Slashdot Mirror


DirectX Flaw Leaves Windows Vulnerable

cryonic*angel writes "Just when you thought it was safe to start buying music from BuyMusic, another another Windows security flaw is found, in DirectX this time, that basically affects every possible windows configuration that is still supported. I wonder, will they indemnify me for this?"

97 of 530 comments (clear)

  1. patch me up baby! by Neophytus · · Score: 5, Informative

    Direct download for 9.0b (not for nt4.0). Strangely it isn't on the main directx page yet considering the critical nature of the problem. Here is the technet article with patches for existing directx versions.

    1. Re:patch me up baby! by Krilomir · · Score: 3, Interesting

      I'm quite sure there is a patch up already on windows update. My computer was patched just hours ago. I really don't see anything special about this story. What's so special about this flaw?

    2. Re:patch me up baby! by GammaTau · · Score: 5, Funny

      Well, you know what they say about downloading and applying Windows patches...

      "They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety."

    3. Re:patch me up baby! by BigBir3d · · Score: 4, Informative

      9.0b has been available since Wednesday 7/23, that I know of. That is when I had to manually update the dozen or so machines in my office.

    4. Re:patch me up baby! by Chester+K · · Score: 5, Funny

      I'm quite sure there is a patch up already on windows update. My computer was patched just hours ago. I really don't see anything special about this story. What's so special about this flaw?

      It's a Microsoft bug, it doesn't matter how important it is. You're supposed to be foaming at the mouth and making sweeping statements about how this proves open source is better! Don't you know what website you're on?

      --

      NO CARRIER
    5. Re:patch me up baby! by Knightmare · · Score: 5, Insightful

      I can't decide if this is a troll or not. How is this a big vulnerability? Well, take a second and think how easy it is to be exposed to a midi file compared to an executable in an email or a malformed packet on one of Windows many default listening ports.

      Newer versions of outlook and many mail servers can block .exe,.src,.com,etc... extensions from ever making it to your double click happy hand.

      A $35 personal firewall from your local computer store can protect you from port based attacks.

      But when was the last time you saw security software/hardware that blocked midi files? An exploit of this in the wild would mean any webpage, any HTML email, any midi file download would be an attack vector. How is this a small problem?

    6. Re:patch me up baby! by Realistic_Dragon · · Score: 4, Funny
      Don't you know what website you're on?

      Microsoft Security Bulletin MS03-035

      Flaw in Internet Explorer Could Cause Website Name Not To Appear (823803)

      Originally posted: July 23, 2003

      Summary

      Who should read this bulletin: All users of Microsoft® Windows®

      Impact of vulnerability: User may become disorientated on the internet

      Maximum Severity Rating: Moderate

      Recommendation: Administrators of Windows computers should consider applying the update patch.

      Affected Software:

      * Microsoft Windows NT 4.0 Server

      * Microsoft Windows NT 4.0 Terminal Server Edition

      * Microsoft Windows 2000

      * Microsoft Windows XP

      * Microsoft Windows Server 2003

      Technical details

      Technical description:

      A flaw exists in all versions of Internet Explorer that could cause the name of the website being visited not to be displayed.
      --
      Beep beep.
    7. Re:patch me up baby! by Entropius · · Score: 5, Insightful

      While /. has been known to indulge in a little over-the-top microsoft bashing when bugs like these come out, there's a reason they (especially ones like this) make the front page.

      Windows has a huge installed base, and windows machines tend to be targeted by kiddies looking for DDoS zombies.

      And of course this is a big bug. Run arbitrary code through a midi file? That's huge, and deserves to be on the front page. Apache security holes of much less import make the front page, and they probably belong there too.

    8. Re:patch me up baby! by FatherOfONe · · Score: 5, Funny

      Man how true it is. I can't believe all the people here that bash Microsoft for their apparent lack of security. I mean whats the problem with checking for patches for your server every hour or so? Even if some of the patches are so bad they crash apps on your server and prevent others from starting. I mean, what is the big deal?

      Hang on a second... it has been 30 seconds since I last checked Microsoft for another security update...

      Ok, I now have another 90MB file I need to apply to the 200 NT boxes I have.... Like I was saying what the heck is the big deal? So what that most vendors release stuff on NT boxes that requires certain service packs, and won't work with others? Yeah this makes server consoldation impossible but who really cares? It isn't that big of a deal, just buy another box. Heck we plan on buying another hundred or so this year.

      Hang on a second it has been another 5 min since my last check at Microsoft for another update...

      Wow only two new updates! This is a first! Now, as I was saying, these open source "Quality is important" types are just zealots. They just don't understand that it isn't that big of a deal to support Windows.

      Sorry, hang on a second... a new Worm just hit or email server...

      Now where was I? Oh yeah, the advantages of running Windows... You have one consistant platform. Well we will when we finally get our 200 NT boxes upgraded to Win2k server. Dag gone it, I have to go and talk to our Microsoft rep again... be back in 15 min...

      Ok I just found out that Windows 2003 server is out now and EVERYONE is going to it. The nice thing is that Microsoft will let us keep running our Win2k servers until the end of the year! Yeah I would like to see what you open source people say about that! See Microsoft isn't bad at all. They even told us that we could run 2003 Server for a full 3 years! Man that will make life great!

      So let all the bitching begin about Microsoft over one SMALL bug! They just don't know what they are talking about...

      --
      The more I learn about science, the more my faith in God increases.
    9. Re:patch me up baby! by ssimpson · · Score: 5, Insightful

      What's so special about this flaw?

      Are you brainwashed by how many flaws like this we see? This allows a malicious adversary to craft a web page (for IE) or e-mail (for OE / Outlook) that would allow the adversary to execute arbitrary programs in that users context.

