Ten Security Bulletins From Microsoft
wschalle writes "Microsoft has released 10 "new" security bulletins, including one pertaining to a vulnerability in the Windows Shell, apparently exploitable via the web. The shell vulnerability only allows code execution as the user viewing the malicious web site. Aren't you glad your shell is web-enabled? The recent GDI+ vulnerability is re-released here as well as a vulnerability in zip compression handling."
....Win2k patched fine. Another Tuesday Patch roulette over with....
please move along.
I think this is very reflective of the content of this report.
You can't handle the truth.
Unleash the Microsoft bashing!!!
you don't have to have a CS degree to configure it safely. Using any number of freely available firewalls is a simple point-and-click matter.
With linux, well...tried to configure IPtables lately? I have, and that made me switch back to windows!
I was just about to write a pro MS defence post to stave off the oncoming attack. I just re-read the article. I quit.
> Aren't you glad your shell is web-enabled?
Does it matter? Is this meant to be an attack on Microsoft just for its own sake? It's becoming as inane as spelling "Micro$oft" or "Windoze".
Web enabled shells? Show me an in-use unix shell that doesn't have Links or Lynx already installed.
RST
I wonder why we don't get many Linux stories like this, seeing has how they have had some serious issues lately too.
Hmm....
So if your user has admin rights (as all at my site do b/c our toolset requires it) then you're screwed if they goto a mal-site. . . . Great.
-nB
whois gawk date unzip strip find touch finger mount join nice man top fsck grep eject more yes exit umount sleep dump
Thank you microsoft for vulnerabilities that can take advantage of the so-far-assumed-to-be-safe data files like jpgs and zip files
txt file vulnerability anyone!?!
Ok, Now is a really web enabled experience! :)
What's in a sig?
The recent GDI+ vulnerability
Good thing I choose to join NOD.
/rimshot
-------
Support Indy Music. Buy
It's nice to know that they have made security such a high priority. Hopefully their next high priority will be 'doing something about it'.
This is my sig. There are many like it but this one is mine.
What in the world is the Windows Shell?
Kerry is the choice of terrorists everywhere.
Man, I seriously need to learn Linux asap. If not cause of all the super holes found lately, as for the fact Microsoft doesn't seem to care too much about the user base.
I think the first link on the page referenced above says it all:
Want Less Technical Detail?
I can think of a more comprehensive bulletin:
1. Internet Explorer (All versions)
2. Microsoft Office (All versions)
3. Microsoft Windows OS (All versions)
Si tacuisses philosophus mansisses. If you had kept quiet, you would have remained a philosopher.
Links or Lynx are both programs that can be called from a Linux Shell. (Command Line Interface)
Bad Troll, no Internet Cookies for you!
Just in case anyone is wondering, SP2 is not affected by any of these vulnerabilities, except for MS04-038. That's the fix for the "drag-and-drop" vulnerability that everyone's been crowing about.
OS: Windows XP Professional ... but mine isn't. :P
Shell: Litestep
--- Ãther SPOON!
Please select your argument here:
[ ] MS has these security exploits because it is the biggest OS
[ ] MS is a steaming pile when it comes to security
[ ] MS is working on fixing these things, and is doing the responsible thing.
[ ] 1337! I can't wait to #4x0r!
MS Tech: Wait... you want to add web support to the shell? What the f**k for?
IT Manager: For kicks, for security, for some stupid reason the execs told me, I dunno. Why should I care? My job is the 3rd worst in the US after all...
Wow now these are guys I can trust!
Are Windows 98, Windows 98 Second Edition, or Windows Millennium Edition critically affected by any of the vulnerabilities that are addressed in this security bulletin?
No. None of these vulnerabilities are critical in severity on Windows 98, on Windows 98 Second Edition, or on Windows Millennium Edition. For more information about severity ratings, visit the following Web site.
Don't sweat it, a remotely exploitable shell is
not critical!
Got Code?
I thought XP is the safest and most secure version yet! That's what all the commercials and the blue installation screens say.
Does this mean that my potential (and therefore their passion) is full of security holes?
If you don't know what AltaVista is (was), get off my lawn.
That is enough for me and my small company. I am using Open Office and Mozilla full time now. Adios Bill.
I must wonder...does this have to do with another story?
and (on my page) a microsoft windows server 2003 advertisement right below this article.
beautiful. fucking beautiful.
This sig contains repetition and redundancy.
Page title:
Microsoft Security Bulletin MS04-037: Vulnerability in Windows Shell Could Allow Remote Code Executione (841356)
Comment removed based on user account deletion
Seriously, I hope that Microsoft gets their act together before too long.
I'm a little worried about the possibility of a "final" windows exploit that quickly and without warning kills every MS box it touches.
All these vulnerabilities are a bit disheartening.
Either Microsoft is really combing over their programs for errors or they are in trouble
Kind of makes me happy that I only rely on free/open source programs
Every other day there's another round of stupid problems that need yet more patches. Why doesn't anyone ever get tired of this security flaw shit from Windows?
Does the shell exploit still occur if you use mozilla/firefox?
"The best thing about Microsoft bugs is that there are so many to chose from..."
The shell vulnerability only allows code execution as the user viewing the malicious web site.
On most XP installations, the only user is "Administrator".
SLASHDOT: news for people who can't concentrate on work or have no life at all and got tired of yelling back at the TV.
Aren't you glad you need admin privileges for day-to-day operations on too many windows boxes?
Aren't you glad that even if you can get by without admin privileges, you can still completely hose your own files just be visiting the wrong website? Aren't you glad the only files that you can infect are the only files that you really care about?
You bet I'm glad my shell is web-enabled! After all, this Windows box belongs to my employer ... its his time that will be wasted.
See what I've been reading.
Comment removed based on user account deletion
Only one vulnerability affects to SP2. In fact, the XP SP2 (desktop OS, you know) had less vulnerabilities than win 2k3/XPSP1, which shows the huge progress made in the SP2. I don't know how to take this..."good" because SP2 is good, or "bad" because the server OS is more insecure than the desktop OS. In any case, they're porting the work they did in SP2 to win 2003, so we'll see. They've raised the bar with the SP2, IMHO.
Why are there more big announcements about MS patches?
Because MS is the dominant OS, and many Slashdot readers need to know about these things.
There have been Slashdot articles on Linux bugs, but fewer. Why? Maybe because there are fewer critical bugs. Why? Market share.
Not everything is anti-MS. Some of it is just reality.
desiv
Nasty hacker crafts email that appears to be from
microsoft talking about this great new software that can be downloaded from their site. Of course mindless MCSE network admin does not realize it is a phishing attack and clicks to see the greatest new stuff from the redmond lords. Now nasty hacker owns your entire network......priceless
Got Code?
just buy a mac :-)
'nuff said.
People like myself that use LiteStep for a shell under Win32 don't have to deal with the memory overhead of a web-enabled shell, or these web-based exploits.
It's pretty cool and it's open source and stable (unlike Windows sometimes) and has a decent-size user base, eventhough most of the themes are pretty worthless. (Then again, for any themable program, aren't the bulk of the themes crap?)
Anyhow, people that are stuck using Windows like I am (Lycoris' Tablet PC version of Linux is next to featureless) should give it a try, if nothing else but as a preventative measure against future bugs like this.
Holy crap! Where can I find this compiler?
With the exception of a proof of concept GDI+ exploit posted to USENET, none of these vulnerabilities are known to be exploited.
The shell and compressed folder vulns require user interaction, just like 99% of all other "worms". As long as your mail application is patched you can't get hooked via email and if you visit "malicious websites" with anything other than Lynx you probably should be shot anyway. Ditto for a decent firewall.
On the other hand, I wonder why things like these for soem reason never get posted.
Pity that, but so what? All the attacker has to do is upload a root kit via browser help object, cookie or similar then execute the kit. Who executes the kit should not matter if the kit is made right.
The thought of the day is, "just another hole in a screen door." Why are people still running Microsoft junk?
Friends don't help friends install M$ junk.
Has anyone else noticed how everything is now classified as remote? For the zip one you have to download the file and then attempt to unzip it. THATS NOT REMOTE. You downloaded it and then got exploited. Its running local context! Its local! Remote for example would be the NNTP. Where a remote user directly exploits you without any user interaction.
I extend this classification to the GDI vuls. They are downloaded and then rendered by windows. Why should it matter that its not an executable file. From an 3rd party perspective it looks the exect same as someone downloading and running a trojan. It shouldn't matter how clever they are in hiding the execution or downloading of the file, if it runs in local context its LOCAL.
Fuck i'm so tired of seeing remote vul tacked on to everything.
Twitter, you're a petulant cock-gobbling sycophant to Linux Torvaldyos! Quit taking DP from ESR and RMS's feculent cocks and why don't you try to stop sucking quite so much? Get out of your parents' basement and see the real world - maybe then you'll see how pathetic you sound, with your neverending stream of bullshit about how Microsoft is stalking you. Wasn't it you who said that Microsoft believes your insane ranting is actually a threat to them, so they PAY PEOPLE to reply to you on Slashdot? No sir, I don't get any money. I do it for the love. Someone has to go up against your paranoid whining. So get back in your cage and shut the fuck up already.
Someone h4x0r3d my box before I could get to it.
Comment removed based on user account deletion
Updates were unable to be successfully installed
.NET Framework 1.1 Service Pack 1
The following updates were not installed:
Microsoft
Cumulative Security Update for Internet Explorer for Windows XP Service Pack 2 (KB834707)
[Configure automatic updates] [Tough shit]
Thanks, Microsoft! What the hell am I supposed to do now! Oh well, this particular machine hasn't been installed for almost 1 year, it's about time I reset the cruft factor...
That pretty much sums it up.
Over to you, Dave.
curl http://www.hackersite.com/deletefiles
DOH!
Curse you RedBaron!
For me in some sense this is good news
The more vulnerabilities and bugs that appear in MS software the greater my unix/linux skills will come into play in the private sector.
Am I the only one that doesnt want masses of people (lusers) to start attempting to use linux?
Just makes for less job security for me in 5-10 years.
So is "shat". Sometimes people use "shit" or even "shitted" as a past-tense verb instead of "shat", and they're missing out.
That's what I get for having faith in you, Microsoft!
I can tell you aren't an admin with 1,000 PC's to deal with. Say, how many months would it take you to do the other 999? And how much money would that cost your employer? And how much would that add to the prices that your employer's customers have to pay to cover it?
Comment removed based on user account deletion
here, here and here
sigs, as if you care.
A complex web of inter-depending systems is never going to be more trustable than the least trustable system in the web.
It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
why release the patches one-by-one when they can release an extra-value ten pack?
No, ten bulletins. Twenty two holes, most of which (according to ZDNet) are critical and the remainder are "important" (read: critical but Microsoft won't say so).
It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
That does it. I'm switching to Linux- Ubuntu, *noppix- or even *BSD, anything but Windows.
Installing today's updates, it asked me if I wanted more information about a vulnerability- and proceeded to open a page with Internet Explorer. How many times do I have to tell the computer that Firefox is my default browser? Whose machine is this, anyway?
With SP2, XP has been annoyingly telling me I may not be protected (I run without anti-virus but am locked down regardless and still scan regularly- with no virus or reinstall in 2 years). In today's update, it keeps nagging me to reboot.
And why do I have to sign yet another goddamned EULA to install critical patches?
There isn't any windows only software I need anymore. OO.org, Firefox, Thunderbird... and now GAIM (which I've gotten used to at work, working on FC1). I'll miss some of the usability features of XP, but I just can't handle it anymore. So long, Windows!
Information: "I want to be anthropomorphized"
actually, parent is my brother(that sentence sounds weird); I just want to make sure his comment is public so he has to carry through with it ;)
http://shit.slashdot.org/comments.pl?sid=125410
When confronted with a new Microsoft security hole, which seems to one to have existed for a while, possibly leaving his entire organization at risk, one should never react with surprise or horror.
One must make a FRIEND of the horror.
Then, one can hear about the security issue, nod sagely with a wan smile, and whisper to the junior IT staff, "But of COURSE there is a hole. This is to be expected, young one. Run and patch, then we'll go to lunch."
Bonus points for leaning back in one's chair, folding one's hands across one's belly, and sighing loudly before addressing the novice.
Farewell! It's been a fine buncha years!
Another blissfully ignorant day using OS/2 Warp!
but, there is poorly written software out there that 'requires' admin membership. so even if what you need are rights to a section of registry or file system, the program either checks for membership or tech support won't help unless it's set up their way.
these people should be boiled in oil.
eric
Actually CNET News.com is reporting 22 not 10. That's quite the grouping.
thanks to surfraw ;-)
http://freshmeat.net/projects/surfraw/
Sorry, Bungi man, Linux browsers don't auto download and install as root browser help objects. They also don't give websites shell level access. Rootkits take more effort than that on Unix and Linux systems.
Friends don't help friends install M$ junk.
Didn't Mozilla patch this a month ago? I remember reading something about the shell: protocol and URLs
Computer security is not protection it's the fear of penetration.
