• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

Take Note - Patch all your Windows PC's

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    Take Note - Patch all your Windows PC's

    http://www.microsoft.com/technet/sec.../ms06-040.mspx

    This update resolves a privately disclosed vulnerability as well as additional issues discovered through internal investigations.

    An attacker who successfully exploited the vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

    We recommend that customers apply the update immediately

    Vulnerability Identifiers Impact of Vulnerability Windows 2000 Windows XP Service Pack 1 Windows XP Service Pack 2 Windows Server 2003 Windows Server 2003 Service Pack 1
    Buffer Overrun in Server Service Vulnerability - CVE-2006-3439
    Remote Code Execution
    Critical
    Critical
    Critical
    Critical
    Critical

    Aggregate Severity of All Vulnerabilities

    Critical
    Critical
    Critical
    Critical
    Critical

    #2
    Which is worse, hackers or Microsoft updates? Haven't updated my win2000 since the last service pack I downloaded completely screwed the system.
    bloggoth

    If everything isn't black and white, I say, 'Why the hell not?'
    John Wayne (My guru, not to be confused with my beloved prophet Jeremy Clarkson)

    Comment


      #3
      It's up to you Xog.

      The DHS was most concerned about the flaw identified in the MS06-040 security report. This identified a problem with the Windows server service that allows attackers to take over machines without users doing anything to help.

      A worm written to exploit this bug "could enable an attacker to remotely take control of an affected system and install programs, view, change, or delete data, and create new accounts with full user rights," said the DHS in a statement. As well as overseeing efforts to combat terrorism the DHS also has a role in cybersecurity.
      There are worms out there now taking over PC's that have not been patched.

      Once they have control they can do anything, install anything, delete everything. You probably will never know.

      PS Maybe I'm lucky but i've never had a patch or service pack go bad on me.

      Comment


        #4
        Originally posted by DimPrawn

        Once they have control they can do anything, install anything, delete everything. You probably will never know.

        Sounds like everyone in our IT department

        Comment


          #5
          Mine was updated last night, the updates knocked out the Linksys card settings, reset the firewall and IE has now working very slow. I wasted an hour and a half getting the settings right again. Microsoft, craapp products but creating work in the IT sector.
          "A people that elect corrupt politicians, imposters, thieves and traitors are not victims, but accomplices," George Orwell

          Comment


            #6
            Originally posted by Phoenix
            Sounds like everyone in our IT department
            Excellent Old Bean !!!!

            Comment


              #7
              Originally posted by DimPrawn
              PS Maybe I'm lucky but i've never had a patch or service pack go bad on me.
              I have - the infamous NT4 SP6 which f**ked 20 servers, and my contract extension.
              His heart is in the right place - shame we can't say the same about his brain...

              Comment


                #8
                Wouldn't you notice after the 1st one went wrong?

                Or do that rather quaint IT practice called "testing"?

                Comment


                  #9
                  Originally posted by DimPrawn
                  Or do that rather quaint IT practice called "testing"?
                  When I asked one client about automated testing I had a few strange looks as if I was some kind of weirdo

                  Comment


                    #10
                    Listen to my last album on Spotify

                    Comment

                    Working...
                    X