Eye on Security: Dangers of Microsoft Windows, Apple hypeTunes
- Dr. Roy Schestowitz
- 2010-08-26 11:30:12 UTC
- Modified: 2010-08-26 11:30:12 UTC
Summary: Proprietary software and its harms - news headlines
●
Windows DLL flaw will be a big headache for end users
●
Microsoft Releases Security Advisory on Windows Application Bugs
"When the application loads one of its required or optional libraries, the vulnerable application may attempt to load the library from the remote network location," Microsoft explained in its advisory. "If the attacker provides a specially crafted library at this location, the attacker may succeed at executing arbitrary code on the user's machine." Remote binary planting bugs "can be exploited over network file systems such as ... WebDAV and SMB."
To prevent these kinds of attacks, Microsoft has issued guidance for developers working with .DLL files. The company also released an "optional mitigation tool that helps customers address the risk of the remote attack vendor through a per-application and global configuration setting."
●
Web scam hits iTunes and Paypal users
Experts told the BBC that victims had most likely fallen for an e-mail scam, rather than being targeted via a flaw in iTunes or Apple servers.
"I just got hacked for $1,000 worth of software, videos and music," tweeted one victim.
Another told the technology blog TechCrunch: "My account was charged over $4,700. I called security at Paypal and was told a large number of iTunes stores accounts were compromised."
Recent Techrights' Posts
- Techrights' Statement on Code of Censorship (CoC) and Kent Overstreet: This Was the Real Purpose of Censorship Agreements All Along
- Bombing people is OK (if you sponsor the key organisations), opposing bombings is not (a CoC in a nutshell)
-
- Patents Against Energy Sources That Reduce Pollution
- this EV space (not just charging) is a patent mine field and it has long been that way
- DARPA’s Information Innovation Office, Howard Shrobe, Values Compartmentalisation But Loses the Opportunity to Promote GNU/Linux and BSDs
- All in all, he misses an opportunity
- Wayland is an Alternative to X
- the alternative to X (as in Twitter) isn't social control media but something like IRC
- BetaNews, Desperate for Clicks, is Pushing Donald Trump Spam Created by LLMs (Slop)
- Big clap to Brian Fagioli for stuffing a "tech" site with Trump spam (not the first time he uses LLMs to do this)
- [Meme] Social Control Media Bliss
- "My tree is bigger than yours"
- Links 24/11/2024: More IMF Bailouts and Net Client Freedom
- Links for the day
- Gemini Links 24/11/2024: Being a Student and Digital Downsizing
- Links for the day
- [Meme] The Most Liberal Company
- "Insurrection? What insurrection?"
- apple.com Traffic Down Over 7%, Says One Spyware Firm; Apple's Liabilities Increased Over 6% to $308,030,000,000
- Apple is also about 120 billion dollars in debt
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Saturday, November 23, 2024
- IRC logs for Saturday, November 23, 2024
- [Meme] GAFAMfox
- Mozilla Firefox in a state of extreme distress
- Google Can Kill Mozilla Any Time It Wants
- That gives Google far too much power over its rival... There are already many sites that refuse to work with Firefox or explicitly say Firefox isn't supported
- Free (as in Freedom) Software Helps Tackle the Software Liability Issue, It Lets Users Exercise Greater Control Over Programs
- Microsofters have been trying to ban or exclude Free software
- In the US, Patent Laws Are Up for Sale
- This problem is a lot bigger than just patents
- ESET Finds Rootkits, Does Not Explain How They Get Installed, Media Says It Means "Previously Unknown Linux Backdoors" (Useful Distraction From CALEA and CALEA2)
- FUD watch
- Techdirt Loses Its Objectivity in Pursuit of Money
- The more concerning aspects are coverage of GAFAM and Microsoft in particular
- Links 23/11/2024: Press Sold to Vultures, New LLM Blunders
- Links for the day
- Links 23/11/2024: "Relationship with Oneself" and Yretek.com is Back
- Links for the day
- Links 23/11/2024: "Real World" Cracked and UK Online Safety Act is Law
- Links for the day
- Links 23/11/2024: Celebrating Proprietary Bluesky (False Choice, Same Issues) and Software Patents Squashed
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Friday, November 22, 2024
- IRC logs for Friday, November 22, 2024
- Gemini Links 23/11/2024: 150 Day Streak in Duolingo and ICBMs
- Links for the day
- Links 22/11/2024: Dynamic Pricing Practice and Monopoly Abuses
- Links for the day
- Topics We Lacked Time to Cover
- Due to a Microsoft event (an annual malware fest for lobbying and marketing purposes) there was also a lot of Microsoft propaganda
- Microsofters Try to Defund the Free Software Foundation (by Attacking Its Founder This Week) and They Tell People to Instead Give Money to Microsoft Front Groups
- Microsoft people try to outspend their critics and harass them
- [Meme] EPO for the Kids' Future (or Lack of It)
- Patents can last two decades and grow with (or catch up with) the kids
- EPO Education: Workers Resort to Legal Actions (Many Cases) Against the Administration
- At the moment the casualties of EPO corruption include the EPO's own staff
- Gemini Links 22/11/2024: ChromeOS, Search Engines, Regular Expressions
- Links for the day
- This Month is the 11th Month of This Year With Mass Layoffs at Microsoft (So Far It's Happening Every Month This Year, More Announced Hours Ago)
- Now they even admit it
- Links 22/11/2024: Software Patents Squashed, Russia Starts Using ICBMs
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Thursday, November 21, 2024
- IRC logs for Thursday, November 21, 2024