"The nice thing about standards is that there are so many to choose from"
I'd really like to know how Windows handles process control blocks and such. Linux, as a last resort, has the stack grow into the PCB of the process. So if you do somehow cause a stack overflow you will blow away your own PCB and likely cause the process to get killed before anything truely nasty happens.
Microsoft has released 10 "new" security bulletins, including one.... ZZZZZZZZZZZZZZzzzzzzzzzzzzzzzZZZZZZzzzz...
It is amusing that the much maligned WinME nowadays work better and doesn't suffer from half the problems in XP - "The Most Secure Windows Ever".
Oh well, what the hell...
Windows should be scrapped and actually engineered next time. I'm really embarrassed for Bill Gates.
I wonder...I'm still running Win2k SP2 and none of the issues come up...MS's site says they only affect SP3 and SP4. Does it mean that they're assuming everyone has SP3/4 or that SP2 is safe from all this?
What, you mean my Windows for Workgroups 3.11 is affected? Great. Now I have to upgrade to Windows 95 sooner than I had planned.
[x] use Linux
...
[x] get a mac
[x] install firebird
[x] install thunderbird
[x] delete IE
[x] delete Outlook Express
[x] install Open Office
[x] install Zone Alarm
[x] install AVG Anti Virus
[x] unplug from internet when not actively online
PS - Have you ever noticed that the default selected option on the MS shutdown list is
[x] restart computer
Interesting, isn't it?
If I could summarize, you are saying that the desktop machine should be configured well and securely so that a firewall is not needed.
To answer your question, a firewall is for damage control when you don't know (or realize too late) that your machine is not perfectly configured. Some program has some vulnerability, or a trojan, or something. You are right --it SHOULD not be this way; but when it just IS, and the trojan starts spamming people or transmitting your private PGP keys onto IRC, the firewall is there to say, "Hey, waitaminnit, something weird is going on here."
A firewall is like a fireman. You hope that it doesn't have to do anything but sit there.
404555974007725459910684486621289147856453481154 in hex is "You sank my Battleship?"
[GPG key in journal]
So find the check in the software and NOP it out. After all, if people are expected to use regmon/filemon to determine the correct permissions (a common statement on /.) then why not patching software that has dumb checks for administrator? Microsoft offers windbg as a free download, so there is no excuse not to fix it.
I wonder if that bug was inherited from the old netscape codebase. Anyone know?
OR
OS inside bugs?
I think the next windows version should be called
BUGHORN - Windows Inside.
NO CHARGE for BuG Update.CHARGE only for Win Update.
Why does yahoo do this
this is my first post, hello all. /. is great!
I think that some users actually enjoy downloading the updates. Sure , MS has new vunerabilities every week it seems, but thats become a standard now, and I think that MS could use it to their advantage.
You think the scene with MS could be worse? Hell yes... MS could have all their customers lives constantly put on halt, except on fridays when MS releases an update that will only last for 1 day before another hole is found...
Here is the way it actually is...
If you get the majority of MS users to download a patch for some security hole, that never affected them in the first place, then they feel cared for and protected.
The rate at which MS releases patches, vs the rate at which people's lives grind to a halt because of the holes, is in favour of releasing.
And just food for thought, some marketing strategies done during heavy war times, are products that 'enhance' your life, make it more 'efficient', and protect you. So maybe while you consume updates you 'battle ready your PC'!
Post your thoughts!
Copied this from the eula... Hope i'm not violating the eula by doing that...
.NET Framework component of the OS Components to any third party without Microsoft's prior written approval.
* You may not disclose the results of any benchmark test of the
Does this change to the eula fix some vulnerability?
This batch of patches includes one for Office XP. After installing I now find that all Office XP applications pop up a window requiring me to accept an obnoxious EULA; if you decline the application closes. So far I can't find a way to uninstall, I may have to roll back the whole machine to get Office functioning again without accepting this. Be warned.
If you look at the dates of CVE advisories, you'll see this:
...
Assigned (20040311)
Assigned (20040615)
Assigned (20040908)
Assigned (20040722)
Here you go, 7 months to fix shell vulnerability. They certainly took their time!
As some of you may or may not know (not that it matters) I work support for a major OEM that ships systems with... you guessed it, Windows. It looks like one of these updates just might have a problem. We've seen a few XP users call tonight with an issue stemming from "Update 1 of 3." This is the last update that installs before the system reboots and starts coming back up to a screen that says the system needs to reboot. Anybody else having issues with this? I managed to fix one with Last Known Good Config but I'd still like to know which one caused it.
Ha ha!
(Nelson uses a Mac).
It's also a common statement of the Open Source (tn) community that anyone should go into the source code and fix whatever probems or add waht ever featrues yourself instead of complaining. Thanks for the double standard, zealots!
Sorry abuut my spealing and/or grammer: engrish is' me first langauge.
If you are running Windows XP SP2 there are only one patch you need to install. And in that patch there are only two security cavets that affect XP SP2.
:)
Drag and Drop Vulnerability - CAN-2004-0839 Which is very hard to exploit.
Plug-in Navigation Address Bar Spoofing Vulnerability - CAN-2004-0843 Which is the most critical one but still hard to exploit in a useful way.
Now if you are running Windows 2000 you need to get your ass over to Windows Update right now..
This could be a great pr tactic. Release 10 new security problems that effect all windows/ie except the new spiffy XP SP2 :)
Tricky marketing? or just real evidence that MS has done something right?
who knows.
But i'm sure someone at MS will spin this.
On the down side this will just make more windows users with modem connections unable to download and fix thier systems due to the enormous time taken to complete the downloads. For example Downloading from windows update on a 33.6 from south africa is like walking across broken glass with bare feat and it raining vinegar.
On the plus side at least microsoft are now patching thier operating systems and the push forward in security is obviously occuring.
Does microsoft release thier updates on CD free? that would be a plus.
Anybody got anything to say about the effectiveness and side-effects of running the patches? All i see is a bunch of whining, defending, gloating and cracking of jokes...
Twitter, you're a petulant cock-gobbling sycophant to Linux Torvaldyos! Quit taking DP from ESR's and RMS's feculent cocks and why don't you try to stop sucking quite so much? Get out of your parents' basement and see the real world - maybe then you'll see how pathetic you sound, with your neverending stream of bullshit about how Microsoft is stalking you. Wasn't it you who said that Microsoft believes your insane ranting is actually a threat to them, so they PAY PEOPLE to reply to you on Slashdot? No sir, I don't get any money. I do it for the love. Someone has to go up against your paranoid whining. So get back in your cage and shut the fuck up already.
the funniest part is that most brands of the antivirus sw that is installed in mail server would consider .zip attachment to be safe, and would mail me in disdain when I send .exe attachments, asking for it to be encapsulated in a zip; next time I will reply them with a .zip that exploits WInXP to its a**
Am I the only one seeing more and more issues with firefox with every new MS patch...
Comment removed based on user account deletion
they are called exoskeletons.
See my journal, I write things there
Not everyone can always afford to deploy the latest software and hardware on every system. However, if I installed say Fedora Core 2, which I run myself , I can easily tune it down to run on older systems.
See my journal, I write things there
Actually, I think parent DIDN'T say go to the SOURCE.
He said do the difficult and modify the COMPILED BINARY to skip the check.
Source would be much easier (and we would do it for you to boot).
The truth about Led Zep should never be told on
Doesn't this bear just a slight resemblence to the DirectTV mods that came down. Do you reckon they're going to make all the pirated Windows versions die? :-)
-={ Security does not exist - give up }=-
use OpenBSD?
From their main page:
Only one remote hole in the default install, in more than 8 years!
Disclaimer: This opinion was created without the use of any facts
.Net and windoze just sucks with holes and bugs.
Wait a second...
The great grandparent of this post writes something that either has got to be meant as a joke, or is just plain Stupid:
"It would actually mean that Microsoft built the SP2 updates with a new compiler that basically eliminates any possibility of buffer overflows."
He gets 5: Interesting (which means that at least three people have been sitting in front of their monitor, thinking, "Duuude! Uh, yeah, maybe M$ has some secret supercompiler that removes all bugs. DUUDE!").
The parent writes something that's actually a quote straight from MS changelog for SP2:
""core Windows components have been recompiled with the most recent version of our compiler technology, which provides added protection against buffer overruns."
And get modded 5: Funny!? I mean, all right, not everybody on here is a developer but please, a reality check might be in order!
:wq!
To think, for once, my sig IS my comment!
Windows XP SP2 told me to install third-party software that prevents viruses and protects stability... I chose Ubuntu
http://www.mandrakelinux.com/en/ftp.php3
Download ISO make cds
Format harddrive and install linux
Download JDK from java.sun.com
install eclipse from eclipse.org
passed on back on the 7th. MS seems to have passed on it too.
If it had been October 7th 2003, MS would have included it.
.signature not found
Do not mod a post as +1 Informative automatically if it links to a news site or wikipedia. Try actually clicking the link. The above post was meant to be funny.
You win today's "No Shit!" award.
But what about a patched Windows system vs. and unpatched Linux system?
"Ask not what your country can do for you." --John F. Kennedy
Another day another windows vulnerability. Looks like there are now 4 constants in life:
1) sun will rise in the East and set in the West
2) You will have to pay your taxes, one way or another
3) One day you will die.
4) there will always be another windows vulnerability
But your brother's a chump.
:)
Still, I'm sure you're aware of this by now
It is not the users fault his machine is infected with this stuff. Hell I watched a admin with a sp2 machine hit a web site yesterday with IE and the web site tried uploading some malicious code. It infected his machine and crashed it. Now tell me how on earth that it is his fault that IE allowed this to happen. Oh I know you are going to tell me he is visiting the wrong web sites right?
Got Code?
The compiler isn't a component in the end user system at all. It is the software used to build the system. A buffer overrun almost always causes the app to crash so it is safe to assume that the build system at MS does not have an overrun.
So I have no idea what you are talking about and suspect that neither do you.
We need another category on /.: YAME - Yet Another Microsoft Exploit.
Posting stories about security holes in Microsoft products is about as exciting as watching paint dry, or as newsworthy as articles proclaiming, "Water is wet!", or "Ice is cold"...
It's not news for nerds - most of us stopped using these obsolete systems years ago. And yes, I understand Windows users do need to be concerned about these things, but it's still not news. This is business as usual for Microsoft.
Windows and Security holes are like Linux and vi: Yes, you can find systems without them, but they're the exception, rather than the rule.
And yet, I'm almost driven to tears when I hear people naively tell me that their Windows system is secure because they've downloaded the latest patches. Was it that this most recent exploit didn't exist a year ago? Or - could it be - that only crackers knew about it until now? Does patching today protect you from the exploit discovered tomorrow? Didn't it ever occur to people that undiscovered exploits might exist in the Microsoft patches? And if the company didn't do it right the first time, what makes you think they'll do it right this time?
I've seen six generations of Microsoft Windows, and not one of them delivered on the promises Microsoft made. Having watched Microsoft since the release of Windows 95, I've learned that constant security problems are a staple of the Windows experience. If you've been using computers for more than a year and haven't gotten a virus, seen your system crash, or had your machine zombied, then you aren't running Windows. It's that simple folks. Problems are an endemic part of the Windows experience.
A professor once said to me, "We use operating systems for what they're good at, not for what they're bad at..." He was referring to the decision to use Linux as a file and print server while maintaining Windows NT servers for other tasks.
The society for a thought-free internet welcomes you.
This makes about 50 post sp4 patches. Takes about 75 megs of space.
1.) Create service pack with bundled fixes for vulnerabilities you already know about
2.) Release fixes for those know vulns for lower service packs afterwords. Make sure to mention new service pack is not affected.
3.) SP2 r0x0rz!!! MS Rul3z!! Trusted Computing fo life!!
www.madeofwinandawesome.com
- thumbnail view within image folders surprising how much I miss this one
- listings of music folders with properties from the id3 tages displayed in columns
- cd burning integrated into explorer (no 3rd party tool needed)
- clean and easily readable fonts
- consistent GUI's with meaningful icons
- very few dependency problems when installing software
- excellent hardware support built in and from manufacturers websites
- can run Mailwasher i miss u mailwasher
- can play MP3 without downloading codecs
- security holes big enough to drive a truck through
- meals required during installation process
- worms, viruses, macros, exploits.....
- lightens your wallett considerably
- constant nagging and micromanagement of my surfing habits and hardware setup
Windows has enough "features" to make it quite handy for the beginner to intermediate user. I agree that without the advantage of familiarity, a newuser learning Windows will find it just as hard as learning GUI Linux use. This is exactly what I found when teaching my Mum. Plus her friends aren't confident to go poking around in Linux, meddling-related breakdowns reduced massively..... now that is a REAL advantage!-- Howto: Get +5 (1) Whine about M$ (2) Namedrop Gentoo (3) Casually Abuse Mods (4) Namedrop Early Computer Model
Some of the recent MS Security Bulletins have been PGP signed, but the signatures do not verify. This is pathetic.
-merv.