Microsoft Scrambles to Fix Flaw

TurgonTurgon Banned Posts: 6,308 ■■■■■■■■■□
«1

Comments

  • photexphotex Member Posts: 25 ■□□□□□□□□□
    Well they did it again icon_rolleyes.gif
  • blargoeblargoe Member Posts: 4,174 ■■■■■■■■■□
    Our MS account manager sent us an alert about this, It's supposed to be available this morning (Pacific time).
    IT guy since 12/00

    Recent: 11/2019 - RHCSA (RHEL 7); 2/2019 - Updated VCP to 6.5 (just a few days before VMware discontinued the re-cert policy...)
    Working on: RHCE/Ansible
    Future: Probably continued Red Hat Immersion, Possibly VCAP Design, or maybe a completely different path. Depends on job demands...
  • BokehBokeh Member Posts: 1,636 ■■■■■■■□□□
    Two people came running into my office all in a tizzy over it. I had sent out emails the other day about it and also one yesterday afternoon on the upcoming patch. Come on folks, gotta read those emails every day.
  • JDMurrayJDMurray Admin Posts: 13,089 Admin
    77 total patches for 2008. That's nothing to be ashamed about. Windows is a vast, complicated, and complex beast that retains compatibility with over 20 years-worth of legacy applications. It shouldn't take being a software engineer to understand how difficult it is to anticipate and discover every problem in such a codebase.
  • ClaymooreClaymoore Member Posts: 1,637
    I checked my WSUS synchronizations last night and this morning, but the update wasn't available yet. I just ran a manual update at 1PM EST and it's there. Those of you using WSUS with automatic approval of security updates should get this during your next synchronization/installation cycle.
  • SlowhandSlowhand Mod Posts: 5,161 Mod
    JDMurray wrote:
    77 total patches for 2008. That's nothing to be ashamed about. Windows is a vast, complicated, and complex beast that retains compatibility with over 20 years-worth of legacy applications. It shouldn't take being a software engineer to understand how difficult it is to anticipate and discover every problem in such a codebase.
    What, you couldn't hack out all the fixes in a weekend? icon_lol.gif

    I agree with you 100% on this one. Any operating system, especially one with a history as long as Windows, is bound to have countless little bugs, ways of being compromised, etc. Every system has ways that it can be breached, intentional or not. The trick is, it's the most popular systems that get noticed. Just imagine how many vurnerabilities would magically be discovered next week if Apple or one of the Linux distros suddenly got 50%+ market-share tomorrow.

    Free Microsoft Training: Microsoft Learn
    Free PowerShell Resources: Top PowerShell Blogs
    Free DevOps/Azure Resources: Visual Studio Dev Essentials

    Let it never be said that I didn't do the very least I could do.
  • Devin McCloudDevin McCloud Member Posts: 133
    This is why I use firefox... ! :P
    The man who trades freedom for security does not deserve nor will he ever receive either.
  • royalroyal Member Posts: 3,352 ■■■■□□□□□□
    This is why I use firefox... ! :P

    Firefox has had a lot of security fixes. But good try. :)
    “For success, attitude is equally as important as ability.” - Harry F. Banks
  • MishraMishra Member Posts: 2,468 ■■■■□□□□□□
    US Cert pushing this hard.
    My blog http://www.calegp.com

    You may learn something!
  • msright1981msright1981 Member Posts: 3 ■□□□□□□□□□
    Slowhand wrote:
    JDMurray wrote:
    77 total patches for 2008. That's nothing to be ashamed about. Windows is a vast, complicated, and complex beast that retains compatibility with over 20 years-worth of legacy applications. It shouldn't take being a software engineer to understand how difficult it is to anticipate and discover every problem in such a codebase.
    What, you couldn't hack out all the fixes in a weekend? icon_lol.gif

    I agree with you 100% on this one. Any operating system, especially one with a history as long as Windows, is bound to have countless little bugs, ways of being compromised, etc. Every system has ways that it can be breached, intentional or not. The trick is, it's the most popular systems that get noticed. Just imagine how many vurnerabilities would magically be discovered next week if Apple or one of the Linux distros suddenly got 50%+ market-share tomorrow.

    I have to definitely disagree on this. Apache is the most wide spread webserver on the earth, but still does not come near IIS in flows & threads.
    The grass always looks greener on the other side.

    SUN Bladecenter vs HP BladeCenter
  • JDMurrayJDMurray Admin Posts: 13,089 Admin
    royal wrote:
    This is why I use firefox... ! :P

    Firefox has had a lot of security fixes. But good try. :)
    And don't forget about all those buggy FireFox Add-ons that Mozilla doesn't pre-check for vulnerabilities.
  • AhriakinAhriakin Member Posts: 1,799 ■■■■■■■■□□
    "That's why I use an Etcha-Skech!"
    (You can quote me when this is popular again)
    We responded to the Year 2000 issue with "Y2K" solutions...isn't this the kind of thinking that got us into trouble in the first place?
  • royalroyal Member Posts: 3,352 ■■■■□□□□□□
    This is why I still use dictionaries and spend every day in the library reading instead of using this thing called the internet.
    “For success, attitude is equally as important as ability.” - Harry F. Banks
  • SlowhandSlowhand Mod Posts: 5,161 Mod
    Slowhand wrote:
    JDMurray wrote:
    77 total patches for 2008. That's nothing to be ashamed about. Windows is a vast, complicated, and complex beast that retains compatibility with over 20 years-worth of legacy applications. It shouldn't take being a software engineer to understand how difficult it is to anticipate and discover every problem in such a codebase.
    What, you couldn't hack out all the fixes in a weekend? icon_lol.gif

    I agree with you 100% on this one. Any operating system, especially one with a history as long as Windows, is bound to have countless little bugs, ways of being compromised, etc. Every system has ways that it can be breached, intentional or not. The trick is, it's the most popular systems that get noticed. Just imagine how many vurnerabilities would magically be discovered next week if Apple or one of the Linux distros suddenly got 50%+ market-share tomorrow.

    I have to definitely disagree on this. Apache is the most wide spread webserver on the earth, but still does not come near IIS in flows & threads.
    Well, let's not forget Apache's rough ride to the top. There's a reason it was called "a patchy" web server before the name Apache was officially adopted.

    Free Microsoft Training: Microsoft Learn
    Free PowerShell Resources: Top PowerShell Blogs
    Free DevOps/Azure Resources: Visual Studio Dev Essentials

    Let it never be said that I didn't do the very least I could do.
  • Devin McCloudDevin McCloud Member Posts: 133
    I use firefox with noscript. Please, go look at the security patches this year for IE!
    The man who trades freedom for security does not deserve nor will he ever receive either.
  • HeroPsychoHeroPsycho Inactive Imported Users Posts: 1,940
    I use firefox with noscript. Please, go look at the security patches this year for IE!

    Just because Firefox addresses multiple flaws per patch virtually all the time, it doesn't make it more secure.

    I like and use Firefox, but let's be fair.
    Good luck to all!
  • snadamsnadam Member Posts: 2,234 ■■■■□□□□□□
    I use firefox with noscript. Please, go look at the security patches this year for IE!

    I'm sorry, but when is it a bad thing that a company releases security patches? Doesn't that mean they are doing their jobs and trying to keep ahead of the curve? Not to mention that other companies release similar critical updates; and yet their products don't get revered as 'crap'. It seems as though the disgruntled end-user is more critical of a patch release than the actual patch itself sometimes... icon_rolleyes.gif
    **** ARE FOR CHUMPS! Don't be a chump! Validate your material with certguard.com search engine

    :study: Current 2015 Goals: JNCIP-SEC JNCIS-ENT CCNA-Security
  • jamesp1983jamesp1983 Member Posts: 2,475 ■■■■□□□□□□
    Claymoore wrote:
    I checked my WSUS synchronizations last night and this morning, but the update wasn't available yet. I just ran a manual update at 1PM EST and it's there. Those of you using WSUS with automatic approval of security updates should get this during your next synchronization/installation cycle.

    Ya I had to do a manual synch as well.
    "Check both the destination and return path when a route fails." "Switches create a network. Routers connect networks."
  • dynamikdynamik Banned Posts: 12,312 ■■■■■■■■■□
    I use firefox with noscript. Please, go look at the security patches this year for IE!

    You can lock down IE much tighter than FF. Most people don't have a clue how to do it though. (I'm saying this as someone who primarily uses FF)
  • HeroPsychoHeroPsycho Inactive Imported Users Posts: 1,940
    You set Internet zone security to High, and run it on Vista. icon_wink.gif
    Good luck to all!
  • Devin McCloudDevin McCloud Member Posts: 133
    Wow... what a bunch of IE fanboys....in one of those articles the guy announcing the story actually recommended using something other then IE. Everyone here must work for Microsoft.
    I'm sorry, but when is it a bad thing that a company releases security patches?

    When it takes months for a billion dollar company to patch holes that ever Chinese hacker and **** site are already exploiting!

    :D[/quote]
    The man who trades freedom for security does not deserve nor will he ever receive either.
  • KasorKasor Member Posts: 934 ■■■■□□□□□□
    Now, you know why many companies still using Novell OSE....
    Kill All Suffer T "o" ReBorn
  • AhriakinAhriakin Member Posts: 1,799 ■■■■■■■■□□
    Wow... what a bunch of IE fanboys....in one of those articles the guy announcing the story actually recommended using something other then IE. Everyone here must work for Microsoft.

