- TalkBack 39 of 46:
- Next »
- « Previous
- Thread View
- Flat View
- My thoughts exactly...
-
Yesiree...
In my previous post above, I was about to end with a 5,000-word diatribe about how Microsoft could have headed off this whole mess in 1996 or 1997 by ditching ActiveX (most malware spread over the Internet since then has involved some sort of exploit of ActiveX security flaws). But then I figured--explaining this to MS-brainwashed IT people and Windows users would be like trying to explain Particle Physics to hamsters (yes, even *I* bought the MS line up until around 1999 or so. Then my sister's system was wiped by 20 or so lines of VBScript code in a Web page. She lost everything). MS doesn't get it...the Flock doesn't get it. Even though security people like Georgi Guninski have been pointing out for YEARS that ActiveX is a malware writer's wet dream. Perhaps they'll fix it with the first production release of Longhorn. In which case, the fix will have occurred about TEN YEARS after the problem was pointed out.
And for all you folks who contend that if Linux, Mac, Commodore128, Proctor-Silex Toaster Ovens, (insert your favorite platform here) etc. etc. ad nauseum were as popular as Windows, there would be as much malware for that particular platform: NONSENSE. ActiveX is responsible for the overwhelming, vast majority of tojans and worms to affect Windows/IE/Outlook/Outlook Express/Media Player/Office since Microsoft "embraced and extended" the Internet to include exclusive, proprietary, buggy ActiveX functionality in their Internet offerings in a vain attempt to make the Net their own. If it weren't for ActiveX, Windows would suffer just a few more attacks from crackerz than other platforms. The first computer virus I ever saw? nVir, circa 1988. Platform? Mac. Seen many Mac trojans, worms or virii since then? How many AS/400 exploits have you seen? That would make much more sense for crackerz...there's TONS more exploitable, useful (to a cracker) info on your average old, decrepit AS/400 than on any 100,000 Windows boxes. Mid-sized corporations still tend to keep their critical info (like payroll and accounts payable) on old AS/400s and other minis (or on Big Iron), NOT on Windows servers. Unless you think 23,742 inter-office memos reporting "My office chair still squeaks, and by the way how's that Smith account going?" would be interesting to a cracker. NOT. Windows is cracked because it's BEGGING TO BE CRACKED. It's the computing equivalent of leaving your car unguarded, unlocked, engine running, in front of a chop shop.
Think you're safe if you've got the latest MS patches and a desktop or server AV system? Think again: George Guninski has revealed several exploits in everything from OfficeXP to Windows Media Player to IE to Outlook/Outlook Express that remain unfixed by Microsoft TO THIS VERY DAY. Even after he reported them to MS and BugTraq. Some of these exploits are over a year old. Heck, I think one or two are going on two or three years old.
Here's just a small sample of UNPATCHED IE exploits, compiled on a Chinese Web site:
http://die.leox.com/ie_unpatched/index.html
Whoever this Liu Die Yu is, MS needs to hire this person at around, oh, $2,000,000 a year because apparently he or she is much better at finding security flaws in MS products than MS's own people. Am I right, or what? - Posted by: Yen_z Posted on: 11/05/03 You are currently: a Guest | Members login | Terms of Use
What do you think?
SponsoredWhite Papers, Webcasts, and Downloads
- VMware Infrastructure: A Guide to Bottom-Line Benefits VMware Frustrated by the costs of maintain ever larger data centers?or building ... Download Now
- Five Steps to Determine When to Virtualize YourServers VMware Server virtualization isn't just for big companies. Entry-level ... Download Now
- Three Steps You Need to Know to Stop Data Loss Varonis Sensitive data exposed to misuse or loss... it is the stuff of nightmares ... Download Now
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- Reduce risk. Reduce complexity. Increase reliability.
-
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
- Learn more >>
- Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
-
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.

- Learn more about the free, six-month trial offer>>
- Save time with automated shipping solutions
-
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
- Visit the UPS Business Essentials Guide
SmartPlanet
- Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
- More from IBM
- Can your business work smarter? Learn more about Lotus Symphony
- Learn how to work smarter and optimize cost using the IBM Smart SOA approach Download the eBook
- Smarter ways to make smarter products Read the brief from IBM







