DV Hardware bringing you the hottest news about processors, graphics cards, Intel, AMD, NVIDIA, ATi, hardware and technology!

   Home | News submit | News Archives | Reviews | Articles | Howto's | Advertise
 
DarkVision Hardware - Daily tech news
  Login/sign up  


Main Menu

Home
User account
Info
News archives
Links
Articles
Howto
Reviews
Member list
 

Who's Online
There are currently 108 people and 0 DV-member(s) online.

 

Latest Reviews
  • Enermax Aeolus Premium CP003
  • Altego Clear Laptop Sleeve
  • Lian Li PC-V354
  • Arctic Cooling K381 keyboard
  • Arctic Power Charger Plus
  • ATP PhotoFinder Mini
  • BitFenix Colossus
  • Roccat Taito Kingsize mTw Edition mousepad
  •  

    RSS
    RSS
     

    Microsoft finally plugs 8-year old security bug

    Posted on Thursday, November 13 2008 @ 01:08:35 CET by Thomas De Maesschalck


    CNET reports Microsoft has finally fixed a security flaw that was discovered in 2000, with code first published in March 2001.
    That means that a known security vulnerability related to a Microsoft authentication protocol sat on your Windows box for more than seven years, waiting for Microsoft to get around to fixing it:

    This vulnerability allows an attacker to redirect an incoming SMB connection back to the machine it came from and then access the victim machine using the victim's own credentials. (Hence the term "credential reflection").

    In typical Windows XP configurations, where SMB sharing is enabled, and the user is a member of the Administrators group, this allows the attacker to easily take over the machine. Public tools, including a Metasploit module, are available to perform this attack.



     
    Threshold
      
    The comments are owned by the poster. We aren't responsible for their content.
     

    DV Hardware - Privacy statement
    All logos and trademarks are property of their respective owner.
    The comments are property of their posters, all the rest © 2002-2012 DM Media Group bvba