Welcome to HashDot.com
Search  


Contact Us

Earn Money
Earn money online, For lifetime Hashdot membership and for Advertisement details..
Click Here

Login




 


 Log in Problems?
 New User? Sign Up!

  
Microsoft Warns Against Outside Fixes
Posted by: ALLISON LINN on Apr 02, 2006 - 12:20 PM
Microsoft 
SEATTLE - When Microsoft Corp. researchers learned recently that a software flaw had been made public and could prompt Internet attacks, the company ordered a team to devote all its time to fixing the flaw and making the repair work with other products.Microsoft argues that's the approach customers want and expect, but some security experts complained that the software company's traditional method, which could take days or weeks, wouldn't help people fast enough.
So for the second time in three months, outside programmers took matters into their own hands by quickly releasing their own fixes, days ahead of the official Microsoft patch for its market-dominant Internet Explorer browser.
Microsoft doesn't endorse such third-party fixes, warning it can't vouch for whether they will work smoothly with Microsoft products and other applications. But those providing them argue they have a responsibility to protect users from attacks.
"It's kind of like having the cure and not sharing it with anybody," said Marc Maiffret, chief hacking officer with eEye Digital Security Inc. of Aliso Viejo, Calif., which earlier this week released such a fix.
Rather than replacing Microsoft's own patch, Maiffret says he is hoping to provide a bandage for the interim.
The security expert also doesn't fault Microsoft for taking time to finalize an official patch because it can be difficult to make sure that repairing one part of the complex Windows operating system, which includes Internet Explorer, doesn't cause problems elsewhere.He also realizes that a patch like this can cause any of the thousands of non-Microsoft applications running on Windows machines to stop working, crippling businesses and frustrating home users.
But Maiffret argues that Microsoft should be the one providing the type of temporary treatment his company was able to quickly pull together in response to what the industry refers to as "zero-day" problems - vulnerabilities that attackers can immediately use to try to infiltrate other people's computers.

Johannes Ullrich, chief technology officer with the security research organization SANS Institute, also recognizes that Microsoft needs time to build patches but believes the company can more quickly release a "beta" patch so users would have temporary - if not perfect - protection in the interim.

"The real problem is that Microsoft leaves that opening," Ullrich said.

Such problems are relatively rare. In most cases, Microsoft learns about flaws in its systems confidentially from security experts, who hold off on making their findings public - and alerting potential attackers - until Microsoft can release an official patch.

But occasionally, reports of a vulnerability leak out before Microsoft has time to build a fix, creating a dangerous situation in which attackers can take advantage of the flaw while users have little protection.
When Microsoft faced such a problem a few months ago, SANS recommended that users download the third-party fix because of the unusual severity of the threat. This time, Ullrich said the flaw appears to be less worrisome, so SANS is recommending that people either disable part of Internet Explorer or temporarily use an alternative browser, such as Firefox or Opera.

Microsoft says it is hoping to release a patch for the most recent IE flaw by April 11, its normal time of month for issuing security updates, and sooner if possible.
In the meantime, Stephen Toulouse, a program manager with Microsoft's Security Response Center, said the company is working with other security companies to help guard against attacks, and helping to shut down the Web sites that exploit the flaw.

Toulouse said the company also is trying to find ways to create and test its patches faster - for instance, by conducting tests in tandem rather than one after another.

But Microsoft, he said, cannot risk releasing a patch that causes problems for even a small number of users because people may decide not to use the fix at all if they hear it's problematic.

"The huge responsibility we have is that we have to answer to our customers, and our customers represent potentially hundreds of millions of different configurations," Toulouse said.

Third-party fixes also create the potential for a malicious person to release a pretend fix that is really an attack, much like the occasional e-mail falsely attributed to Microsoft and others, masking as legitimate communications but really luring users to malicious Web sites.

Even well-meaning programmers have the potential to wreak havoc on businesses if their unofficial fix has even a minor problem, said John Pescatore with research firm Gartner.

"The analogy I use is, if the FDA was testing an anticancer drug, and your neighbor said, 'I have an anticancer drug,' would you use it?" Pescatore said, referring to the Food and Drug Administration.

Meanwhile, Microsoft will likely have to keep grappling with this problem, despite all the security improvements the company has made in the past few years. It takes only a few programming mistakes - amid millions of lines of code - to expose Windows users to potential attacks.

"Even if they're doing everything right," Maiffret said, "there's going to be four to five mistakes a year, and those four to five mistakes are going to lead to the same things you're seeing now."

Associated Press
By ALLISON LINN (AP Business Writer)
Copyright 2005 Associated Press. All rights reserved. This material may not be published, broadcast, rewritten, or redistributed.

Microsoft Warns Against Outside Fixes | Log-in or register a new user account | 4 Comments
Comments are statements made by the person that posted them.
They do not necessarily represent the opinions of the site editor.

Re: Microsoft Warns Against Outside Fixes

(Score: 1)
by labirex on Dec 11, 2007 - 02:51 PM
(User information  | Send a message 
video esibizioni sexi da casa video porno erika bella foto fige gratis foto fighe gratis cicciolina che si fa scopare da cani e cavalli racconti di madri con negri elena grimaldi clip ragazzine con vecchi porchi nere che scopano foto adolescenti fighe rotte gratis mamme che succhiano incesto con nonna esperienze fisting annunci con foto di troie casalinghe be dottoresse troie a chieti figa hentay storie porno massaggi cinesi a bologna siti porno incesti puttane ucraine sesso con cugine cani che inculano donne porche su msn foto guardoni foto donne con collant chiavare figa foto dominatrice sexy foto fiche cinesi mamme che succhiano daniela succhia cazzi da monta figa sotto la gonna eva robbins donne di strada mature mouvi gratuite di ragazze donne incinte scopate fermo posta annunci cerco due cazzi per mia moglie filmati ard elisabetta canalis fake esibizionisti neri racconti tradimenti cazzi di cavalli esibizioniste outdoor racconti eros suocera wwww virgilio it inculate dolorose fighe con calze nere www vergini it porno china bambine filmati porno da vedere numeri telefo
Read the rest of this comment...

Re: Microsoft Warns Against Outside Fixes

(Score: 1)
by labirex on Dec 11, 2007 - 03:02 PM
(User information  | Send a message 
video clip amatoriali tette mania www tutti nudi it scopate in discoteca spiate sotto le gonne video gratis cicciolina vagina aperta fiche bollenti foto gratis vecchie zoccole puttana sborra in bocca video tgp donne russe over 70 video casalinghe annoiate orge con cazzoni neri foto sculacciate donne mature arrapate canalis fa vedere la figa wwwtutto gratis foto vidio hard casalinghe professoresse porno dragonballx gratis casalinghe sole annunci hard numeri telefonici troie pompini ravenna filmati rumeni erotici gratuiti infermiere mistress move hard italiani video xx immagini trans bocchinare troie video porno zie mignotte nudo ga www video di dragonball it www gnocca travel letizia bruni video gratis i piu belli culi rotti dell eros video hard in bagni pubblici a caltanissetta donne cinquantenni tettone www donne escort it poro foto minorenni lesbiche immagini ragazze e ragazzi nudi vecchie che trombano video piccanti da vedere free donna scopata da un cavallo leccare la cappella donne brasiliane con il cazzo giuliana sexy foto cavalle selen hot videos video pornno gratis Read the rest of this comment...

Re: Microsoft Warns Against Outside Fixes

(Score: 1)
by labirex on Dec 14, 2007 - 04:25 PM
(User information  | Send a message 
spanish tight ass lingerie lesbians sex vacations black butts sex ***** boat fast sex free bbs little girls suck my tits galleries mature free mature free mature estella warren topless painful ***** free fetish pics young teens in bra and panties drunk girls ***** wet undies gallery male sex dolls rugrats all grown up teen girls having sex girls of walmart sex and porn choose a bowling ball best ass awards teen girls that are hot sexy alessandra ambrosio star wars hentai devon porn free mature woman pics cumfiesta sloan young girls virgin 16 paris hilton nip slip ***** very young girls young girls ***** trailer park whores skinny whores unmonitored webcams hot jocks in underwear topless young girl teen girls posing in bras the rock nude young model bbs british porn stars gay porn blog free mature woman pics rape pic siblings have sex gay ass licking big tit babes ***** jenna jameson boobs ***** teen girls that are hot familyguy sex juegos eroticos tifa lockheart hentai stuffed tiny ***** Read the rest of this comment...

Re: Microsoft Warns Against Outside Fixes

(Score: 1)
by labirex on Dec 14, 2007 - 04:52 PM
(User information  | Send a message 
pornogratis it racconti erotici piedi calze super dotati esibizioniste nude in pubblico mamme che scopano figli troie catanesi in cerca di cazzi neri videoporno gratis lunghi foto di penetrazioni vaginali dragonballx gratis video sexj pipi pisciate troie in calore con animali moana pozzi ru porno a taranto erotic video masturbazione amanti del culo com storie erotiche incesto eva henger sexi tutto cazzi grandi gay anteprima bocchini gratis racconti erotici lesbo lei cerca lui con foto fottere pornp amanti del culo com rocco siffredi trailer movie sesso di donne incinta video super dotati video sexsy pompini di casalinghe pipi pisciate gioci sexsy gratis video amatoriali it negre che succhiano il cazzo foto bastarde wwwfoto di donne porno mignotte con animali pornostar cinesi foto puttane giovani luoghi per esibizionismo ragazze porche a verona annunci sessuali senza iscrizione lombardia nere nigeriane hard siti gay fetish pompini tardone pornodive magrissime inculate tra trans video anteprima troie video amatoriali it Read the rest of this comment...

Web site powered by PostNuke ADODB database library PHP Language

All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest (c) 2008 by me
This web site was made with PostNuke, a web portal system written in PHP. PostNuke is Free Software released under the GNU/GPL license.

You can syndicate our news using the file backend.php