[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Fw: Today's WinInfo: November 10



PureBytes Links

Trading Reference Links

Apart from the pathetic anti-Microsoft tone used by Paul (WinInfo), eg
appreciating (his voting for)  this "new era" of covered State-law communism
-the ruling spoken out by an ill informed judge + that coincidently happened
 on the 10th aniversery day of the collapse of the "Berlin Wall"- , eg where
 Europe futher liberated and the US seems to reverses history to
 clear examples of "killing the free enterprise system" (eg main target of
 communism), and that can   -in future-   effect any business that is succesfull
 in practising what any business-student is being thought at in Business Schools,
 eg their economy classes and lessons that are an example and that would
 have protected many   -now-   bankrupt companies in going bust, eg clean
 economic rules and lessons for those co's in how to stay on top of things, find
 below the link to the continous availability of protection by downloading and
 installing (on a regular scheme) the Security Bulletin's security patches

The Microsoft Security Advisor web site
http://www.microsoft.com/security/default.asp
and click the Bulletin-link.

Regards,
Ton Maas
ms-irb@xxxxxxxxxxxxxxxx
Dismiss the ".nospam" bit (including the dot) when replying and
note the new address change. Also for my Homepage
http://home.planet.nl/~anthmaas

==========================================

WinInfo: Windows news and information -- Copyright (c) 1995-9 Paul Thurrott
Visit WinInfo on the Web at WUGNET: http://www.wugnet.com/wininfo

Today's WinInfo: (partly printed)
  
Judge was right: BubbleBoy worm proves IE/Windows insecure 

A malicious new email worm can infect the systems of Microsoft Outlook and
Outlook Express users that have Internet Explorer 5.0 installed, giving a
dramatic "told you so" moment to Judge Jackson's pronouncement in his
findings of fact that integrating a Web browser into Windows presented a
security risk. The startling new bug, which surfaced less than a week after
Jackson's ruling against Microsoft, is the first of its kind: An email worm
that can cause a virus to infect a system without any participation from the
user. Dubbed "BubbleBoy" after an episode of the TV series "Seinfeld," this
worm can attack your system by simply opening the email that it is attached
to: You don't need to manually open the attachment.

The implications of such a bug are, of course, frightening: In the past,
email attachment bugs required the user to open an infected attachment for a
virus to infect the system. But BubbleBoy takes advantage of the lax
security features in Internet Explorer 5.0, which provides Outlook and
Outlook Express with HTML email capabilities, to infect a system without any
user interaction.

Fortunately, the original version of BubbleBoy doesn't contain any
destructive code, though it does propagate itself by sending an infected
email to every contact in the user's address book. Email from the worm is
generally accompanied by a subject line reading, "BubbleBoy is back!" while
the body of the mail includes the text "The BubbleBoy incident, pictures and
sounds," along with an invalid Web address.

At risk are users running Windows 98 or Windows 2000 (but not NT 4.0, for
some reason) with Internet Explorer 5.0 and Windows Scripting Host (WSH)
installed (this is a standard component of Windows 98 and 2000). In Outlook,
the offending email must be opened in its own window for the virus to
escape. Outlook Express users aren't so lucky: You can unleash the virus
simply by displaying the email in the preview window.

As for protecting your system, the same rules apply as always: Make sure
you've downloaded the latest security patches for Internet Explorer 5.0 from
Windows Update. A security fix that was released earlier this year (one of
about a dozen so far) will protect your system from BubbleBoy.

______________________________________________________

Visit WinInfo on the Web at WUGNET: http://www.wugnet.com/wininfo

To unsubscribe from the WinInfo list, simply send an E-mail message to
listserv@xxxxxxxxxxxxxxxxxxxx with the phrase "unsubscribe wininfo" (no
quotes) in the body. If you are having problems unsubscribing or any other
problems with the list, please write the List Administrator at
listadmin@xxxxxxxxxxx