DV Hardware bringing you the hottest news about processors, graphics cards, Intel, AMD, NVIDIA, ATi, hardware and technology!

   Home | News submit | News Archives | Reviews | Articles | Howto's | Advertise
 
DarkVision Hardware - Daily tech news
  Login/sign up  


Main Menu

Home
User account
Info
News archives
Links
Articles
Howto
Reviews
Member list
 

Who's Online
There are currently 295 people and 1 DV-member(s) online.

 

Latest Reviews
  • Laptop Lifts
  • Logitech Illuminated Keyboard
  • ZOWIE P-RF mousepad
  • Cooler Master Storm Sniper case
  • Razer Lachesis mouse
  • Sharkoon PC Jump Start
  • Lowepro Cirrus TLZ 25 camera bag
  • Patriot Xporter Magnum 64GB
  •  

    RSS
    RSS
    RSS by email. Enter your email address:

     

    Worst Windows bugs of the last 10 years

    Posted on Sunday, October 12 2008 @ 15:42:01 CEST by Thomas De Maesschalck


    InfoWorld looks back at the worst flaws in Windows of the past decade. Here's one of the embarrassing security flaws that was discovered in October 2000 in Windows 9x:
    Windows 9x introduced a nifty little concept wherein users could host a password-protected mini file server, aka a share, on their PCs. The idea was simple: Allow users of networked computers to host and share files securely. Only the padlock Microsoft used to lock the door came equipped with a gaping hole that rendered it useless.

    "When processing authentication requests for a NetBIOS share, Windows 95/98 would look at the length of the password sent by the attacker and then only compare that number of bytes to the real password," writes vulnerability expert H.D. Moore, who manages the Metasploit Framework project.

    Oops. "This let the attack specify a password of zero bytes and gain access to the share," without actually knowing the password at all, Moore explains.

    "The real damage," he continues, "was that by trying all characters of incrementing lengths, they could literally obtain the password for share from the server."



    Add to Del.icio.us | Digg It

     
    Threshold
      
    The comments are owned by the poster. We aren't responsible for their content.
     

    DV Hardware - Privacy statement
    All logos and trademarks are property of their respective owner.
    The comments are property of their posters, all the rest © 2002-2009 DM Media Group bvba