    :D

    Or simply that many internal corporate applications use ActiveX controls and require IE, also policies may exist that preclude quickly changing core software like the Browser of choice. There's a big difference between response for personal systems, and response companywide. Do not assume everyone else is lazy, or a fanboy, because they have to deal with a bigger picture.
    We responded to the Year 2000 issue with "Y2K" solutions...isn't this the kind of thinking that got us into trouble in the first place?
  • Daniel333Daniel333 Member Posts: 2,077 ■■■■■■□□□□
    Interesting about the patch, no biggie though. General web rules continue to apply.

    As for using a 3rd party browser, you really need to look at application life cycle management. If you have never had to do a life cycle report or negociate a long term contract you really should read up on these.

    I currently support about 40 companies in the SMB range running 2000-Vista(32/64) with nearly 30% of them being a mobile workforce along with nearly half of them dealing with legecy software that requires various versions of IE from 5.5 to 7 and any number of special settings.

    The reality is in most of the world their is an application life cycle that needs to be addressed, patching Internet Explorer with Firefox is not the answer when companies have multimillion dollar investments in legacy code.
    -Daniel
  • win2k8win2k8 Users Awaiting Email Confirmation Posts: 262
    My combat arms account got hijacked first day i created it, although i heard bad reviews about the game about it being easily hacked and what not...


    win2k8
  • Devin McCloudDevin McCloud Member Posts: 133
    I was merely kidding...I know business's are bound by IE. I have a friend who works at one of the big Airline companies and she cannot access any internal secure sites , with anything but IE. I use Firefox for personal use. I just think that Microsoft's priorities are screwed up when security holes are not patched for months and months. Microsoft's response time is ridiculous!
    :D
    The man who trades freedom for security does not deserve nor will he ever receive either.
  • Daniel333Daniel333 Member Posts: 2,077 ■■■■■■□□□□
    Microsoft does better than most software vendors I work with.

    Worst reponse time I have seen in a while was Apple's DNS patch. *shudder* Still not sure if they ever patched X.2-3.
    -Daniel
  • WebmasterWebmaster Admin Posts: 10,292 Admin
    icon_arrow.gifhttp://support.apple.com/kb/HT3298
    Notice how all 11 fixes apply to Windows XP/Vista and only 4 also to Mac OS X. Even at Apple they can't write secure code for Windows icon_twisted.gif
    JDMurray wrote:
    Windows is a vast, complicated, and complex beast that retains compatibility with over 20 years-worth of legacy applications. It shouldn't take being a software engineer to understand how difficult it is to anticipate and discover every problem in such a codebase.
    Which shows perhaps it's better to let the Windows era end and everyone should change to Mac OS X with its less complex, less compatible, and minimalistic design, so developers can focus on userfriendliness and security rather than compatibility and bells-and-whistles ;) I admit, my new Mac and my iPhone infected me, I'm biased. I entirely agree with Slowhands first reply. Then again security through obscurity can still be an effective additional layer of security as long as you don't depend on it, i.o.w. using software that is less likely to be a target is a nice side-effect.

    Earlier this month Apple released an update of 190 MB updating Mac OS X to 10.5.6, including almost 15 security fixes and over 20 software updates/fixes/improvements. Most users don't see the list/specification and just notice a single patch. It sure doesn't feel like I'm getting less updates for the Mac than Windows. I'd be more worried if I didn't get a whole bunch of updates frequently.
  • JDMurrayJDMurray Admin Posts: 13,089 Admin
    I don't care so much for the number of updates as I do their criticality. Distributing a dozen fixes as either a single patch or a dozen patches is done simply for book keeping convenience by the vendor. How severe the problem is that is fixed is far more important. I also discern between operating system fixes and application fixes--which is hard to do when both types of software are maintained by Microsoft.
    Webmaster wrote:
    and everyone should change to Mac OS X with its less complex, less compatible, and minimalistic design
    I can't wait until you put the high-level applications programming aside and delve into the world of BSD UNIX programming. Then we'll see if you still think that OS X is less complex and with a minimalistic design. ;)
  • HeroPsychoHeroPsycho Inactive Imported Users Posts: 1,940
    Webmaster wrote:
    Notice how all 11 fixes apply to Windows XP/Vista and only 4 also to Mac OS X. Even at Apple they can't write secure code for Windows

    OR...

    Apple is filled with human beings as programmers who also make mistakes, especially when they code for an OS they don't know as well as their own. icon_wink.gif
    Good luck to all!
Sign In or Register to comment.