<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; full-disclosure</title>
	<atom:link href="http://www.darknet.org.uk/tag/full-disclosure/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Windows Help Vulnerability Exploited In The Wild</title>
		<link>http://www.darknet.org.uk/2010/06/windows-help-vulnerability-exploited-in-the-wild/</link>
		<comments>http://www.darknet.org.uk/2010/06/windows-help-vulnerability-exploited-in-the-wild/#comments</comments>
		<pubDate>Fri, 18 Jun 2010 10:56:04 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[full-disclosure]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hacking xp]]></category>
		<category><![CDATA[hacking-windows-XP]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft patch tuesday]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[out of bound patch]]></category>
		<category><![CDATA[patch-tuesday]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[responsible disclosure]]></category>
		<category><![CDATA[tavis ormandy]]></category>
		<category><![CDATA[vulnerability disclosure]]></category>
		<category><![CDATA[windows xp exploit]]></category>
		<category><![CDATA[windows xp security]]></category>
		<category><![CDATA[windows xp vulnerability]]></category>
		<category><![CDATA[Windows-XP]]></category>
		<category><![CDATA[xp hacking]]></category>
		<category><![CDATA[xp security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2710</guid>
		<description><![CDATA[So the other big news this week apart from the AT&#038;T iPad/iPhone 4 screw-up is that a recently announced critical vulnerability in Windows XP is being exploited in the wild. It was disclosed fairly recently and is a vulnerability in the Windows XP help system disclosed by Tavis Ormandy, a Google researcher who has appeared [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>So the other big news this week apart from the <a href="http://www.darknet.org.uk/2010/06/iphone-4-pre-order-system-exposes-customer-data/">AT&#038;T iPad/iPhone 4</a> screw-up is that a recently announced critical vulnerability in <a href="http://www.darknet.org.uk/tag/windows-xp/">Windows XP</a> is being exploited in the wild.</p>
<p>It was disclosed fairly recently and is a vulnerability in the Windows XP help system disclosed by <a href="http://www.darknet.org.uk/tag/tavis-ormandy/">Tavis Ormandy</a>, a <a href="http://www.darknet.org.uk/tag/google/">Google</a> researcher who has appeared on this site quite a number of times.</p>
<p>It&#8217;s dangerous because a victim can be compromised completely (including remote code execution) just by visiting a malicious web page.</p>
<blockquote><p>Five days after it was disclosed in a highly controversial advisory, a critical vulnerability in Microsoft&#8217;s Windows XP operating system is being exploited by criminal hackers, researchers from anti-virus provider Sophos said on Tuesday.</p>
<p>The flaw in the Windows Help and Support Center was disclosed on Thursday by researcher Tavis Ormandy. His public advisory came just five days after he privately informed Microsoft of the defect, prompting fierce criticism from some circles that he hadn&#8217;t given the software giant adequate time to fix the hole. That made it easier for attackers to target the bug, which allows attackers to take complete control of vulnerable machines when a user views a specially designed webpage, the critics howled.</p>
<p>According to Sophos, researchers have seen the first case of a website using the vulnerability to install malicious software on victim machines. “This malware downloads and executes an additional malicious component (Troj/Drop-FS) on the victim’s computer, by exploiting this vulnerability,” they warned.</p></blockquote>
<p>Well there&#8217;s some discussion on the issue going on about responsible disclosure with people saying Tavis made the advisory public too quickly after informing Microsoft. It&#8217;s a fair comment considering Microsoft and it&#8217;s <a href="http://www.darknet.org.uk/tag/patch-tuesday/">Patch Tuesday</a> policy which limits the speed in which they can push patches out.</p>
<p>We all know how often Microsoft pushes <a href="http://www.darknet.org.uk/tag/out-of-band-patch/">out-of-bound patches</a> out, very rarely if at all.</p>
<p>Add the fact that Windows XP is coming to the end of it&#8217;s life-cycle soon, it&#8217;s unlikely they are going to be scrambling to get a patch out.</p>
<blockquote><p>Microsoft soon amended its own advisory on the vulnerability to say researchers are “aware of limited, targeted active attacks that use this exploit code.” Although the vulnerability also afflicts Windows Server 2003, Microsoft&#8217;s advisory said that OS wasn&#8217;t “currently at risk from these attacks.”</p>
<p>Ormandy&#8217;s advisory has reignited the age-old debate over full disclosure, in which researchers publish complete details of a vulnerability under the belief that it is the best way to ensure a company fixes it quickly. Ormandy has defended his decision to give Microsoft just five days of advanced warning saying in a recent tweet: “I&#8217;m getting pretty tired of all the &#8217;5 days&#8217; hate mail. Those five days were spent trying to negotiate a fix within 60 days.”</p>
<p>Users of XP and Server 2003 should consider disabling features within Help Center that allow administrators to remotely log onto machines. </p></blockquote>
<p>Oh well, the debates about disclosure will rage on I guess, either way it&#8217;s out there now and it&#8217;s being exploited in the wild &#8211; so as of now it&#8217;s a real risk.</p>
<p>For individual users you can use the online application from Microsoft here:</p>
<p><a href="http://support.microsoft.com/kb/2219475">Vulnerability in Help Center could allow remote code execution</a></p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2010/06/15/windows_help_bug_exploited/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Windows+Help+Vulnerability+Exploited+In+The+Wild+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2710+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/06/windows-help-vulnerability-exploited-in-the-wild/&amp;t=Windows+Help+Vulnerability+Exploited+In+The+Wild" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/06/windows-help-vulnerability-exploited-in-the-wild/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/06/windows-help-vulnerability-exploited-in-the-wild/&amp;title=Windows+Help+Vulnerability+Exploited+In+The+Wild" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/06/windows-help-vulnerability-exploited-in-the-wild/&amp;title=Windows+Help+Vulnerability+Exploited+In+The+Wild" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/06/windows-help-vulnerability-exploited-in-the-wild/&amp;title=Windows+Help+Vulnerability+Exploited+In+The+Wild" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/06/windows-help-vulnerability-exploited-in-the-wild/&amp;title=Windows+Help+Vulnerability+Exploited+In+The+Wild" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F06%2Fwindows-help-vulnerability-exploited-in-the-wild%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/06/windows-help-vulnerability-exploited-in-the-wild/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vista Security Claims Debunked &#8211; Figures Skewed</title>
		<link>http://www.darknet.org.uk/2007/08/vista-security-claims-debunked-figures-skewed/</link>
		<comments>http://www.darknet.org.uk/2007/08/vista-security-claims-debunked-figures-skewed/#comments</comments>
		<pubDate>Tue, 21 Aug 2007 09:00:04 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[full-disclosure]]></category>
		<category><![CDATA[hacking-vista]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[severity]]></category>
		<category><![CDATA[vista]]></category>
		<category><![CDATA[vista-exploits]]></category>
		<category><![CDATA[vista-security]]></category>
		<category><![CDATA[vista-teredo]]></category>
		<category><![CDATA[vista-vulnerabilities]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/08/vista-security-claims-debunked-figures-skewed/</guid>
		<description><![CDATA[Ah more news about the insecurity of Vista and something we are all pretty aware of&#8230;the skewing of figures by Microsoft. Microsoft apparently still hasn&#8217;t learned that counting vulnerabilities doesn&#8217;t establish some kind of &#8216;security level&#8217;. You can read the report here: Vista 6 Month Vuln Report [PDF] The Microsoft &#8220;researcher&#8221; claims that Windows Vista [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Ah more news about the insecurity of Vista and something we are all pretty aware of&#8230;the skewing of figures by Microsoft.</p>
<p>Microsoft apparently still hasn&#8217;t learned that counting vulnerabilities doesn&#8217;t establish some kind of &#8216;security level&#8217;.</p>
<p>You can read the report here:</p>
<p><a href="http://www.csoonline.com/pdf/6_Month_Vista_Vuln_Report.pdf">Vista 6 Month Vuln Report [PDF]</a></p>
<blockquote><p>The Microsoft &#8220;researcher&#8221; claims that Windows Vista is exponentially less vulnerable than many Linux distributions and Mac OS X. It may be true that the default Vista installation has had less public vulnerability reports, and that Linux has had many more, but this is due to the nature of Open Source. Jeff does not include any &#8220;silently fixed&#8221; vulnerabilities that have been patched since Vista was released and Microsoft has not disclosed such vulnerabilities publicly. </p></blockquote>
<p>The methodology used was deeply flawed, as I briefly mentioned before, bugs in Firefox and other software like emacs count as a flaw for Linux whilst IE bugs get ignored for Vista.</p>
<blockquote><p>The conclusions that are drawn are built on a lack of understanding by the Microsoft researcher. I highly encourage him to go back and take another look, and pare down the results to essential information that is absolutely critical to the conclusions, rather than just &#8220;Other OS&#8217;s have more bugs, see, look at my graphs&#8221;&#8230; </p></blockquote>
<p>Good PR, but bad research? Seems par for the course.</p>
<p>And perhaps it could backfire PR wise, as the clued in people get pushed further away from Vista.</p>
<p></p>
<p>Source: <a href="http://seclists.org/fulldisclosure/2007/Jun/0528.html">Full Disclosure</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Vista+Security+Claims+Debunked+%E2%80%93+Figures+Skewed+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D616+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/08/vista-security-claims-debunked-figures-skewed/&amp;t=Vista+Security+Claims+Debunked+%E2%80%93+Figures+Skewed" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/08/vista-security-claims-debunked-figures-skewed/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/08/vista-security-claims-debunked-figures-skewed/&amp;title=Vista+Security+Claims+Debunked+%E2%80%93+Figures+Skewed" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/08/vista-security-claims-debunked-figures-skewed/&amp;title=Vista+Security+Claims+Debunked+%E2%80%93+Figures+Skewed" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/08/vista-security-claims-debunked-figures-skewed/&amp;title=Vista+Security+Claims+Debunked+%E2%80%93+Figures+Skewed" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/08/vista-security-claims-debunked-figures-skewed/&amp;title=Vista+Security+Claims+Debunked+%E2%80%93+Figures+Skewed" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F08%2Fvista-security-claims-debunked-figures-skewed%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/08/vista-security-claims-debunked-figures-skewed/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

