Advertisement
Promo

Security threats Toolkit

Windows users: 'Don't panic' over flaw

Munir Kotadia ZDNet.co.uk

Published: 11 Feb 2004 11:55 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Windows users have been told not to panic after news of the latest Windows security bug made front page headlines in many of the UK's national newspapers.

Antivirus company Sophos has advised users to keep a sense of proportion and "calmly ensure all computers are correctly patched". The company said that as yet, there have not been any hackers or worms exploiting the flaws.

Graham Cluley, senior technology consultant at Sophos said: "With doom-laden headlines in the newspapers about this bug in Windows, users need to keep a sense of proportion. At the moment we haven't seen any hackers or worms exploiting this hole, but that doesn't mean that computer users don't need to protect their PCs."

"This announcement couldn't have come at a worse time for Microsoft, as it tries to build its reputation for security," said Cluely.

Antivirus company TruSecure confirmed that there have so far been no incidents exploiting the security hole, which affects the way Windows handles digital certificates.

TruSecure said business should give highest priority for patching to domain controllers, Exchange servers, Internet Information Servers (IIS) which use certificates and VPN and firewall appliances that accept authenticated connections.

"Microsoft's critical network security infrastructure components must be patched immediately to ensure the on-going, and significant trust businesses place in them," said TruSecure chief scientist Russ Cooper in a statement.

EEye, the company that discovered the flaw, had to wait six months before Microsoft released a fix. The company said the extended wait allowed it time to compose a lengthy song to accompany the release of the security advisory. "U can't trust this" is credited to MC(SE) Hammer and makes its own comment on Windows security.

Blaster did ya some harm
We just say, hey, another worm
But thank you, for trusting me
To mind your site's security
It's all good, when your server's downed
Our dope PR will pass blame around
Cuz it's known as such
That this is some software, you can't trust

The advisory, with the rest of the song's lyrics, is available from eEye's Web site. Microsoft's patch is available here.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
87 out of 166 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

1 comment

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters