Eye on Security: Windows is Vulnerable, GNU/Linux is Not
- Dr. Roy Schestowitz
- 2010-06-11 21:17:22 UTC
- Modified: 2010-06-11 21:17:22 UTC
Summary: Today's examples of security weaknesses in Windows (which help justify Google's recent abandonment of Windows on the desktop)
●
Microsoft Security Vulnerability Disclosed (no
silent patches yet?)
Microsoft was left racing to patch a Windows Help and Support Center vulnerability after Tavis Ormandy, an information security researcher who's charged with keeping Google's products secure, Thursday publicly disclosed both the bug as well as proof-of-concept attack code.
Ormandy reportedly informed Microsoft of the vulnerability on Saturday, June 5, and Microsoft acknowledged receipt the same day. Five days later, however, Ormandy went public with a posting to the Full Disclosure mailing list. Later that day, Microsoft issued its own vulnerability announcement.
●
Bug gives attackers complete control of Windows PCs [
via]
A security researcher has warned of a vulnerability in older versions of the Windows operating system that allows attackers to take full control of a PC by luring its user to a booby-trapped website.
The flaw resides in the Windows Help and Support Center, a feature that provides users with online technical support. Malicious hackers can exploit the weakness of Windows by embedding commands in web addresses that activate the feature's remote assistance tool, which allows administrators to execute commands over the internet. The exploit works in XP and Server 2003 versions of Windows and possibly others.
●
Malware Squared
Use browsers and operating systems that are more secure. Get away from the monopoly OS that is the main target of attacks. Cut down your risk by a factor of 1000 or so by a single step, migrating to GNU/Linux. It makes sense.
Recent Techrights' Posts
- Richard Matthew Stallman, or rms (RMS), Turns 72 This Coming Weekend
- This coming Sunday he deserves a cake
-
- Expect XBox to Be Shut Down Like Skype
- "hey hi"-washing fools nobody
- Truth Hurts (Especially Some Dishonest and/or Greedy People), But Reporting Truth is What Makes Journalism Valuable to the General Public and Helps Protect Society From Abuse by Sociopaths or Pathological Liars
- When it comes to reporting, we're on the side of female victims, not the men who strangle them.
- New Paper Reveals the Web (and Net) Drowns in LLM Slop, "Linux" is Impacted Too
- It will be getting harder to trust anything on the Web
- Links 13/03/2025: RIP, Carl Lundström; Tesla (the Company, Not Scientist It Piggybacks) Besieged by Public Backlash
- Links for the day
- Gemini Links 13/03/2025: MElon "Greek Tragedy" and Going Offline More
- Links for the day
- Links 13/03/2025: COVID-19 Legacies and "Modern" Cars as Spying Machines on Wheels
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Wednesday, March 12, 2025
- IRC logs for Wednesday, March 12, 2025
- The Fall of the Open Source Initiative (OSI): Microsoft-Sponsored OSI is Probably Not Even the Real Steward of the Open Source Definition, It's More Like an Identity Thief at This Point (Like "FSFE", a Microsoft-Sponsored Imposter of FSF)
- As we'll show later, many people (even inside OSI) are very angry at the OSI right now
- Gemini Links 12/03/2025: Cataloging Books, Ramen, and MElon
- Links for the day
- Links 12/03/2025: Anti-Union Actions and New Efforts at Truce/Ceasefire in Ukraine
- Links for the day
- Sponsored by Linux Foundation
- All the pages are full of 'Linux' Foundation ads that are not about Linux
- CodeWeavers Ads Weaved by LLM Slop at BetaNews
- How much of this was even touched by a human being?
- It's Hard to Dispose or Get Rid of Swasticars Now
- 'Memecars' only sell as long as people have a 'belief' in them
- Springtime Plans
- We currently have two long series underway
- In Australia, iOS Estimated to be Bigger Than or Equal to Windows
- Not even counting macOS
- Brett Wilson LLP Does Not Deny Microsoft or Another "Third Party" Secretly Funds the SLAPPs Against Techrights, Bankrolling Despicable People Who Deserve Criticism
- Writing about crime is not a crime
- Gemini Links 12/03/2025: LLM Slop Lacks a Future, Wordle Clone Comes to Gemini Protocol
- Links for the day
- Using FUD That Blames "Linux" for Typos, Turning It Into LLM Slop That Blames "Linux" for Typos
- It is probably the "leader" at LLM slop (fake 'articles') about "Linux"
- Links 12/03/2025: Big Cuts to US Education and Science (e.g. NOAA)
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Tuesday, March 11, 2025
- IRC logs for Tuesday, March 11, 2025
- Crossbow murders: prevention, missed opportunities
- Reprinted with permission from Daniel Pocock
- This yt-dlp Bug Report Shows Us That the Future of YouTube is DRM and It's Time to Leave (yt-dlp Should Also Leave Microsoft GitHub, Which Censors YouTube Downloaders)
- GAFAM traps aren't "free hosting"; they herd us all into a world of tollbooths and locks, surveillance and planned obsolescence (you own nothing, you only rent)
- Ukraine Didn't Take Twitter/X Down, Microsoft or Windows Likely Did
- There are many debunkings (to likely false accusations), but won't that just be another example of Windows TCO, exacerbated externally in the form of Windows botnets?
- The Fall of the Open Source Initiative (OSI): Worse Than What the Media Has Focused on, Losing Sight of Who Owns and Runs the OSI
- Members' dues are less than 3% of the income; where does the 97+ percent come from other than Microsoft?
- Apple Seems to Have Run Out of Things to Boast About After Apple Vision Pro Failed Spectacularly
- With "Apple Intelligence", Apple has finally named a product after what target customers lack
- Slopwatch: Reckless FUD and Machine-Generated Spam from LinuxSecurity.com, cybersecuritynews.com, and gbhackers.com (Google Boosts LLM Slop About "Linux")
- Google and so-called 'Google News' continue to yield anti-Linux misinformation
- Gemini Links 11/03/2025: 'Chainsaw Politicians' and Proprietary Software Hell
- Links for the day
- Links 11/03/2025: Covid-19 5 Years On and Violence in Syria
- Links for the day
- Links 11/03/2025: NASA Besieged and "DOGE Has Become What It Claimed To Destroy"
- Links for the day
- Fresh IBM Layoffs Reported in Europe and North America, Jobs Allegedly Moved to South Asia (Low Salaries)
- As usual, IBM does not talk about this
- Illuminating Injustice is Critical When Reckless Microsofters and Law Firms Try to Silence Reporters of Violence Against Women
- I want to clarify that I'm well within my right (and not running afoul of any rules) by explaining what goes on here
- EPO Central Staff Committee: "The Strategy of the Office Lacks Transparency and Cannot be Understood"
- Microsoft and the EPO violate data protection laws
- Microsoft Has Not Much Left to Show Investors, Shares Fall Almost 20%
- It's not even clear how Microsoft makes money anymore
- Links 11/03/2025: Spring and Misfin Server
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Monday, March 10, 2025
- IRC logs for Monday, March 10, 2025