      The point isn't that an update is out already, it's that there will remain god knows how many tens of millions of computer vulnerable to this flaw for a long time. Not only will those machines be hacked and taken down, but someone will most likely produce and exploit that turns the machines into a DDoS client, or an SMTP relay for spam, or...You get the idea. In the end it pisses over the rest of the Internet community.

      And it's all thanks to shite security engineering in MS and non-conformance to standards (the MIDI playing is caused by a non-W3c HTML tag "BGSOUND").

      --
      "Mary had a crypto key, she kept it in escrow, and everything that Mary said, the Feds were sure to know."
    10. Re:patch me up baby! by drunk_as_in_beer · · Score: 5, Funny

      What's so special about this flaw?

      What's so special is you actually *don't* have to reboot after applying the patch.

      --
      --Drunk as in Beer
    11. Re:patch me up baby! by FroMan · · Score: 2, Insightful

      Where do you work that you get to play games?

      Or is there some other purpose for DX?

      --
      Norris/Palin 2012
      Fact: We deserve leaders who can kick your ass and field dress your carcass.
    12. Re:patch me up baby! by ncc74656 · · Score: 2, Informative
      A big flaw with windows update is that you have to get the whone 11mb per computer.

      Put an HTTP proxy server between your LAN and the Internet. The first download will take a while, but your proxy should cache it so that subsequent downloads on other systems on your LAN will be much faster.

      --
      20 January 2017: the End of an Error.
    13. Re:patch me up baby! by ClippyHater · · Score: 2, Insightful

      Don't be so sure. Think of the millions of Windows users launching executables from an e-mail they got. Now think of them clicking on a link to a webpage containing the exploit (of course they only see the "See my hot new photos" link in outlook). Page loads up, and that's all she wrote.

      I really can see this being a HUGE problem for millions.

    14. Re:patch me up baby! by JanusFury · · Score: 2, Informative

      And it's all thanks to shite security engineering in MS and non-conformance to standards (the MIDI playing is caused by a non-W3c HTML tag "BGSOUND").

      I don't see how BGSOUND has anything to do with this. You can play MIDIs in webpages without that tag. The OBJECT tag, for example... or an embedded media player control... or a regular old link.

      --
      using namespace slashdot;
      troll::post();
    15. Re:patch me up baby! by ssimpson · · Score: 2, Informative

      Regular old links need the users to click on a link whereas BGSOUND doesn't require user interaction. Not sure if Object tag / embedded media player can embed in the same way for Outlook / OE based e-mails (I would hope that the users get some kind of prompt, but knowing MS...).

      --
      "Mary had a crypto key, she kept it in escrow, and everything that Mary said, the Feds were sure to know."
    16. Re:patch me up baby! by more+fool+you · · Score: 2, Insightful

      sounds good in theory. in practice it's a little unreasonable to have to set maximum_object_size to well over 50MB (IE 6 SP anyone?)

  2. Tough one... by WD_40 · · Score: 5, Funny

    Let's see, pay for music and get F'ed... download for free and be fine (as long as you don't share).

    --

    "With sufficient thrust, pigs fly just fine." -- RFC 1925

    1. Re:Tough one... by Latent+IT · · Score: 5, Insightful

      Let's see, pay for music and get F'ed... download for free and be fine (as long as you don't share).

      So, let me see if I have this right - you think that files off a pay-for-music download site are more likely to be infected vs. files on Kazaa?

      Seriously?

    2. Re:Tough one... by jmorris42 · · Score: 4, Insightful

      Unless you running Linux, then make sure you have the latest mpg123 (and libmpg123, which powers xmms) or one of those mp3 files could be evil and 0wn3z your ass.

      Nobody is 100% safe these days. I used to be confident and tell people to 'hit me with their best shot' because I wouldn't be running untrusted executables and data files couldn't carry nasties. Now we have mpg123 and in the past we had a buffer overflow in libtiff. Pine could get you owned with a bogus header once. Sendmail of course has been a security nightmare.

      Yes *NIX is safer, sendmail in it's worst year never matched the horrors of Outlook, but never feel safe. Which sucks major ass because we shouldn't have to just accept as a given that the only safe computing is a sealed box with no external media or network connection. Personally I'd like to see a whole year set aside to making software SAFE instead of adding features.

      --
      Democrat delenda est
    3. Re:Tough one... by dimer0 · · Score: 4, Funny

      So, let me see if I have this right - you think that files off a pay-for-music download site are more likely to be infected vs. files on Kazaa?

      For those of us who are running Mozilla and not IE, etc, buymusic.com's home page has a quite amusing message:

      ---

      Thank you for visiting BuyMusic.com.

      In order to take full advantage of BuyMusic.com's offerings you must be on a Windows Operating System using Internet Explorer version 5.0 or higher.

      --- /That's/ the point the poster was making.

    4. Re:Tough one... by Quarters · · Score: 2, Funny

      If you're paying someone so you can download craptastic MIDI files then this security flaw is the least of your problems.

  3. Received the Update Notification and Fixed by NoCoward · · Score: 4, Insightful

    My Win2k solution already downloaded and installed the update last night automatically via WindowsUpdate.com. Nice system.

    1. Re:Received the Update Notification and Fixed by FrostedWheat · · Score: 4, Funny

      My Win2k solution

      If that was the solution, what the heck was the problem?!

    2. Re:Received the Update Notification and Fixed by Radon+Knight · · Score: 3, Funny

      >>My Win2k solution

      >If that was the solution, what the heck was the problem?!

      His computer wouldn't stop working properly.

    3. Re:Received the Update Notification and Fixed by isorox · · Score: 2, Insightful

      Yes, nice system, but why is this unusual enough to be modded up? I'd guess any OS worth its salt would have the option of auto-updating with the latest security patches. My laptop does when I connect to the internet via a network, my desktop does it every few hours, and I can alway mannually apt-get update && apt-get upgrade

  4. Microsoft software has security flaw... what's new by advocate_one · · Score: 5, Funny

    move along now folks... nothing new here...
    mind you... the particular buffer overflow is unusual...MIDI files... who'd have thought???

