Re: [Full-Disclosure] Give XP SP2 a chance

From: Stef (stefmit_at_gmail.com)
Date: 08/12/04

  • Next message: idlabs-advisories_at_idefense.com: "[Full-Disclosure] iDEFENSE Security Advisory 08.12.04a: Adobe Acrobat Reader (Unix) Shell Metacharacter Code Execution Vulnerability"
    To: full-disclosure@lists.netsys.com
    Date: Thu, 12 Aug 2004 10:33:46 -0500
    
    

    Hmmm ... talking about what you just said: to me M$ just offered
    security practitioners yet another reason to have a live *nix CD
    handy, after having "upgraded" their "favorite(?!?)" OS to SP2, or
    just plainly use an OS with capabilities of supporting the much needed
    security tools:

    ========== insecure.org ==========================

    Subject: Windows XP SP2 incompatible with Nmap

    Date: Wed, 11 Aug 2004 12:31:23 -0700

    From: Fyodor <fyodor@insecure.org>

    To:

    This is just a heads-up that most Nmap functionality will not work on
    the just-released Microsoft Windows SP2. Why? Microsoft apparently
    broke it on purpose! When an Nmap user asked MS why security tools
    such as Nmap broke, MS responded[1]:

    "We have removed support for TCP sends over RAW sockets in SP2.

    We surveyed applications and found the only apps using this on XP were

    people writing attack tools."

    I don't know why they consider Nmap an "attack tool", particularly
    when they recommend it on some of their own pages[2]. Shrug. Removing
    SP2 re-enables the functionality and causes Nmap to work again. Many
    problems unrelated to Nmap have been found with SP2 as well[3], though
    it does some welcome security improvements for people stuck on that
    platform.

    I will work on this if I get time, but am currently busy rewriting the
    core port scanning engine for the next version of Nmap. It is much
    faster, offers much better multiple-host parallelization, and provides
    other long-desired features such as completion time estimates. If
    someone finds a solution to this SP2 problem, please send a patch. It
    may not be too hard, as Nmap supports operating systems such as Win95
    that didn't have raw socket support in the first place.

    Cheers,

    Fyodor

    [1] http://seclists.org/lists/nmap-dev/2004/Apr-Jun/0077.html

    [2] http://www.microsoft.com/serviceproviders/security/tools.asp

    [3] http://www.crn.com/sections/breakingnews/breakingnews.jhtml?articleId=23905071

    =================================
    On Thu, 12 Aug 2004 09:06:49 -0400, Charles Earl <earlcw@starship.ca> wrote:

    > What is the problem with this service pack? Vendor applications suck, all of
    <snip>

    > I'm tired of every new version of applications being more feature ridden and
    > buggier than the last.
    >
    <snip>

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: idlabs-advisories_at_idefense.com: "[Full-Disclosure] iDEFENSE Security Advisory 08.12.04a: Adobe Acrobat Reader (Unix) Shell Metacharacter Code Execution Vulnerability"

    Relevant Pages

    • Re: XP SP2 nmap incompatibility
      ... > the just-released Microsoft Windows SP2. ... When an Nmap user asked MS why security tools ...
      (NT-Bugtraq)
    • Re: is XP SP2 RC2 advisable for the average FCKGW user?
      ... > copies," said Microsoft group product manager Barry Goffe. ... > internet security and avoiding responsibility for the consequences ... As we have said - SP2 will be available for all legitimate users of Windows ...
      (microsoft.public.windowsxp.basics)
    • Re: Secure Win98 SE?
      ... John the Ripper program and run in on a network that runs 98's and it ... XP/2k have three levels of security. ... days in the OEM channel XP sp2 will be released in August. ... Group policy to adjust so that the firewall is on inside our networks ...
      (microsoft.public.windows.server.sbs)
    • Re: No Wireless Connectivity after SP2, Hardwire OK
      ... So I don't think its a security issue. ... it is not only the firewall. ... >>SP2, but with SP2 it will fall on its nose. ... If you enable DEP and a driver falls foul ...
      (microsoft.public.windowsxp.network_web)
    • Re: RFC: Starting a stable kernel series off the 2.6 kernel
      ... >> improved by hiding detailed software versions from ... I wrote my original post with nmap in mind. ... > noticed all kinds of attacks against Linux using old ... IMHO, to have good security, 1) use open source and 2) ...
      (Linux-Kernel)