six serious flaws in Vista discovered.

Microsoft Windows operating system, and software for Windows platform, including QuickTime Player and iTunes for Windows. We also discuss topics about Microsoft Corp.

Moderators: Josh, Don_HH2K, Mandrake

six serious flaws in Vista discovered.

Postby Antony » Tue 26 Dec, 2006 4:55 pm

I heard the news this morning from Sunrise.

Wired reported that there are six serious flaws discovered in Windows Vista, a month before Vista officially available to consumers.

Flaws Are Detected in Microsoft’s Vista (The New York Times)

The browser flaw is particularly troubling because it potentially means that Web users could become infected with malicious software simply by visiting a booby-trapped site. That would make it possible for an attacker to inject rogue software into the Vista-based computer, according to executives at Determina, a company based in Redwood City, Calif., that sells software intended to protect against operating system and other vulnerabilities.
UserAgent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en) AppleWebKit/418.9.1 (KHTML, like Gecko) Safari/419.3
User avatar
Antony
diamond member
diamond member
 
Posts: 14342
Joined: Tue 18 Jun, 2002 11:36 pm
Location: Sydney, Australia

Postby orizng » Wed 27 Dec, 2006 5:05 pm

sounds like IE7 isn't as secure as M$ bragged, better keep firefox going..
UserAgent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en-US; rv:1.8.1.1) Gecko/20061223 Firefox/2.0.0.1
Whatever,whatever,have a nice day.
User avatar
orizng
silver member
silver member
 
Posts: 325
Joined: Mon 12 Aug, 2002 2:50 am
Location: Dallas, TX

Postby Mandrake » Wed 27 Dec, 2006 6:44 pm

orizng wrote:sounds like IE7 isn't as secure as M$ bragged, better keep firefox going..


That's a pretty ignorant statement. I'm no fan of IE, but there have been plenty of flaws in Firefox too.

We'll just have to wait and see if Vista is going to be more secure than previous terms of Windows in the long term. But, realistically, when over 90% of computer users are going to use Windows there's bound to be a lot of flaws crop up.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9a2pre) Gecko/20061226 Minefield/3.0a2pre
Core i7 920 | ASUS P6T Deluxe v2 | 3TB+ HDD | 12GB Corsair DDR3 | Radeon 4890 Xfire | X-Fi Titanium Fatal1ty | Logitech Z-5500 Speakers | Dell 3008WFP | Seven RC1
User avatar
Mandrake
Moderator
Moderator
 
Posts: 4160
Joined: Fri 13 Sep, 2002 6:35 am

Postby Don_HH2K » Wed 27 Dec, 2006 7:42 pm

I was reading a good article up at Ars Technica about how this flaw isn't as bad as it's made out to be. Most security advisories rate it rather low on a severity scale.

From what I've been reading, you need to be authenticated on the target machine in order for this vulnerability to work, so you'd need to exploit another hole other than this one before getting it to work anyway.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 6.0 x64; en-US; rv:1.8.1) Gecko/20061030 BonEcho/2.0 (mmoy CE K8N-X02)
Laptop: HP Compaq nx6325 - Turion 64 X2 @ 2GHz, 2GB DDR2, 100GB HD, ATI Radeon X300, 15" LCD, Seven Pro
Handheld: Palm Treo 650 - Intel PXA270 @ 312MHz, 10MB RAM, 32MB flash, 2.7" LCD, Palm OS 5.4
User avatar
Don_HH2K
Moderator
Moderator
 
Posts: 5112
Joined: Sun 09 May, 2004 3:59 pm


Return to Windows (and Microsoft talk)

Who is online

Registered users: Google [Bot], Yahoo [Bot]