.com.unity Forums

.com.unity Forums (http://forum.shrapnelgames.com/index.php)
-   Dominions 3: The Awakening (http://forum.shrapnelgames.com/forumdisplay.php?f=138)
-   -   OT: Serious Windows & Adobe Security Flaw (http://forum.shrapnelgames.com/showthread.php?t=36612)

Edi October 27th, 2007 05:08 PM

OT: Serious Windows & Adobe Security Flaw
 
I've posted this same in a couple of other forums I frequent, so I decided to do the same here. Since I need to deal with fallout from crap like this at work, might as well spread the word and help the Dom3 community avoid the problem.

http://www.theregister.co.uk/2007/10...o_fix_windows/

Basically, there's a serious new vulnerability related to Windows handling 3rd party programs, another big one in Adobe and it's often triggered by malicious PDFs. Patch your Adobe Reader to v8.1.1 and be on your toes after that. Even then, you might get hosed. Machines that get infected by the Adobe PDF vulnerability or through the Windows one tend to become spam servers spewing out maliciously constructed PDFs to spread the infection.

Just so you have a heads up on this, it's very recent, but I've already run into one case at work. If it doesn't get patched soon, it'll get worse.

Another thing regarding the malware (type unknown) I encountered: It has at least some anti-AV capabilities, since it was able to evade detection by F-Secure software except indirectly and could apparently interfere with the scanning process and abort it prematurely. That kind of crap is a real ***** and half and then some to root out of a machine and you generally need at least half a dozen different programs to make sure. Most often it's easiest to nuke the site from orbit and do a complete reinstall, which is at least as much of a hassle if you need to do extensive data backups first. I don't know what other big name AV software besides F-Secure might be affected, but Norton would be one good candidate, so would CA, Panda, TrendMicro and other significant security software vendors.

lch October 27th, 2007 05:13 PM

Re: OT: Serious Windows & Adobe Security Flaw
 
Alternatively, uninstall Windows. http://forum.shrapnelgames.com/images/smilies/happy.gif

(come on, somebody HAD to do it!)

Evil Dave October 27th, 2007 05:58 PM

Re: OT: Serious Windows & Adobe Security Flaw
 
Ich beat me to it: "serious vulnerability in Windows" is not news. http://forum.shrapnelgames.com/images/smilies/wink.gif [img]/threads/images/Graemlins/MacLogo.gif[/img] http://forum.shrapnelgames.com/image...es/Penguin.gif

Autochthon October 27th, 2007 06:39 PM

Re: OT: Serious Windows & Adobe Security Flaw
 
Quote:

lch said:
Alternatively, uninstall Windows. http://forum.shrapnelgames.com/images/smilies/happy.gif

(come on, somebody HAD to do it!)

I would, but the withdrawal pains would mess me up pretty badly http://forum.shrapnelgames.com/image...ies/tongue.gif

Hopefully, with WinDoze being so widespread, someone will figure out a fix before this gets out of hand.

Tuidjy October 28th, 2007 12:08 AM

Re: OT: Serious Windows & Adobe Security Flaw
 
I found this on a PC at my workplace as well, less than 8 hours ago. I went with a
full wipe (easy when all your desktops are not much more than dumb terminals) What
really pisses me off is that the vulnerability is due to a problem with Explorer7,
which the user installed against company policy... but given that she is one of
the owners, she gets to keep her administrator account. On the other hand, I'm
testing whether she will notice that I forgot to add it to the administrator group.

If you have to have Windows, just make sure that you do not upgrade Explorer beyond
six unless an application you need requires it. There is a patch for Adobe, but
the vulnerability exists in a number of other applications, because it is a
problem of Microsoft's, not one of the third parties.

Lord_Bob October 28th, 2007 01:07 PM

Older is more stable, and less bugs
 
One of the good things about people being forced to upgrade, but no actual improvements happening is that you can use the old stuff, like Windows 2000, and you don't have any bug problems. It's really irritating actually that QuatroPro hasn't got any better since Fast Hand's Bill stole it and renamed it "Excel". But that's pretty much Bill Gate's entire carreer. Look up "Gary Kildall" to see what I mean.

Hadrian_II October 28th, 2007 03:32 PM

Re: Older is more stable, and less bugs
 
Is this not the same bug that made problems with firefox before and microsoft did say that there is nothing wrong with their software?

things like that dont happen on linux
SCNR

Edi October 28th, 2007 04:06 PM

Re: Older is more stable, and less bugs
 
Yes, it is, except the Firefox crew patched their software, thus eliminating that particular attack vector, but it is now a confirmed issue with IE and the Windows XP operating system in general.

Velusion October 29th, 2007 03:36 AM

Re: Older is more stable, and less bugs
 
This isn't a problem with Vista for those curious.


All times are GMT -4. The time now is 11:40 AM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Copyright ©1999 - 2025, Shrapnel Games, Inc. - All Rights Reserved.