Re: [Full-Disclosure] Interesting side effect of the new IE patch

From: Daniele Muscetta (daniele_at_muscetta.com)
Date: 02/05/04

  • Next message: FreeBSD Security Advisories: "[Full-Disclosure] FreeBSD Security Advisory FreeBSD-SA-04:02.shmat"
    To: <s.esser@e-matters.de>
    Date: Thu, 5 Feb 2004 20:54:19 +0100 (CET)
    
    

    Stefan Esser said:
    > Hello,
    >
    >> FIAT (the famous Italian CAR producer) invested quite an amount of
    >> money and effort in lauching the promotional site:
    >> http://www.buy@fiat.com
    >>
    >> ....I think they must not be very happy now..... :(
    >
    > Of course they are not happy now. Like a lot of other people who relied
    > on this standard. It is really sad, that Microsoft removes features
    > because they are to lazy to think up other solutions.

    They are just RUSHING to close as may bugs as possible.... and as always
    happens when fixing things afterwards intead of designing them in from the
    beginning, things either break, or settings that get closed have to be
    re-opened again.
    Another issue I personally encountered some days ago was an application
    which all of a sudden stopped working after having applied SP4 (on a
    windows 2000 server), because of the NEW user rights they introduced:
    http://support.microsoft.com/default.aspx?kbid=821546

    which might have been nice to have from the beginning, so that people
    would have not written applications that require that right in the first
    place.Now, while waiting for a new version of that application to be released
    (if and when this is going to happen)... all one has to do is to
    EXPLICITLY GRANT that right to all of the users on that machine.....
    practically reverting the machine to the inseure setting it had before
    SP4.
    Same applies for the 'security enhanced configuration' of IExplore in
    Windows 2003.... which is SO tight that not even their own windowsupdate
    works..... which results in people uninstalling it....

    > (Oh yeah and this is not a Microsoft only problem, or why do f.e.
    > openssh/openssl allow RSA keys without passphrases?)

    Indeed.
    But it is the continuos struggle between security and usability....

    > Ohh yes and I choose the word standard, because standard is not what
    > some RFC/paper dictates, but what the majority of people (or browsers)
    > use (support). NTSC would not exist otherwise, because NTSC was NOT the
    > official standard for color television in the beginning.

    I don't know, we have PAL ;)

    Regards,

    Daniele Muscetta

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: FreeBSD Security Advisories: "[Full-Disclosure] FreeBSD Security Advisory FreeBSD-SA-04:02.shmat"

    Relevant Pages

    • Re: Creating a Custom Users Group in Windows XP Professional
      ... In GPEDIT, you should be able to go to Computer Configuration, Windows Settings, Security Settings, Local Policies, User rights assignments and modify the Load and unload device driver setting to allow Power Users, or your custom group to this policy. ... The biggest issue with a custom group is ensuring that you give them access to everything they need access to. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Interactivity Logon not permitted
      ... Somehow you botched up the logon locally or deny logon locally user rights ... Management from your XP computer to view the security logs on the Windows ... > Renamed Administrator Account ...
      (microsoft.public.win2000.security)
    • Re: about MCE 2005 updates
      ... Most of North America is NTSC, as well, I believe. ... > Windows XP Media Center Edition 2005 Create DVD Update ... MS-MVP Windows Media Center\Windows Powered Smart Display\Security ...
      (microsoft.public.windows.mediacenter)
    • Re: Group Policy in xp
      ... If the MUI articles here are not relevant, I'd check the User Rights ... Assignment parts of your policies and remove any 's that you see ... Windows Platform Support Team ... >>their systems this is working in windows 2000 clients but in windows xp ...
      (microsoft.public.win2000.group_policy)
    • Re: Networking issues - "Logon failure"
      ... I have run the Network Setup Wizard and I ... The problem is with user rights assignments on the desktop computer. ... The Guest account settings in Control Panel | User Accounts have ... If the desktop computer runs Windows XP Professional: ...
      (microsoft.public.windowsxp.network_web)

  • Quantcast