internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Adobe Flash Player

Most Popular Software Downloads
Windows Vista Service Pack 2 (Vista SP2)
Mozilla Firefox 3
QuickTime for Windows
Adobe Flash Player
Windows 7
Norton Internet Security 2010
Internet Explorer 8
CCleaner (Crap Cleaner)
Winamp
Skype

Most Popular Software Articles
Windows Vista Tips: Home Networking Setup Tutorial
10 Must-Have Apps: The Free Windows Networking Toolkit
How to Make Your Internet Connection Faster, Better


Software Reviews

Researcher Finds Flaws in XP SP2
Advisory Issued for Pair of Security Flaws
Ryan Naraine

Windows XP Service Pack 2 German research firm Heise Security has issued an advisory for a pair of security flaws in Microsoft's recently shipped Windows XP Service Pack 2 with a warning that attackers could launch malicious files from an untrusted zone.

According to the alert posted online, Heise said two vulnerabilities in the implementation of a new "security warning" feature in SP2 opens the door for the spread of harmful viruses.

The flaws occur because the Windows command shell ignores zone information and starts executables without warnings. Heise Security said the second bug relates to the inability of the Windows Explorer feature to update zone information properly when files are overwritten.

"[Windows Explorer] can be tricked to execute files from the Internet without warning," the firm said.

According to the advisory, Microsoft investigated the warnings and found that they were not in conflict with the design goals of the new protections built into XP.

"We are always seeking improvements to our security protections, and this discussion will certainly provide additional input into future security features and improvements, but at this time we do not see these as issues that we would develop patches or workarounds to address," Microsoft explained.

However, Heise said there was evidence that XP SP2 will launch malicious files without warning the user.

"Exploitation of this issue requires some user interaction — at least as long as nobody comes up with a way to execute cmd.exe with parameters from within Outlook Express or Internet Explorer," the company said, noting that virus writers could create e-mail worms to launch files without getting a warning from SP2.

News courtesy of internetnews.com

August 19, 2004


Download Windows XP SP2 Now!Download

View All Microsoft Service Packs

Contents:
1. Advisory Issued for Pair of Security Flaws


Additional Articles:

  • Windows XP Service Packs: What's New in XP SP2
  • Windows XP SP2 Inches Closer
  • XP SP2 Launch Price: $300 Million
  • XP SP2: Do's & Don'ts for Web Sites
  • Windows XP SP2 Comes Closer with RC2
  • August It Is for XP SP2
  • Microsoft's XP SP2 Arrives
  • Microsoft XP SP2 Blog Watch
  • XP SP2 Warning List Released
  • XP SP2 Delivery Schedule Adjusted
  • MS Releases XP SP2 App Testing Guide
  • XP SP2 Deadline Extended
  • Microsoft Releases Scanning Tool
  • XP SP2 Downloads Surpass 100M Mark
  • Enterprise Foot-Dragging on XP SP2
  • Windows XP SP2 Said at Risk From Heap Overflow
  • Do You SP2?
  • Windows XP Service Pack 3 Pushed Back to 2008
  • Would You Like 'XP' With That PC?
  • Vista, XP Service Pack Changes Revealed
  • Public Test for XP Service Pack 3
  • Windows XP Service Pack 3? Place Your Bets
  • Microsoft: XP Not Out to Pasture Yet
  • Get the Latest on Windows XP SP3
  • Windows XP SP3 Just Around The Corner
  • When Is a Downgrade a Good Thing?
  • No XP Service Pack 3 for You Today
  • On Again, Off Again, XP SP3 Back On
  • XP SP3 Glitch a 'Gotcha' for IE7 & IE8
  • Microsoft Just Can't Kill XP
  • Meet Microsoft's New Embedded OS: Windows XP
  • XP's 'Last Day' Less Final Than Gates'
  • Dell Finds a Way to Continue XP Sales
  • Microsoft to Begin Pushing XP SP3 to Users
  • Business PC Buyers Pick Windows XP Over Vista
  • Windows XP Gets Another Life Extension
  • XP/Vista SP Blockers to Expire as Vista Surges
  • Another Reprieve for Microsoft's XP 'Downgrades'
  • 'Mainstream' Support for XP Ends Today


  • internet.commediabistro.comJusttechjobs.comGraphics.com

    Search:

    WebMediaBrands Corporate Info

    Legal Notices, Licensing, Permissions, Privacy Policy.
    Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs