Tech stuff
Monday, 02 January 2006
OK, two important things:
  1. If you're running Windows - any version - you really, really need to pay attention to this:

    Microsoft is investigating new public reports of a vulnerability in Windows. Microsoft is also aware of the public release of detailed exploit code that could be used to exploit this vulnerability. Based on our investigation, this exploit code could allow an attacker to execute arbitrary code on the user's system by hosting a specially crafted Windows Metafile (WMF) image on a malicious Web site. Microsoft is aware that this vulnerability is being actively exploited.

    Your exposure may be lessened under certain circumstances if you're running Firefox, but it may not be. So it is critical that until Microsoft releases a bug fix - which could be tonight, for all I know - you should not visit any sites that you're not familiar with, nor should you download any images. You should set your mail client to view plaintext only, not HTML or images.

    You can follow this news at Weblogsinc's unofficial Microsoft blog.

    If you are running Windows 98 or Windows ME, or an older version of Windows like 95 or 3.1, you're basically screwed - you may need to upgrade, buy a new computer or switch to Linux.

  2. I have decided not to change over to Joomla! from Mambo, at least for now. The Joomla! development team has forked off from the Mambo team, and people with Mambo sites (like me) are a little lost about what to do. I did a test re-install of Amaz0ns on Joomla! last month, but there wasn't any real upside to it that I could see. So I'm sticking with Mambo for now.



Comments
Add NewSearch
dcmatthews   | 70.121.175.xxx | 2006-01-03 11:16:38
Just another reason to be happy I'm on a Mac... :grin
Lingster - Code and data   | 209.158.205.xxx | 2006-01-03 11:23:56
My understanding of Mac OS X is that it will not read program instructions from a data file. So data files and program files are two different things, and you can't hide a program in a data file.

Also, because OS X and other Unix-based systems do not encourage users to run as "Root", the amount of damage that malicious code can do while running as the user is much more limited.

I would encourage a lot of people with older versions of Windows, which probably won't be officially patched by Microsoft, to consider installing Linux on those machines.
RobW - Test and fix for the WMF vulne   | 58.105.109.xxx | 2006-01-03 18:56:57
Here's a link to the show notes for the Security Now Podcast. It contains a test for the vulnerability and a patch that can be applied to your system until such time as Microsoft bothers to release their own.

Rob W
Lingster - Problem...   | 209.158.205.xxx | 2006-01-03 22:38:07
The real problem is that about 10% of Amaz0ns users come in using Windows ME, 98 or 95. And they're not going to be fixed.

Bottom line: if you're using one of those operating systems, you must upgrade or change. And you must do it now. This is not me exaggerating the risk. If you use ME, 98 or 95, your system will be compromised. Someone will have access to the data on your machine, and would able to access files on your machine, browser history and even track keystrokes to get online banking passwords, etc. You must stop using those operating systems.

I use a Mac for most things, now. Linux is also acceptable.
Ric   | 86.144.191.xxx | 2006-01-04 16:01:25
For those that aren't aware the work-around listed here seems to be be a good bet - particularly if you don't want to have to install (and potentially later uninstall) an unofficial patch.

http://blogs.guardian.co.uk/askjack/

You need to scroll down a little, but the fix comes from the Microsoft website, so should work fine.

Its a real pain for those stuck with older Windows systems though. I wonder how users in countries where upgarding now isn't an option will cope.
Lingster - Linux   | 209.158.205.xxx | 2006-01-05 11:21:09
They'll have to switch to Linux: Open Office, GIMP, VLC, Firefox, Jabber, etc. in place of MS Office, Photoshop, WMP, Explorer, AIM, etc.
rsmith666a - fix released today   | 24.128.232.xxx | 2006-01-05 17:27:23
Run Windows Update. MSFT released the fix ahead of time.
tourist - my win update won't download   | 84.144.17.xxx | 2006-01-06 05:53:22
but i got thanks to your link to the microsoft tech page. But i'm sick and tired of windows, as soon as possible i will switch to Linux now.

Thanks very much for the link.

t.
Lingster - Linux   | 24.125.40.xxx | 2006-01-07 12:40:50
There are specific Linux versions and GUIs you might want over others. Some are aimed at new users.
Lingster - Ubuntu   | 24.125.40.xxx | 2006-01-07 13:57:12
I've heard very good things about Ubuntu Linux.
tourist - LINUX UBUNTU   | 84.144.2.xxx | 2006-01-08 10:27:48
Thanks for the tip. I seriously consider the switch because ever since I installed the patch my computer crashes in regular intervalls. It has never done that before. windows sucks.

t.
Masschine   | 69.22.222.xxx | 2006-01-09 22:11:12
Wow a Windoze update that didn't slow my machine.
Lingster - Ubuntu   | 209.158.205.xxx | 2006-01-10 21:28:11
Nice thing about Ubuntu is that you can download an installation distribution, burn it to CD, and then boot off the CD to try out Ubuntu without changing anything else. So if you like it, you can install it as the core OS of your PC, and if you don't like it, you just reboot the PC.
Only registered users can write comments!

Copyright (C) 2007 Alain Georgette / Copyright (C) 2006 Frantisek Hliva. All rights reserved.

 
< Prev   Next >
RocketTheme Joomla Templates