Forum Home
Press F1
 
Thread ID: 24694 2002-09-16 12:00:00 Win XP Users Urgent Jim B (153) Press F1
Post ID Timestamp Content User
80106 2002-09-16 12:00:00 It is absolutely essential that those people using Win XP download and install XP SP1 update urgently.
See my previous post about Win XP serious flaw.

From grc.com


~ UPDATE ~
As feared and expected, just five days after the release of Service Pack 1, and the publication of this vulnerability's details by irresponsible web journalists, instances of malicious URLs for deleting all files from user directories started appearing on the Internet.
PLEASE be sure to inform your friends and associates who are using XP about the need to either update to Service Pack 1, or quickly run XPdite on their systems.
Jim B (153)
80107 2002-09-16 12:21:00 and then there was grc sucks (http://grcsucks.com/) hmmmmm who to believe flying_green_leprachaun (1767)
80108 2002-09-16 12:54:00 Believe it

www.theregister.co.uk
Jim B (153)
80109 2002-09-16 21:57:00 www.theregister.co.uk BIFF (1)
80110 2002-09-16 22:20:00 This has no relevance to the very real danger of using XP without the update.

Gibson is only one of many people who has pointed out the serious flaw and suggesting that this not be taken seriously is irresponsible and could influence users not to do the large update.

It has been demonstrated by many responsible security experts that this flaw in XP can delete the contents of any directory in your Windows system.
Jim B (153)
80111 2002-09-16 22:53:00 Unwary Windows XP users can have entire directories
emptied of files simply by clicking on a hyperlink,
according to an Australian security researcher .
.

. zdnet . com . au/newstech/security/story/0,2000024985,20268254,00 . htm]" target="_blank">www . zdnet . com . au ( [url) ZDNet Australia[/url]
Jim B (153)
80112 2002-09-17 04:34:00 > This has no relevance to the very real...

Yeah yeah, this exploit came out August 15th. Gibson is just doing the usual cash in on someone elses discovery.
Delete %windir%\PCHEALTH\HELPCTR\System\DFS\uplddrvinfo.h tm for a quick fix.
BIFF (1)
80113 2002-09-17 08:45:00 Who did first find that whole in XP then?

How come they didn't make it all that public.
-=JM=- (16)
80114 2002-09-17 10:54:00 It was announced at an internet security conference for all the security bigwigs, and they agreed to keep it quite until SP-1 was released so that a fix was a vailable from microsoft before hackers found out about the flaw and exploited it. unfortunately some experts couldn't keep their traps shut, and a few days after the press found out, instances of the problem began surfacing.

I had a look, and just by knowing the file involved, the coding to make one of these url's is pretty easy looking. I haven't tried it yet, but it looks very basic.

G p
Graham Petrie (449)
80115 2002-09-17 12:21:00 > available from microsoft before hackers found out

what a pointless exercise as the only ones who didn't know about it were the ones likely to be exploited and Steve Gibson. Oh and that dweeb working the the cube across from me. :)
BIFF (1)
1 2