    --
    Donald 'Duck' Dunn: We had a band powerful enough to turn goat piss into gasoline.
  5. ...So? by Jonsey · · Score: 2, Interesting

    So what you're saying is Windows, without proper patches & updating us unsecure?

    Sounds like every other OS out there! : )

    Nah, thanks for calling attention to this, I'm going to be patching my clients to 9.0b tonight.

    --
    I assert that my comment is only my opinion, not that of any employer, past, present or future.
  6. logged in by dirvish · · Score: 2, Informative

    If I remember/understand correctly someone has to be logged onto the machine to take advantage of this exploit. If they are allready logged on they could do lots of other stuff anyways? Hmmmm...doesn't sound too serious.

    1. Re:logged in by spydir31 · · Score: 5, Informative

      Wrong, all you need is that someone view a webpage with the following tag
      <BGSOUND SRC="exploit.MID" >
      (assume the file exists :)
      IE plays these by default.

  7. Huh? BuyMusic? by mhore · · Score: 3, Insightful

    From what I read, the exploit comes in the form of a weird MIDI file. Are you buying MIDI files from BuyMusic, or...?

    Mike.

    --

    Mmmm......sacrelicious.

    1. Re:Huh? BuyMusic? by MachineShedFred · · Score: 3, Funny

      Yeah, that's the track that only costs $0.79

      --
      Slashdot still doesnâ(TM)t support Unicode after it was added to the HTML standard in 1997.
  8. Re:Windows ... by iapetus · · Score: 5, Interesting

    I'd like to. Could you recommend an alternative operating system that hasn't had a single security problem in a year, and has been adding new functionality over that period?

    --
    ++ Say to Elrond "Hello.".
    Elrond says "No.". Elrond gives you some lunch.
  9. Hmmm... by chrisgeleven · · Score: 5, Funny

    Only every single supported version of Windows has this flaw? Thank God, I thought I was in trouble here.

  10. Wha... by mgcsinc · · Score: 5, Informative

    ""They'd have to come up with some way to get the user to click on that file," said Stephen Toulouse of Microsoft's Security Response Center, noting that default security settings in recent versions of Microsoft Outlook e-mail software and the Internet Explorer Web browser prevent automatic launching of such files. " Last I checked, as annoying as the feature is, the ability to have IE play MIDI files autonomyously is still there; a friend sent a link to me last night with a lovely display of world architecture and sappy MIDI music playing in the background... This is not a matter of downloading, not a matter of clicking, MIDI files have always been thought harmless, and its that feeling of complacency which threatens to make this dangerous for common users...

    1. Re:Wha... by chill · · Score: 4, Interesting

      Last I checked, as annoying as the feature is, the ability to have IE play MIDI files autonomyously is still there; a friend sent a link to me last night with a lovely display of world architecture and sappy MIDI music playing in the background...

      That's the kicker. I know a LOT of sites that do this. A couple of financial services sites I frequent have Registered Reps that seem to think a MIDI that runs in the background lends "ambiance" or some such to their site. They INSIST on it.

      --
      Learning HOW to think is more important than learning WHAT to think.
    2. Re:Wha... by vasqzr · · Score: 3, Funny

      Argh! I hate those sites. If I ever happen to stumble into a site that has background music, I go back and never come again. They lost my business. Websites are for reading, not listening to some really crappy midi files.


      Right! Web sites are for animated GIF's and blinking text!

    3. Re:Wha... by Entropius · · Score: 2, Insightful

      I'm just glad it's midi music--midi is a separate mixer channel and can be killed without muting the mp3 player.

      Once everyone gets broadband and they use background mp3's or oggs... bah.

  11. Downloaded the patch this morning. by wayward_son · · Score: 3, Insightful

    Windows Update on Win2k Pro told me of the problem before Slashdot.

    It's already been fixed on my machine.

  12. Will they indemnify me? by SoTuA · · Score: 5, Funny

    Har Har Har! Yeah, they'll indemnify up to the price you paid for DirectX...

    You have to give M$ some credit though... finally, a security flaw where you don't have to care if you are using Win95a, win98blah, Win2k, Win2k SP1e92, WinXP, WinYP, whatever. A *cross-platform* security issue, if you will. ;)

  13. Great. by grub · · Score: 5, Funny


    A MIDI overflow? That means no more visits to most Geocities pages.

    --
    Trolling is a art,
  14. WTF, over by Mikey-San · · Score: 2, Insightful

    Huh? What the fuck does this have to do with BuyMusic.com? The flaw, as the article says, affects MIDI, not WMA.

    I don't like Windows or BuyMusic.com, either, but this flaw doesn't seem to affect BuyMusic.com directly.

    What'd I miss? (Seriously. If I missed something, tell me.)

    --
    Mikey-San
    Karma: +Eleventy billion (mostly affected by watching Celebrity Jeopardy)
    1. Re:WTF, over by 7x7 · · Score: 2, Informative

      You missed the Joke. Buymusic.com, in a fit of 1995 zeleousy, has designed the site to detect your browser and refuse to function with anything other than IE.

    2. Re:WTF, over by kikta · · Score: 2, Informative

      No, it's because he had JavaScript disabled. I tried faking the UA & it still wouldn't let me through. Turning off JavaScript let me in just fine, even with the true UA being sent (Mozilla 1.4). Once you're in, if you reenable JS, it'll dump you to the page you mentioned.

  15. 'just cuz i had to look it up... by sporty · · Score: 2, Informative

    For those who couldn't infer the word..

    Indemnify -

    Main Entry: indemnify
    Pronunciation: in-'dem-n&-"fI
    Function: transitive verb
    Inflected Form(s): -fied; -fying
    Etymology: Latin indemnis unharmed, from in- + damnum damage
    Date: circa 1611
    1 : to secure against hurt, loss, or damage
    2 : to make compensation to for incurred hurt, loss, or damage

    --

    -
    ping -f 255.255.255.255 # if only

  16. Re:SCO insiders sell, sell, sell. by Knife_Edge · · Score: 3, Funny
    It sucks, doesn't it, how slashdot ignores the important news when it's even slightly contraversial.

    Yeah, I wish slashdot would pick up on this whole SCO thing. I cannot understand why SCO is being completely and uttely ignored here.

  17. Downplay by Winterblink · · Score: 3, Insightful
    "They'd have to come up with some way to get the user to click on that file," said Stephen Toulouse of Microsoft's Security Response Center, noting that default security settings in recent versions of Microsoft Outlook e-mail software and the Internet Explorer Web browser prevent automatic launching of such files.

    I love how they downplay that, like it's such a stretch to get a user who doesn't know any better to click a link in an email or webpage. Hell, my father just agrees to every ActiveX install that happens to come up on his screen, and clicks on any banner ad saying he's got a potential security risk on his computer. Irony is a harsh mistress indeed.

    --
    "I'm a leaf on the wind. Watch how I soar."
    -Hoban Washburn
  18. Why was there no mention of the RPC flaw? by burgburgburg · · Score: 3, Interesting
    The Last Stage of Delirium Research Group (LSD) has announced and Microsoft has confirmed and released patches for a critical flaw in the RPC Interface implementation in all recent versions of Windows. This includes NT 4.0, 2000, XP and Server 2003 (regardless of the service packs installed). As reviewed in this TechTarget article, the exploit creates a buffer overflow that could allow remote attackers to run commands with the highest system privileges. Applying the new patch and/or blocking port 135 (turned on by default on many Windows systems) are the solutions.

    LSD has produced two proof of concept exploit codes (which they have not released)which they were able to get to work even with Server 2003 and it's new buffer overflow prevention mechanism. The nature of the flaw makes it ripe for exploitation by a worm.

    As discussed here, the reports are unusually embarrassing as they affect Server 2003, Microsoft's most powerful and safest software yet. It is ironic that the announcement comes one day after the Homeland Security Department announced that it awarded a five-year, $90-million contract for Microsoft to supply all its most important desktop and server software for about 140,000 computers inside the new federal agency.

  19. Nice System My Ass by nurb432 · · Score: 3, Insightful

    So, what did the patch automatically break for you.

    What EULA change did it automatically agree to for you?

    Oh, and dont forget the option of faking out your machine and letting it automatically download a trojan..

    Automatic NOTICES are a good thing, automatic INSTALLS are not..

    --
    ---- Booth was a patriot ----
    1. Re:Nice System My Ass by iainl · · Score: 2, Interesting

      "Automatic NOTICES are a good thing, automatic INSTALLS are not.."

      Automatic notices are the default option, if memory serves. Certainly, thats what my XP Home machine is set to do. You can choose to have automatic install should you wish, but you don't have to. I left it on notify only, not because I find their EULA notices scary, but simply because I didn't want it deciding that I really shouldn't check my 3 items of email over a 56k connection without installing 20Mb of patches for unrelated things first.

      --
      "I Know You Are But What Am I?"
  20. More technical Info. by PenguiN42 · · Score: 4, Informative

    It would have been nice if the poster posted a link to the actual microsoft security bulletin, which also links to the patch for your particular DirectX. Also nice would have been a link to this article at eEye security, which goes into much more technical information. What also would have been nice is if the poster specified that the attack only affected MIDI files, instead of implying that all downloads of online music were at risk. The link to the random and not-really-related article about Microsoft protecting its users from legal hassles could probably have been left out, as it just confused the issue.

    (Maybe I'm just bitter that my submission of the same story got rejected)

    --
    The following sentence is true. The preceding sentence was false.
    1. Re:More technical Info. by crivens · · Score: 4, Funny

      You'll probably find that your story wasn't sensational enough for it to be accepted, rather than the one that was.

  21. SPIN SPIN SPIN by chill · · Score: 5, Informative

    From the MSNBC article (which is all most people will see)...

    "They'd have to come up with some way to get the user to click on that file," said Stephen Toulouse of Microsoft's Security Response Center, noting that default security settings in recent versions of Microsoft Outlook e-mail software and the Internet Explorer Web browser prevent automatic launching of such files."

    HOWEVER, from the TechNet article on the flaw...

    "If the file was embedded in a page the vulnerability could be exploited when a user visited the Web page."

    Meaning that at BEST, Stephen Toulouse of Microsoft's Security Response Center is incompetent. At WORST he is a lying scuzzball.

    --
    Learning HOW to think is more important than learning WHAT to think.
    1. Re:SPIN SPIN SPIN by Watcher · · Score: 2, Informative

      Or he's very good at qualifying his statements. Note the article claims he says that recent versions have default settings to prevent automatic loading. In the MS security bulliten, they note that the default configuration of IE running under Windows Server 2003 is not affected due to its higher security settings. I can attest to that one, if you want to browse the web at all without seeing half the content locked off (like css headers, for example), you have to turn off all of the security lockdowns. I wouldn't know for certain about the latest Outlook releases, as I'm not about to test that!

      So, he wasn't a lying scuzzball, he just was very careful with how he couched what he said.

  22. not the first time by ih8apple · · Score: 4, Informative

    This is not the first time DirectX has had security issues. Here's another issue from a year ago:

    Overview:
    Risk: High
    Distribution: Low-Medium
    Patch available from vendor: True

    Systems Affected:
    Systems having Microsoft DirectX Files Viewer
    xweb.ocx (2,0,16,15 and possibly older)

    Impact:
    A remote attacker may be able to execute arbitrary code with the privileges of the current user.

    Description:
    A buffer overflow exists in the "File" parameter of the Microsoft DirectX Files Viewer ActiveX control that may permit a remote attacker to execute arbitrary code on the system with the privileges of the current user. This vulnerability affects users visited ActiveX samples galery at activex.microsoft.com. Since the control is signed by Microsoft, users of Microsoft's Internet Explorer (IE) who accept and install Microsoft-signed ActiveX controls are also affected. This control was also available for direct download from the web, but can be uploaded on any website.
    The tag could be used to embed the ActiveX control in a web page. If an attacker can trick the user into visiting a malicious site or the attacker sends the victim a web page as an HTML-formatted email message or newsgroup posting then this vulnerability could be exploited. This acceptance and installation of the control can occur automatically within IE for users who trust Microsoft-signed ActiveX controls. When the web page is rendered, either by opening the page or viewing the page through a preview pane, the ActiveX control could be invoked. Likewise, if the ActiveX control is embedded in a Microsoft Office (Word, Excel, etc.) document, it may be executed when the document is opened.

    Vendor Information:
    secure_at_microsoft.com was informed on
    9.May.2002.
    MSRC 1149cb ticket was opened and finaly resolved on 25.Jun.2002
    Solution:
    Apply a latest IE/OS patches available from Microsoft:
    Setting kill bit expected to be included in latest IE Service pack.
    Windows 2000 SP3 and Windows XP SP1 expected to solve this problem.
    Links:
    ActiveX control still available for retrieval from Global Internet "backup copy":
    http://web.archive.org/web/20010410194632/http://a ctivex.microsoft.com/activex/controls/directx/xweb .htm

  23. MIDI by ciryon · · Score: 5, Funny

    Cool, Then you can construct some kind of hacked MIDI keyboard that just plugs into the computer you want to compromise. Press B# three times and you get the admin password.

    Ciryon

    1. Re:MIDI by iainl · · Score: 2, Funny

      "you can construct some kind of hacked MIDI keyboard that just plugs into the computer you want to compromise."

      Now this just has to be the next /. poll:

      Which tune should you have to play to get the admin password through MIDI? Personally, I vote for the Mission: Impossible theme, but I'm sure someone has a better idea.

      --
      "I Know You Are But What Am I?"
  24. DirectX Bloat... by BJZQ8 · · Score: 2, Interesting

    I find it amazing that a graphics API update is 11mb...let alone the "runtime" which is 164237 KB...although I don't know how big OpenGL's program was....

    1. Re:DirectX Bloat... by sithlord2 · · Score: 2, Informative


      OpenGL is just graphics. DirectX is a lot more...

      DirectX Contains :
      - 3D API (DirectGraphics)
      - Sound and 3D Sound API (DirectSound)
      - Network play API (DirectPlay)
      - MIDI and music API (DirectMusic)
      - Various drivers for Sound- and graphic-cards)


      --
      ...You are over-qualified and under-paid. If we give you a raise, we will break the cosmic balance of the universe.
  25. Turn to Slashdot for breaking news! by Call+Me+Black+Cloud · · Score: 4, Informative

    Let's look at the evidence:

    Flaw in DirectX allows code embedded in a malformed MIDI file to be executed on machine (read more)

    Patch from MS available before news "broke" on slashdot

    Article submitter somehow tries to tie this to buymusic.com

    Looks like a case of a rapid fix from MS and a kneejerk editor at Slashdot. How about this spin? "Notified of critical bug, MS immediately issues fix". Nah, wouldn't play to this crowd.

    To answer your question, cryonic*angel, MS won't indemnify you but level headed readers may excoriate you...

    1. Re:Turn to Slashdot for breaking news! by IIH · · Score: 2, Funny

      Looks like a case of a rapid fix from MS and a kneejerk editor at Slashdot. How about this spin? "Notified of critical bug, MS immediately issues fix". Nah, wouldn't play to this crowd.

      New slashdot poll:

      A flaw is announced in MS products, what happens next and why?

      a) Microsoft release a fix slowly - that would never happen in open source!
      b) Microsoft release a fix quickly - they must have known about it already and not told anyone!
      c) MS product are a flaw in themselves, recursion not allowed.
      d) They should have implemented CoyboyNeal
      e) Crappy of options/all of the above

      --
      Exigo spamos et dona ferentes
    2. Re:Turn to Slashdot for breaking news! by Troed · · Score: 2, Interesting

      The vulnerability was disclosed to Microsoft on the 16:th of April. I don't know what's "rapid" about the fix appearing today.

  26. WineX? by Laur · · Score: 3, Funny

    Is WineX affected by any chance? After all, aren't they supposed to be recreating the API exactly, bugs and all? Besides, it isn't fair that Linux users have to miss out on all the really cool highly publicized bugs. ;)

    --
    When you lose something irreplaceable, you don't mourn for the thing you lost, you mourn for yourself. - Harpo Marx
  27. "Unsually wide spread"?!?! by thepacketmaster · · Score: 4, Funny

    He doesn't know Microsoft very well, does he? :-)

    --

    --

    Luck is just skill you didn't know you had.

  28. Re:Windows ... by nolife · · Score: 3, Insightful

    Can you name another OS that exposes a security flaw via the BGSOUND tag? How about one where simply previewing or opening an email will cause security problems? How about one where scripts can be run and have access to your address books for mass emailing. How about one where browsing the web with certain active x controls causes security problems? How about one where the mime encoding is ignored or misrepresented and arbitrary local programs can be run via email or web browsing? How about one where the help system can run arbitrary code in the background? How about embedding viruses and macros into documents that can run arbitrary code and start any program automaticially?. I can keep going if you'd like. Can you even name a single OS that has ANY of these issues of data and code combined into one? Getting a perfect bugfree OS is unrealistic, getting one that is swiss cheese and a complete security clusterf**k should not be acceptable either.

    --
    Bad boys rape our young girls but Violet gives willingly.
  29. Re:Windows ... by Anonymous Coward · · Score: 5, Informative

    OpenBSD did only have a single exploit in the last seven years. (In default install profile).

    But i'm not sure it was in the last year, if it's earlier then OpenBSD is your answer! :)

  30. Re:Windows ... by jmorris42 · · Score: 2, Interesting

    I'd love to see an operating system that didn't get a security problem in a year, regardless of it's state of feature accretion. But even OpenBSD has had one exploit now and they play some real funny games to get it down to only one. Bind, fr example, isn't counted because the minimal install doesn't include it. But if you run a nameserver on OpenBSD BIND is the one that gets installed. So by that logic RedHat shouldn't count BIND bugs either since they also don't install it by default.

    I want an OS that can go a year without an exploit in ANY of the software they consider part of their 'distribution'. And still have enough functionality to be useful as a general purpose Internet server. I realize a secure desktop is going to be a lot harder, but lets at least shoot for a real secure server.

    --
    Democrat delenda est
  31. I won't EVER be buying music from BuyMusic.... by NetCurl · · Score: 5, Informative

    So after it was mentioned in the intro to the story, I looked at this BuyMusic.com, and read their terms of sale....man, this is a shitty music service...

    Who cares about the freaking security, did anyone read the TERMS OF SALE AGREEMENT?

    Check this out:

    Content Use Rules. All downloaded music, images, video, artwork, text, software and other copyrightable materials ("Content") are sublicensed to End Users and not sold, notwithstanding use of the terms "sell," "purchase," "order," or "buy" on the Site or this Agreement.
    Your Digital Download sublicense is nonexclusive, nontransferable, nonsublicenseable, limited and for use only within the United States.
    End users may play the Digital Downloads an unlimited number of times on the same registered personal computer to which the Digital Download is originally downloaded.


    So are you saying I don't actually own what I'm "buying" on their site?

    How can you unlicense your computer too? So if I get a new machine, I lose all my songs!? I couldn't find any mention of switching "primary computers" so that I can keep my music when I upgrade my machine. What about the next time I have to install a fresh version of XP over my current install? Has anyone checked out this service?

    --

    It's only when we've lost everything, that we are free to do anything...

    1. Re:I won't EVER be buying music from BuyMusic.... by forgoil · · Score: 2, Interesting

      It is simply not worth it. You only lease it (can they even stop you from listening to them songs at their whim?), you get it in WMA (Why?) probably with some DRM slapped on.

      If I buy a CD (which I won't, because they are too expensive nowdays, I own about 600 of them thus far though) I can play it in my computer (technically my old stereo), in my surround system, in my car, in mine or my girlfriends portable CD player, at work, or at a friends place.

      If I could buy the music legally in high quality ogg format, and then put it whereever I want (except trading to people) I would be happy. Very much so even. It would appeal to my sense of fairness (yes they made the music, I should pay them and not pirate) and my laziness (*burn* and it goes into the car).

      Hell, wasn't OGG even made just for this? When are they going to stop thinking about the tech stuff and give ogg some more uses than for us hackers?

      On another note, I have patched all the windows computers I use before this story came on slashdot and I don't find this worse than a new Linux kernel corrupting the filesystem. This is a piece of non news!

  32. Windows Update by JAZ · · Score: 3
    I just tried to run windows update.
    I haven't run it since I built the computer 6 weeks ago, but here is the text of the page I got:

    Windows Update is the online extension of Windows that helps you get the most out of your computer.

    Windows Update uses ActiveX Controls and active scripting to display content correctly and to determine which updates apply to your computer.

    To view and download updates for your computer, your Internet Explorer security settings must meet the following requirements:

    Security must be set to medium or lower
    Active scripting must be set to enabled
    The download and initialization of ActiveX Controls must be set to enabled
    Note These are default settings for Internet Explorer.

    To check your Internet Explorer security settings

    On the Tools menu in Internet Explorer, click Internet Options.
    Click the Security tab.
    Click the Internet icon, and then click Custom Level.
    Make sure the following settings are set to Enable or Prompt:
    Download signed ActiveX Controls
    Run ActiveX Controls and plug-ins
    Script ActiveX Controls marked safe for scripting
    Active scripting

    (c) 2001 Microsoft Corporation. All rights reserved. Terms of Use.


    This is funny on so many levels:
    - don't ya'll fix ie security?
    - do ya'll trust ms automatically?
    - ms's default setting are medium or lower?!?

    --


    "Karma can only be portioned out by the cosmos." -- Homer Simpson
    1. Re:Windows Update by shamino0 · · Score: 3, Informative
      Yeah, Windows Update requires you set Microsoft to medium or lower security.

      But how can it possible be otherwise? The whole purpose of Windows Update is to install core system software - precisely the kind of activity that you generally want to prevent any other web site from attempting.

      Of course, I don't think Windows Update should be done through a web browser in the first place. The Software Update facility in MacOS is a standalone program that can't be used for anything other than fetching and installing Apple's software updates. I think such a system is inherently more secure, because it can't be used to access third-party servers that may contain malicious software. (Yes, I'm aware that a malicious proxy server between yourself an Apple can redirect the request, but that's not something I expect to happen very often.)

  33. Re:Windows ... by KillerHamster · · Score: 2, Interesting

    Don't know much about it, but how about OpenVMS?

  34. :Actually its been known for a long time ago, but by ratfynk · · Score: 3, Interesting
    Actually its been known for a long time, but the software writers just have to put up with it, use DirectX or your midi interface will not work, or worse still it might until some user goes and loads the newest MS DirectX. So you play along with the DirectX game or your software will not work. The usual MS bullshit.
    DirectX controls have been a problem in music notation software for years.
    Maybe now someone will write a real piece of music notation software that doesn't use f'ing midi timing to set note placement. One of my main peeves with commercial notation software.

