially, this is a backfit of their XP license and DRM technology for the 60% of WinSlaves that are using Win98.
Given that Windows Security is an oxmoron, there's no reason to "upgrade" your computer this way. Outlook, IE or some stupid piece of junk like a plug and play deamon that you never knew listened to the network will eat you anyway.
If you just must have M$ in your house, blind it to the network by NOT installing the network card drivers or pointing it to a bogus gateway IP number. Never use it to surf, read email or anything else that M$ will never do right. I admit that I have such a beast in the corner for talking to cameras and an old scanner. It's legal and I own it. But I'll never ever trust it. Red Hat's dual boot (GRUB) let's me get the information off of it.
DMCA, Hollings, Palladium. What might have sounded like paranoia is now common sense.