![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Computer Security News The Latest Computer Security News |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Analyst, Security Team
|
MS explains 7-year patch delay
Microsoft has explained why it took seven years to patch a known vulnerability. Fixing the bug earlier would have taken out network applications and potential exploits alike, it explained.
Security bulletin MS08-068 fixed a flaw in the SMB (Server Message Block) component of Windows, first demonstrated by Sir Dystic of Cult of the Dead Cow fame at a hacking conference in 2001, if not before. The flaw opened the door to SMB replay or reflection attacks that would have allowed the operator of a malicious SMB server to run exploits on vulnerable PCs. The flaw was rated as important by Microsoft but critical by some independent security watchers, such as the SANS Institute's Internet Storm Centre. Microsoft explained the delay on issuing a patch on the effect a fix would have had on network-based applications. In a post on Microsoft's Security Response Blog, Christopher Budd explains that the SMBRElay attack worked in much the same way as its legacy NTLM protocol. "When this issue was first raised back in 2001, we said that we could not make changes to address this issue without negatively impacting network-based applications. And to be clear, the impact would have been to render many (or nearly all) customers’ network-based applications then inoperable," Budd explained. Interaction between programs, for example Outlook 2000 and Exchange 2000, would have been affected by a patch at the time, according to Budd. Redmond advised customers to apply a workaround - involving SMB signing - but always knew this approach had its limitations. "We did say that customers who were concerned about this issue could use SMB signing as an effective mitigation, but, the reality was that there were similar constraints that made it infeasible for customers to implement SMB signing," Budd added. Gradual changes Microsoft has introduced with successive versions of its software have reduced the scope of the flaw and allowing Redmond to (finally) issue a patch last Tuesday. Full article here - http://www.channelregister.co.uk/200...s_patch_delay/
__________________
If we have helped you then please consider donating ![]() Proud Member of ASAP & UNITE Since 2007 |
|
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
![]() |
| Thread Tools | |
|
|