    I have seen the possibility that midi could be used as a hack for years! In fact a little friend of mine has used this exploit to demonstrate a flaw in the whole concept of midi as a scripting control. He has written a replacement algorythm that directly generates wave at the processor level and then sends it to the sound card without the use of shitty DirectX. DirectX sucks for security and flexability always has and always will, because of its fork processes. I personaly do not care if my notation software can make sound, so I just have to put up with useless junk midi. Read my journal entry about more music #32862

    --
    OH THE SHAME I fell off the wagon and use sigs again!
  35. Re:MOD PARENT UP by Latent+IT · · Score: 4, Funny

    After uninstallation of the IIS update, OpenGL started working again. Trustworthy Computing, my balls.

    It is trustworthy! You can trust it not to work!

    Ba-dum-bup! (rimshot)

    Thanks folks! I'll be here all week! Try the veal!

  36. Re:Windows ... by iapetus · · Score: 4, Informative

    Fine. But as soon as you want to do something useful with OpenBSD, you need to go beyond the default install profile, which is set up to be as secure as possible by disabling everything. Once you start enabling even common and inoffensive services, you hit security problems.

    OpenBSD security advisories from this year (for version 3.2):

    # March 31, 2003: A buffer overflow in the address parsing in sendmail(8) may allow an attacker to gain root privileges.

    # March 24, 2003: A cryptographic weaknesses in the Kerberos v4 protocol can be exploited on Kerberos v5 as well.

    # March 19, 2003: OpenSSL is vulnerable to an extension of the ``Bleichenbacher'' attack designed by Czech researchers Klima, Pokorny and Rosa.

    # March 18, 2003: Various SSL and TLS operations in OpenSSL are vulnerable to timing attacks.

    # March 5, 2003: A buffer overflow in lprm(1) may allow an attacker to elevate privileges to user daemon..

    # March 3, 2003: A buffer overflow in the envelope comments processing in sendmail(8) may allow an attacker to gain root privileges.

    # February 25, 2003: httpd(8) leaks file inode numbers via ETag header as well as child PIDs in multipart MIME boundary generation. This could lead, for example, to NFS exploitation because it uses inode numbers as part of the file handle.

    # February 22, 2003: In ssl(8) an information leak can occur via timing by performing a MAC computation even if incorrect block cipher padding has been found, this is a countermeasure. Also, check for negative sizes, in allocation routines.

    # January 20, 2003: A double free exists in cvs(1) that could lead to privilege escalation for cvs configurations where the cvs command is run as a privileged user.

    --
    ++ Say to Elrond "Hello.".
    Elrond says "No.". Elrond gives you some lunch.
  37. Roberta Flack is back by mabu · · Score: 3, Funny

    ..deleting me softly with his song..

  38. Re:Windows ... by WNight · · Score: 2, Insightful

    QNX.

    But really, Linux and MacOS X are both better, and while there have been bugs found in each, if the bug isn't one in a component you use, or in the kernel, can you count it? When I update my system, many of the updates are for third-party packages. As if MS provided patches for Eudora.

  39. *Another* buffer overrun? by IWantMoreSpamPlease · · Score: 2, Interesting

    When I was in college for programming, the teachers would *intentionally* try to crash our software, mainly by buffer overruns, if the software crashed, we would fail.

    The class taught us about error checking ond control. Something MS seems to desperately need.

    --
    So rise up, all ye lost ones, as one, we'll claw the clouds.
  40. Bashdot? by pair-a-noyd · · Score: 2, Funny

    Yeah, I like that. Let's spawn a division of /. called bashdot (b.) where the daily M$ flaws can be posted. That will free up a LOT of /. real estate for important matters like SCO scoops..

  41. Dear Windows Users by Letter · · Score: 5, Funny

    Dear Windows Users,

    <EMBED SRC="h4x0r3d.mid" HEIGHT=200 WIDTH=55></EMBED>

    Yours,
    B. Overflow

  42. Huh? by r00k123 · · Score: 2, Funny
    "DirectX flaw leaves Windows vulnerable?"

    How about: "Windows leaves Windows vulnerable?"

  43. WTF! by mrseigen · · Score: 4, Insightful

    How the fuck did a gaming API ever get enough priveleges in a "modern" operating system to be able to cause any kind of problems beyond resource starvation?

  44. Some way to get a click... by KentoNET · · Score: 2, Funny

    "They'd have to come up with some way to get the user to click on that file," said Stephen Toulouse of Microsoft's Security Response Center

    Such as a link saying "CLICK HERE!"?

    --
    "You tried your best and failed miserably. The lesson is...never try. Heh!" -Homer
  45. Windows security hole counter by forgetmenot · · Score: 4, Interesting

    Instead of posting every single security flaw in windows to slashdot (I mean seriously... we KNOW they exist don't we? It's not exactly "news" and there ARE other sites for them) to be flamed to pieces how about just have a little "counter" somewhere on the main page.. along with a date the user can set in his/her settings. Increment it everytime a new flaw is found so that it keeps a running tally. Number of Windows flaws since . Fun AND informative. Sorta.

  46. SP4 products are not affected by this flaw by jeeptj · · Score: 3, Informative

    FYI...

    Windows 2000 machines running SP4 are not affected by this flaw. I suggest anyone running anything less than this starts deploying SP4 instead of this individual patch. Shavlik has excellent products to make your patch deployment easier.

    1. Re:SP4 products are not affected by this flaw by krray · · Score: 2, Informative

      Unless of course you're running AutoCAD Architectural or Mechanical desktops (release 2000 or better) and trying to use StudioViz-3d. SP4 from Microsoft completely CORRUPTS the DATA FILES upon opening them now.

      Ironically ... AutoCAD is one of the only applications keeping the need for any Windows 2000 workstations to even exist anymore in my company. Everything else (servers to workstations) is running Netware, BSD, Linux or OS X.

  47. auto updaters deserve grief by nurb432 · · Score: 2, Insightful

    The title says it all ( and will be modded down ).

    If you auto update you deserve all the grief and broken applications you get.

    It has nothing to do with paranoia. its called being responsible. you DON'T automatically changes things because someone else says its new and improved.

    You first see if you NEED the update, if the bug fixes effect you, then you TEST TEST TEST. If it doesnt then you DONT install it.

    I'm glad you don't run any network I'm on.

    And YES i knew it was optional in the first place, the parent of this chose autoUPDATE, thus prompted comments.

    Sheesh.

    --
    ---- Booth was a patriot ----
  48. At the root of the problem by krinje · · Score: 2, Interesting

    ...is why would Microsoft distribute drawing and music libraries in what is essentially a server operating system? (WinServer2k3) Why these aren't optional components that an administrator could choose to include at install time is a good question, and should be asked of Microsoft.

    The reader with 200 NT/2K boxes to patch would probably be grateful if he didn't have to worry about patching whatever bogus components MS includes by default.

    I say we take 'em back to court and get them to rip out ALL the unnecessary functionality from the kernel.

    --
    "He treats objects like women, man!"
    - The Dude, The Big Lebowski
  49. Well done Microsoft by enneff · · Score: 2, Interesting

    It's great to see Microsoft treating a threat of this severity appropriately. When I booted up my machine this morning (long before this Slashdot article was posted) I was greeted with a Windows Update message offering me a patch to this vulnerability. I didn't even know it existed! I was able to patch first, and ask questions later.

    My only complaint is that MS seems less concerned with many less severe vulnerabilities. You'd think a corporation of their size would have a whole department devoted solely to fixing all security (and other) flaws.

  50. Re:I prefer streaming Real or MP3 by Jorrit · · Score: 2, Insightful
    It's not necessarily a bad idea. With proper music and implementation it adds to the site. Most sites fail on both accounts though.

    And what if I'm:
    • at work and not willing to disturbe my collegues.
    • listening to other music (either on computer or my stereo).


    I think music playing without me specifically requesting it is ALWAYS a bad idea. Same as I don't want my browser to open unrequested windows EVER.

    Greetings,
    --
    Project Manager of Crystal Space (http://www.crystalspace3d.org). Support CS at http://tinyurl.com/cb3x4
  51. Bugs Bunny says by N3WBI3 · · Score: 3, Funny

    I should have taken a left a 17.254.3.183

    --
    1. Re:Bugs Bunny says by tapin · · Score: 2, Funny
      I should have taken a left a 17.254.3.183
      Don't you mean 198.182.159.17?
  52. Re:Frequency of Windows Patches by Forkenhoppen · · Score: 2, Informative

    There is Transgaming's WineX, you know. I hear it's pretty good for playing games under Linux.

  53. The DRM on BuyMusic's music is essentially useless by mrbrown1602 · · Score: 2, Interesting

    OK, I'll admit - I bought a CD off of buymusic.com (specifically "Gutterflower" by the Goo Goo Dolls) and downloaded the protected WMA files. Most licenses on BuyMusic.com allow you to burn the music to an audio CD a few times (mine allowed for up to 3 burns). So, I burned the album to a standard Audio CD... and then I figured, well, lets try ripping them in CDex and making them MP3s. Worked perfectly - no distortion or loss in sound quality. Time to share these bitches on Kazaa. :-P

  54. Re:WARNING dont Patch!!! by AvengerXP · · Score: 2, Funny

    MS already knows you were going to say that by analyzing your surfing habits. Psh, amateurs.

    --
    Trolls dont like to be Flamebait, because they burn so well. Protect our Troll heritage!
  55. NOT every possible Windows configuration... by WIAKywbfatw · · Score: 2, Informative

    I'm running Windows 2000 Professional with DirectX 8.1. Seems like I'm immune as, on this OS, only 7.0 and 9.0a are effected.

    The complete list of effected Windows/DirectX combinations are as follows:

    Microsoft DirectX® 5.2 on Windows 98
    Microsoft DirectX 6.1 on Windows 98 SE
    Microsoft DirectX 7.0a on Windows Millennium Edition
    Microsoft DirectX 7.0 on Windows 2000
    Microsoft DirectX 8.1 on Windows XP
    Microsoft DirectX 8.1 on Windows Server 2003
    Microsoft DirectX 9.0a when installed on Windows Millennium Edition
    Microsoft DirectX 9.0a when installed on Windows 2000
    Microsoft DirectX 9.0a when installed on Windows XP
    Microsoft DirectX 9.0a when installed on Windows Server 2003
    Microsoft Windows NT 4.0 with either Windows Media Player 6.4 or Internet Explorer 6 Service Pack 1 installed.
    Microsoft Windows NT 4.0, Terminal Server Edition with either Windows Media Player 6.4 or Internet Explorer 6 Service Pack 1 installed.

    Not every possible Windows configuration but probably a majority of them.

    Check the relevant technical bulletin for more info.

    --

    "Accept that some days you are the pigeon, and some days you are the statue." - David Brent, Wernham Hogg
  56. A bit more serious than the average bug by Cyberllama · · Score: 2, Informative

    Alot of people are acting as though this particular bug is no big deal and isn't worthy of being posted on the main page. But consider this, how many people are running thier browsers with the default configurations? And Both IE and Mozilla will automatically play MIDI files embedded in webpages with this configurations. So this exploit could theoretically allow any website you visit to run arbitrary code on your system. . . I'd say that's pretty serious.