On mySimon: Top Gifts For Him, Her, Mom, Dad & More!
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 9 of 58:
Next »
« Previous
In 1-2 years peope will be surprised
First, from the article:

``The first vulnerability affects MSN Messenger 6.0 and MSN Messenger 6.1 and will allow attackers to view contents of a victim's hard drive during a chat session with the victim.

Attackers "could view files through MSN Messenger on their computer," said Stephen Toulouse, security program manager for the Microsoft Security Response Center. "They can do it, and you are not necessarily aware of what they are doing."

Users that do not block anonymous callers are most vulnerable to the exploit. If anonymous callers are blocked, the attacker has to be identified on the victim's address list. To obtain particular information, such as credit card numbers, attackers have to troll the hard drive, said Toulouse. However, they can continue to comb the drive as long as the chat session lasts.

Oliver Friedrichs, senior manager for Symantec's security response team, said that victims don't actually have to be in conversation with the attacker. As long as the user permits anonymous callers to send messages, an attacker could come in and peruse Quicken files or other identifiable files that could likely contain sensitive data. However, most people block that function, so random attacks will likely be rare, he said.''

This is clearly an open door to remote access of one's owns data on the disk.

``The second medium-level risk potentially allows a hacker to take over a system by executing Internet Explorer code through a flaw in Outlook 2002.

A computer has to be configured in a particular manner, though, said Toulouse. The user has to set "Outlook Today" as their Outlook home page. ''

If a remote process can take over system control then this IS a system vulnerability.

Second: longhorn has real LONG way to go until it becomes a useful system. It wont be out until after two years (or more likely 3 or 4, given the well known MS delays).

In the last two years Linux went from a niche OS to one that has been penetrating almost all sectors from the server down to the desktop. ALL major vendors are releasing their commercial s/w under Linux. Desktop and office applications have improved very much in the last 1-2 years. Only if you haven't used Linux recently you may have the impression that the user has to do command line system management. As a matter of fact, Linux GUI apps have become as tedious and ornate as their ms windows counterparts.

About friendliness: ms windows is hostile to the point of prejudice against the occasional or the serious user. Linux management -including learning time- is MUCH LESS than the time a user / admin has to spent in re-re-...patchings, reinstalls, reboots, cleaning viruses, recovering data, ETC. This is a simple fact of life and it becomes more and more obvious to PC users that try their hand on Linux.

As for the clueless-user friendliness, this is not a reality anymore for ms windpows. Setting up even a home or a LAN ms windpows box with ADEQUATE security requires THE SAME ammount of expertise as that to do the same on Linux.

If the trends continue, by the time longhorn will be out, Linux will have a significant portion of the PC market.

-m
Posted by: michael-t   Posted on: 03/09/04 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

50 billion can not stop the negative security news.  DonnieBoy | 03/09/04
Faster Than Windows ???  nikoli | 03/09/04
Longhorn on the way?  Monkey_MCSE | 03/09/04
Longhorn on the way?  seosamh_z | 03/09/04
Look how fast Linux is improving.  DonnieBoy | 03/09/04
applications compatible with XP ha ha  hipparchus | 03/10/04
Integration makes them part of OS  Sunny Jalolly | 03/09/04
Re: "as user friendly as XP": . . . Your priorities are bass ackwards !!!  Plain Logic | 03/09/04
In 1-2 years peope will be surprised  michael-t | 03/09/04
Groan, hardly a trivial fault with messenger then  hipparchus | 03/10/04
Re: Faster Than Windows  wadeprater | 03/09/04
Sco  voska | 03/10/04
Sco Lies!!!!  nucrash | 03/10/04
Re: Sco Lies!!!!  jones_jj | 03/10/04
Actually they are a serious problem  Rick_K | 03/09/04
3-5 years  hipparchus | 03/10/04
It's common sense  voska | 03/10/04
50 billion can not stop the negative security news  seosamh_z | 03/09/04
Security and 200,000 Software Assurance Customers who may or may not renew.  rinaldo | 03/10/04
MCSE'S ARE FOR MONKEYS  FreeBSD | 03/09/04
works for me  Monkey_MCSE | 03/09/04
True, there is good money to be made keeping Windows running.  DonnieBoy | 03/09/04
You're right  Chad_z | 03/09/04
Hey, now  Chad_z | 03/09/04
real cute!!!  ryusen | 03/09/04
The article said "notices"...  Confused by religion | 03/09/04
Actually ZZ may have a point  Squawkbox | 03/09/04
Not to worry.  DragonBRockin | 03/10/04
perhaps...  ryusen | 03/10/04
I can relate.  DragonBRockin | 03/10/04
The fact of the matter is...  theace18 | 03/09/04
The reviews seem to be working.  joseb_z | 03/09/04
MSN Messenger with XP, downloadable one  hipparchus | 03/10/04
They Do  Test Subject | 03/10/04
as us geeks read this...  cchenoweth | 03/09/04
I'm an unhappy microsoft customer  hipparchus | 03/10/04
and the vulnerability causes spam and viruses blocking the net for all os  hipparchus | 03/10/04
Take head out of sand  voska | 03/10/04
why does a media player need to accespt INCOMMING connectons  JWatson77 | 03/09/04
So it can be periodically queried to find out what it has done  Taz_z | 03/10/04
"Windows Media Station Service " is server side  jfrankcarr | 03/10/04
MSN Instant Messenger NOT part of Windows OS.  DragonBRockin | 03/10/04
re: two points  ryusen | 03/10/04
Agreed but...  DragonBRockin | 03/10/04
actually,  ryusen | 03/11/04
WRONG !!! Messenger on my machine is MSN Messenger  hipparchus | 03/10/04
Better look again Dude!  DragonBRockin | 03/10/04
And also.  DragonBRockin | 03/10/04
HUH??  jones_jj | 03/10/04
Excellent Post!  DragonBRockin | 03/10/04
MS Longhorn  dogman_z | 03/10/04
I disagree  nucrash | 03/10/04
Age does not equal maturity  RamaBrooks | 03/10/04
Good Point  middle of nowhere | 03/10/04
Nothing New  bit_rot | 03/10/04
Partially Right  bit_rot | 03/10/04
Re: Partially Right  jones_jj | 03/10/04
contention:  ryusen | 03/10/04

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

SmartPlanet

Click Here