On TV.com: Confession: I Like THE BIG BANG THEORY
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 2 of 65:
Next »
« Previous
Vulnerable by default?
Exploit code for a remote reboot flaw in Microsoft's implementation of the SMB2 protocol has been posted on the internet, exposing users of Windows 7 and Windows Vista to the teardrop attacks that used to be popular on Windows 3.1 and Windows 95.

I presume this attack is able to bypass the firewall because if it can't, this isn't an issue for 99.9999% of Windows machines.
Posted by: NonZealot   Posted on: 09/08/09 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Never let it be said  Yagotta B. Kidding | 09/08/09
Vulnerable by default?  NonZealot | 09/08/09
so as long as there is a good firewall  Viva la crank dodo | 09/08/09
What do you mean by "excused"? nt  ye | 09/08/09
Perhaps I  Viva la crank dodo | 09/09/09
You misunderstood.  ye | 09/09/09
I see  Viva la crank dodo | 09/09/09
Misunderstanding squared...  jasonp@... | 09/09/09
By default the built in firewall restricts access to the port in question.  ye | 09/09/09
I would tend to agree...  jasonp@... | 09/09/09
@jasonp: We disagree  ye | 09/09/09
Not sure  CobraA1 | 09/08/09
My experience on "cheap consumable"..  JCitizen | 09/09/09
"No user action is required." Except disabling the firewall.  ye | 09/08/09
Except disabling the firewall AND enabling network discovery  honeymonster | 09/08/09
This is a serious problem for many.  sporkfighter | 09/11/09
Wrong and wrong  NonZealot | 09/11/09
So will this work...  Sleeper Service | 09/08/09
fresh install, no network config changes  JoeMama_z | 09/08/09
So what we're saying is...  Sleeper Service | 09/08/09
No surprises there  frgough | 09/08/09
Wrong.  sporkfighter | 09/11/09
Once again, same as above  NonZealot | 09/11/09
It is the filesharing service SMB2.0  SamCPP | 09/08/09
It isn't if you're using Windows XP...  ye | 09/08/09
But anyone who uses filesharing on a Vista/Win7 network won't do that n/t  SamCPP | 09/08/09
And anyone who uses NFS won't do it either.  ye | 09/08/09
Simple answer: NO  honeymonster | 09/08/09
Reasons why this isn't a big issue  georgeou | 09/08/09
Reasons why it is an issue (maybe not big)  SamCPP | 09/08/09
Correction to point 2  SamCPP | 09/08/09
Please  Richard Flude | 09/08/09
They shouldn't be.  ye | 09/08/09
Yet back in the real world  Richard Flude | 09/08/09
Pick a side and stick with it.  ye | 09/09/09
Link please  Richard Flude | 09/09/09
Where have I ever down played this?  ye | 09/09/09
Read this thread  Richard Flude | 09/09/09
Worse; fileservers based on 2008 or 2008R2 are exposed  honeymonster | 09/08/09
Reasons why it may become a big issue  honeymonster | 09/08/09
I agree.  ye | 09/08/09
If you can get code to execute before a patch is out, yes  georgeou | 09/09/09
What makes you think WS2008R2 is "definitively" exposed to this?  Johnny Vegas | 09/09/09
Software Reuse  ps.zdnet@... | 09/09/09
HAHAHA Nice FUD. In other words no, you have no idea.  Johnny Vegas | 09/10/09
Rare events  Yagotta B. Kidding | 09/08/09
Reread the post you are replying to  NonZealot | 09/08/09
Using a cellular phone/data card to access the internet....  sean_hando@... | 09/08/09
Not accurate  CobraA1 | 09/08/09
RE: Windows 7, Vista exposed to 'teardrop attack'  john doee | 09/08/09
This is why I always use a hardware firewall.  CobraA1 | 09/08/09
Other positive MS news  Richard Flude | 09/08/09
RE: Windows 7, Vista exposed to 'teardrop attack'  shellcodes_coder | 09/09/09
Thats what you get  The 'G-Man.' | 09/09/09
Strange logic...  jasonp@... | 09/09/09
The RTM version of Windows 7 appears to be unaffected.  ye | 09/09/09
Likely scenario...  jasonp@... | 09/09/09
I wasn't referring to you specifically.  ye | 09/09/09
RE: Windows 7, Vista exposed to 'teardrop attack'  ps.zdnet@... | 09/09/09
Then the "advisory" was wrong  honeymonster | 09/09/09
To back up honeymonster about SMB and SMB2...  Grayson Peddie | 09/09/09
All you have to do is disable SMB2....  dunn@... | 09/09/09
RE: Windows 7, Vista exposed to 'teardrop attack'  apjohnson@... | 09/09/09
RE: Windows 7, Vista exposed to 'teardrop attack'  tyvek@... | 09/09/09
RE: Windows 7, Vista exposed to 'teardrop attack'  diharp@... | 09/09/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline