Advertisement
Promo

Security threats Toolkit

Windows users: 'Don't panic' over flaw

Munir Kotadia ZDNet.co.uk

Published: 11 Feb 2004 11:55 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Windows users have been told not to panic after news of the latest Windows security bug made front page headlines in many of the UK's national newspapers.

Antivirus company Sophos has advised users to keep a sense of proportion and "calmly ensure all computers are correctly patched". The company said that as yet, there have not been any hackers or worms exploiting the flaws.

Graham Cluley, senior technology consultant at Sophos said: "With doom-laden headlines in the newspapers about this bug in Windows, users need to keep a sense of proportion. At the moment we haven't seen any hackers or worms exploiting this hole, but that doesn't mean that computer users don't need to protect their PCs."

"This announcement couldn't have come at a worse time for Microsoft, as it tries to build its reputation for security," said Cluely.

Antivirus company TruSecure confirmed that there have so far been no incidents exploiting the security hole, which affects the way Windows handles digital certificates.

TruSecure said business should give highest priority for patching to domain controllers, Exchange servers, Internet Information Servers (IIS) which use certificates and VPN and firewall appliances that accept authenticated connections.

"Microsoft's critical network security infrastructure components must be patched immediately to ensure the on-going, and significant trust businesses place in them," said TruSecure chief scientist Russ Cooper in a statement.

EEye, the company that discovered the flaw, had to wait six months before Microsoft released a fix. The company said the extended wait allowed it time to compose a lengthy song to accompany the release of the security advisory. "U can't trust this" is credited to MC(SE) Hammer and makes its own comment on Windows security.

Blaster did ya some harm
We just say, hey, another worm
But thank you, for trusting me
To mind your site's security
It's all good, when your server's downed
Our dope PR will pass blame around
Cuz it's known as such
That this is some software, you can't trust

The advisory, with the rest of the song's lyrics, is available from eEye's Web site. Microsoft's patch is available here.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
86 out of 164 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters