* Important * Hole in Windows XP – all you M $ users better patched! [windows xp security] [research advisories]

Q: Details here:

http: / / apnews.excite.com/article/20011220/D7GH2TTO0.html

Linkified for the Lazy . (Http: / / apnews.excite.com/article/20011220/D7GH2TTO0.html)

More info here (http://www.eeye.com/html/Research/Advisories/AD20011220.html)

MS Tech bulletin and patch here (http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS01-059.asp)

Windows XP leak . Windows “security”? HEH – Are there any of you really shocked that the holes were already found ?!


Re:The "patch" was on XP Windows Update yesterday . . . got it. But, a report from the FBI's security experts say it isn't good enough. The solution is to disable the extensive PnP capability in XP that is intended for future use with home security systems, etc. Anyone familiar with that route?

Re:I got my "patch" a couple of hours ago. The MS site was super slow. I just thought it was my new POS modem! :o

Re:LOL, seems like MS's site is down, cant even do a telnet on port 80, maybe they've started upgrading their boxes to .NET server and got hit by this exploit ;)

Damn it feels good to not have to worry about any Windows boxes but the ones at home anymore, and those at home are behind an OpenBSD(Thanks n0c;)) firewall.


Re:<<

<< Thanks guy. >>

<< thanx guy… >>

See there, I'm only trying to take care of you guys (and gals) here on the OS forum. And people try and say I'm a "meanie poo-poo head". :P ;) >>

I dont say that. I just make fun of the fact you are a Windows guy ;)

/me tip toes out without making Windows security cracks ;)


Re:<< Thanks guy. >>

<< thanx guy… >>

See there, I'm only trying to take care of you guys (and gals) here on the OS forum. And people try and say I'm a "meanie poo-poo head". :P ;)


Re:thanx guy… :cool:

Re:thanks for the heads up :)

Re:Most of you IT guys here are probably aware of the Microsoft Security Notification Service, so this is aimed more at the home user who might not be aware of this service.

To be notified of security related patches use the following:
Product Security Notification (http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/notify.asp)

Alternatively you can look up security related patches at the following:
HotFix & Security Bulletin Service (http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/current.asp)

I would imagine Scoob subscribes to this. As his post here was time-stamped shortly after I received notification that the patch was available.


Re:Story on News.com (http://news.cnet.com/news/0-1003-200-8244349.html) (includes links):

Microsoft issues patch for XP security hole

By Wylie Wong
Staff Writer, CNET News.com
December 20, 2001, 11:15 a.m. PT

just in Microsoft may have touted Windows XP as the most secure operating system it has made, but the company on Thursday released a bug fix for a security hole that could leave some people's systems open to malicious attack.

Microsoft is recommending that every Windows XP customer apply the patch immediately. Customers using Windows 98, Windows 98 Second Edition and Windows ME with the "Universal Plug and Play" service up and running should also use the patch, the company said.

Universal Plug and Play (http://news.cnet.com/news/0-1004-200-6594210.html) is Microsoft software that uses Internet protocols to allow devicessuch as computers, scanners and printers to automatically discover one another so they can communicate. Microsoft said an attacker who exploited the hole could take over computers on such a network.

Windows users can download (http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS01-059.asp) the patch from Microsoft's Web site.

More details to follow


Re:bozo – try here (http://www.microsoft.com/Downloads/Release.asp?ReleaseID=34951)

Re:Doesn't look like the patch is posted yet. All I see is an IE6 security patch from a week ago.

Related posts

Leave a comment

0 Comments.

Leave a Reply


click to changeSecurity Code

[ Ctrl + Enter ]