Eye on Security: Dangers of Microsoft Windows, Apple hypeTunes
- Dr. Roy Schestowitz
- 2010-08-26 11:30:12 UTC
- Modified: 2010-08-26 11:30:12 UTC
Summary: Proprietary software and its harms - news headlines
●
Windows DLL flaw will be a big headache for end users
●
Microsoft Releases Security Advisory on Windows Application Bugs
"When the application loads one of its required or optional libraries, the vulnerable application may attempt to load the library from the remote network location," Microsoft explained in its advisory. "If the attacker provides a specially crafted library at this location, the attacker may succeed at executing arbitrary code on the user's machine." Remote binary planting bugs "can be exploited over network file systems such as ... WebDAV and SMB."
To prevent these kinds of attacks, Microsoft has issued guidance for developers working with .DLL files. The company also released an "optional mitigation tool that helps customers address the risk of the remote attack vendor through a per-application and global configuration setting."
●
Web scam hits iTunes and Paypal users
Experts told the BBC that victims had most likely fallen for an e-mail scam, rather than being targeted via a flaw in iTunes or Apple servers.
"I just got hacked for $1,000 worth of software, videos and music," tweeted one victim.
Another told the technology blog TechCrunch: "My account was charged over $4,700. I called security at Paypal and was told a large number of iTunes stores accounts were compromised."
Recent Techrights' Posts
- Small Codebase is Typically Safer (More Aftermarket Snakeoil Means More Holes)
- Rust is just more code
- Spending Christmas Pasting Microsoft's Chatbot Garbage - Anti-Linux and Anti-BSD FUD - Into LinuxSecurity.com (Under the Guise of 'Article')
- In 2025 we need to tackle this problem
-
- Happy Birthday to Linus Torvalds (55)
- he's not the "git" which bashers and haters say he is
- 'LaunchLibre' and Introducing People to Software Freedom While They're Still Young
- announcement from "carmenmaris"
- With 5 Days Left (Sans Time Extension, Which is Expected) FSF Has Already Raised 60% of the Money It Sought
- Technically 59.6485%
- Links 27/12/2024: Ongoing Demise of Real Healthcare, Gemlog Cleanup, Fingers Point to Russia After Passenger Plane Crash
- Links for the day
- Links 27/12/2024: Perfect Desk, Banning Cellphones, Many Cables Cut Near Finland
- Links for the day
- Gemini Links 27/12/2024: Slop and Self-hosting
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Thursday, December 26, 2024
- IRC logs for Thursday, December 26, 2024
- Microsoft Openwashing Stunts Initiative (OSI) is A Vulture in "Open" Clothing
- it's quite telling that the OSI isn't protecting the Open Source Definition
- Gemini Links 25/12/2024: Reality Bites and Gopher Thanks
- Links for the day
- Links 26/12/2024: Japan-China Mitigations and Mozambique Prison Escape (1,500 Prisoners)
- Links for the day
- 2025 Will be Fought and Fraught With LLM Slop or Fake 'Articles' (Former Media/News Sites Turning to Marketing Spam)
- The elephant in the room?
- Links 26/12/2024: Ukraine's Energy Supplies Bombed on Christmas Day, Energy Lines Cut/Disrupted in the Baltic Sea Again
- Links for the day
- Gemini Links 26/12/2024: Rot Economy, Self-hosted Tinylogs
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Wednesday, December 25, 2024
- IRC logs for Wednesday, December 25, 2024
- [Meme] Time to Also Investigate Bill Gaetz
- Investigation overdue
- IBM Has Almost Obliterated or Killed the Entire Fedora Community (Not IBM Staff)
- Remaining Fedora insiders are well aware of this, but bringing this up (an "accusation" against IBM) might be a CoC violation
- Links 25/12/2024: Fentanylware (TikTok) Scams and "Zelle Scams Lead to $870M Loss"
- Links for the day
- Brittany Day Can Rest and Let Microsoft/Chatbots Write Fake 'Articles' About "Linux" This Christmas
- Who said people don't work on Christmas? Chatbots or plagiarism-as-a-service work 24/7, every day of the year except during Microsoft downtimes
- Links 25/12/2024: Windows TCO Brought to SSH, Terence Eden 'Retires'
- Links for the day
- Links 25/12/2024: Latest Report Front Microsoft Splinter Group, War Updates
- Links for the day
- Links 25/12/2024: Hong Kong Attacks Activists During Holidays, Xerox to Buy Lexmark
- Links for the day
- Over at Tux Machines...
- GNU/Linux news for the past day
- IRC Proceedings: Tuesday, December 24, 2024
- IRC logs for Tuesday, December 24, 2024
- Gemini Links 25/12/2024: Open Source Social and No Search
- Links for the day