Windows Vista Forums
Vista Forums Home Join Vista Forums Windows 7 Forum Vista Tutorials Tags
Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks.

Go Back   Vista Forums > Vista Newsgroups > Vista security

Vista - New Vista Security Flaws - Should we be concerned?

Reply
 
Old 02-06-2007   #1 (permalink)
Roscoe


 
 

New Vista Security Flaws - Should we be concerned?

Should we be concerned about two more dangerous exploits/security flaws
uncovered by “Long” and “Zheng” (two Swedish security experts using these
names to hide their identity from Microsoft)?:

"The first exploit is a bug inside the keyboard and mouse subsystem which
enables the targeted system to be hijacked and maliciously delete files,
folders, music, torrents and other important sounding stuff without the user’s
authorization or control.

Details of how such an exploit works are sketchy, but leaked documents
reveal the keyboard and mouse APIs offers unprecedented amount of control
over an operating system, allowing anyone and everyone to have full access
to your computer with or without your authorization. This exploit allows
anyone ranging from younger siblings to gang leaders who could use brute
force, such as a punch or tickle, to gain access to your keyboard and mouse
cursors and perform malicious activities such as browsing The Inquirer or
deleting vital fraudulent financial documents.

A second exploit highlights a serious flaw inside the popular
Windows-platform development tool, Visual Studio. An undocumented feature
inside this software is said to enable the ability for malicious users to
compile and execute unsigned and potentially damaging source code. If users
somehow come across malicious source code and decide to copy, paste, compile
and execute within Visual Studio, the resulting application could change
wallpapers, block access to YouTube, increase the volume and other serious
irreversible damages to the computer system."


My System SpecsSystem Spec
Old 02-06-2007   #2 (permalink)
Mark Burnett


 
 

Re: New Vista Security Flaws - Should we be concerned?

> This exploit allows anyone ranging from younger siblings to gang leaders
> who could use brute force, such as a punch or tickle, to gain access to
> your keyboard and mouse


Read it again, its a joke.



My System SpecsSystem Spec
Old 02-06-2007   #3 (permalink)
akita


 
 

Re: New Vista Security Flaws - Should we be concerned?

"Mark Burnett" wrote:

> Read it again, its a joke.


Sorry Mark, but NO, it ain't a joke! Read here:

http://www.istartedsomething.com/200...vista-exploits
My System SpecsSystem Spec
Old 02-06-2007   #4 (permalink)
Mark Burnett


 
 

Re: New Vista Security Flaws - Should we be concerned?

> Sorry Mark, but NO, it ain't a joke! Read here:
>
> http://www.istartedsomething.com/200...vista-exploits


Haha, just because it has a url doesn't mean its not a joke.

Vulnerability one:
- Vista allows someone to hijack a computer due to a flaw in the "keyboard
and mouse subsystem"
- "This exploit allows anyone...who could use brute force, such as a punch
or tickle, to gain access to your keyboard

Vulnerability two:
- Visual Studio allows malicious users to "compile and execute unsigned and
potentially damaging source code"
- "If users somehow come across malicious source code and decide to copy,
paste, compile and execute within Visual Studio, the resulting application
could change wallpapers, block access to YouTube, increase the volume and
other serious irreversible damages to the computer system."

and also:

"Next week, keep an eye out for the exclusive report on why Solitaire is a
fire hazard. How the end-game fireworks might burn down your operating
system."

etc.




My System SpecsSystem Spec
Old 02-08-2007   #5 (permalink)
Jesper


 
 

Re: New Vista Security Flaws - Should we be concerned?

"Mark Burnett" wrote:

> > Sorry Mark, but NO, it ain't a joke! Read here:
> >
> > http://www.istartedsomething.com/200...vista-exploits

>
> Haha, just because it has a url doesn't mean its not a joke.


Watch for your favority security vendor to publish Intrusion Prevention
System signatures soon to protect you against these types of glaring issues.
I heard the leading analyst organizations are preparing statements to warn
people too.

My System SpecsSystem Spec
Old 02-08-2007   #6 (permalink)
Dennis Pack


 
 

Re: New Vista Security Flaws - Should we be concerned?

Jesper:
Hopefully there will be a better tool. The only tool that's been
able to control the loose nut behind this keyboard is to turn the computer
off. Have a great day.

--
Dennis Pack
XP x64, Vista Enterprise x64
Office2007
"Jesper" <Jesper@discussions.microsoft.com> wrote in message
news:5E712D63-9DC7-48F1-9371-DC170BEB67A2@microsoft.com...
> "Mark Burnett" wrote:
>
>> > Sorry Mark, but NO, it ain't a joke! Read here:
>> >
>> > http://www.istartedsomething.com/200...vista-exploits

>>
>> Haha, just because it has a url doesn't mean its not a joke.

>
> Watch for your favority security vendor to publish Intrusion Prevention
> System signatures soon to protect you against these types of glaring
> issues.
> I heard the leading analyst organizations are preparing statements to warn
> people too.
>


My System SpecsSystem Spec
Old 02-08-2007   #7 (permalink)
Kevin Spencer


 
 

Re: New Vista Security Flaws - Should we be concerned?

In fact, I understand the leading keyboard manufacturers are working on some
safegurads - childproof keyboard covers and fingerprint-sensitive mice.

--

Kevin Spencer
Microsoft MVP
Software Composer
http://unclechutney.blogspot.com

The shortest distance between 2 points is a curve.

"Jesper" <Jesper@discussions.microsoft.com> wrote in message
news:5E712D63-9DC7-48F1-9371-DC170BEB67A2@microsoft.com...
> "Mark Burnett" wrote:
>
>> > Sorry Mark, but NO, it ain't a joke! Read here:
>> >
>> > http://www.istartedsomething.com/200...vista-exploits

>>
>> Haha, just because it has a url doesn't mean its not a joke.

>
> Watch for your favority security vendor to publish Intrusion Prevention
> System signatures soon to protect you against these types of glaring
> issues.
> I heard the leading analyst organizations are preparing statements to warn
> people too.
>



My System SpecsSystem Spec
Reply

Thread Tools


Similar Threads
Thread Forum
Re: Microsoft, Adobe warn of critical security flaws .NET General
Should I be concerned? General Discussion
Vista is generally ok, but has it's flaws Vista General
Bounty for Identifying Vista Security Flaws Vista General
Why some of us are concerned about Vista Vista General


Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46