Live data from Hacker News

Microsoft fixes '19-year-old' bug with emergency patch

bbc.com

11–20 of 47 posts

Re: Microsoft fixes '19-year-old' bug with emergency patch

#11
post #10

BBC technology reporting at its usual standard. "In computer security, a drive-by attack typically means making users download malicious software." That's really not clear. It means that you'll get infected by simply passing by [a website] rather than actively doing anything.

While its good to point out errors in the article, It'd be helpful to include the correction as well.

A 'drive-by-download' attack is a malware delivery technique that is triggered simply because the user visited a website. Traditionally, malware was only 'activated' as a result of the user proactively opening an infected file (for example, opening an email attachment or double clicking on an executable that had been downloaded from the Internet).

Source: https://www.comodo.com/resources/home/newsletters/nov-10/ask...

Re: Microsoft fixes '19-year-old' bug with emergency patch

#13
post #8

> Specifically, it related to Microsoft Secure Channel, known as Schannel, Microsoft's software for implementing secure transfer of data. I'm confused... The article says this research relates to the SChannel vulnerability being patched this month and cites IBM Researchers[1] finding it, but the link to the blog post showing the work is towards OLE and not SChannel. Also, Microsoft has mentioned that they found[2] th…

I think the BBC reporter likely got confused. However it seems http://securityintelligence.com/ibm-x-force-researcher-finds... is a blog post about a 19 year old remotely exploitable bug being fixed recently, so it seems like if anything the link should go there.

Re: Microsoft fixes '19-year-old' bug with emergency patch

#14

So if this really goes back that far, I would hate to be anyone using Windows XP.

XP is 13 years old.

When the Blaster worm hit in 2003, the Unix people laughed, because they were immune. The Morris worm was ancient history, because it had been 15 years since that hit.

XP is almost ancient history. You shouldn't be running it, any more than you should've been running something vulnerable to the Morris worm in 2003.

edit 'omh makes a good point below

Re: Microsoft fixes '19-year-old' bug with emergency patch

#15

So if this really goes back that far, I would hate to be anyone using Windows XP.

I'm using XP but also a filtering/reencrypting proxy, so all secure connections are going through OpenSSL's client code. Ironically, I just updated OpenSSL 2 days ago and patched the proxy to add SNI...

Re: Microsoft fixes '19-year-old' bug with emergency patch

#16
post #8

> Specifically, it related to Microsoft Secure Channel, known as Schannel, Microsoft's software for implementing secure transfer of data. I'm confused... The article says this research relates to the SChannel vulnerability being patched this month and cites IBM Researchers[1] finding it, but the link to the blog post showing the work is towards OLE and not SChannel. Also, Microsoft has mentioned that they found[2] th…

I think the BBC reporter likely got confused. However it seems http://securityintelligence.com/ibm-x-force-researcher-finds... is a blog post about a 19 year old remotely exploitable bug being fixed recently, so it seems like if anything the link should go there.

[deleted]

Re: Microsoft fixes '19-year-old' bug with emergency patch

#17
post #8

> Specifically, it related to Microsoft Secure Channel, known as Schannel, Microsoft's software for implementing secure transfer of data. I'm confused... The article says this research relates to the SChannel vulnerability being patched this month and cites IBM Researchers[1] finding it, but the link to the blog post showing the work is towards OLE and not SChannel. Also, Microsoft has mentioned that they found[2] th…

I think the BBC reporter likely got confused. However it seems http://securityintelligence.com/ibm-x-force-researcher-finds... is a blog post about a 19 year old remotely exploitable bug being fixed recently, so it seems like if anything the link should go there.

Completely agree, maybe the mods can fix the link.

Re: Microsoft fixes '19-year-old' bug with emergency patch

#18

So if this really goes back that far, I would hate to be anyone using Windows XP.

XP is 13 years old. When the Blaster worm hit in 2003, the Unix people laughed, because they were immune. The Morris worm was ancient history, because it had been 15 years since that hit. XP is almost ancient history. You shouldn't be running it, any more than you should've been running something vulnerable to the Morris worm in 2003. edit 'omh makes a good point below

You shouldn't be running it but a hell of a lot of people and businesses still are. And MS is to blame IMO. The continued extending support, they screwed up with Vista and after making things right with Windows 7 screwed up again (although no where nearly as badly as with Vista) with Windows 8.

I also know of people running XP because it's incredibly stable now and they don't see anything in newer versions of Windows they really want or need.

Re: Microsoft fixes '19-year-old' bug with emergency patch

#19
Confused BBC.

https://technet.microsoft.com/library/security/MS14-066

https://technet.microsoft.com/library/security/ms14-064

Full list of updates: https://technet.microsoft.com/library/security/ms14-nov

Of significant importance too are the Flash Player updates released: http://helpx.adobe.com/security/products/flash-player/apsb14...

Post reply on HN