Re: [Full-disclosure] 70 million computers are using Windows 98rightnow



isnt browsing the web to sites with flash, java, asp, php, etc,
allowing an untrusted user to run code on your machine?

Yes. Sometimes. No. No. Etc.

ASP, PHP, and some Java applications are run on the server. They send
your client HTML, javascript, css, etc. Now Java APPLETS are run on
your computer -- if you allow them.

I think so given the rate at which exploits are released for all the
above protocols, and especially considering the fact they will all go
unpatched from now on.

Forgive me if this is a stupid question, but doesnt win9x have file
shares? Does that require authentication?

Yes. It can.

-JP<who has never used win9x>

--
Chris Umphress <http://daga.dyndns.org/>

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: win2000 - 1000s of ports opened
    ... java applications for the past 4 years. ... days we experienced program crashes etc. ... When the server is cold- ... Can I close these ports manually or via ZoneAlarm? ...
    (alt.computer.security)
  • win2000 - 1000s of ports opened
    ... I have a w2k server running ... java applications for the past 4 years. ... Can I close these ports manually or via ZoneAlarm? ...
    (alt.computer.security)
  • Re: [OT]Mac mini server, OS choice
    ... I could get a new intel mini that would support more things (lots of ... I could put an ordinary OSX 10.5 on it and set that up as a server. ... Things like jbidwatcher and Java applications aren't really the kind of ... I don't know whether Mac OS X server does, but plain old Mac OS X does, ...
    (uk.comp.sys.mac)