Re: Did MS pull an Ilfak? (MS patch bindiff results)



Joe Polk wrote:

Actually, Ilfak never tested his patch on a Win 9x machine. Steve Gibson, however, plans to write a patch for 95, 98, and ME if Microsoft doesn't.

The patch Ilfak wrote can't work on a Windows 9x machine since it relies on technology that did not exist in Windows 9x.


The idea that Gibson is going to "write" a patch for Windows 9x and save the mankind sounds pretty ridiculous. Even if there will be a patch for Windows 9x written by third parties *and* GRC happens to be one of them (or at least claims being one of them, probably the best and/or the only one), I am pretty confident that Gibsons solution is to be considered the least trustworthy one. He never published sophisticated software (and still there is no claim that he really wrote the software he publishes) and he apparently has absolutely no clue about the security implications he is talking about. GRC looks like a huge marketing bubble without *any* fundamental security researcher knowledge behind it.

For more information on the status of the WMF vulnerability in Windows 9x i'd like to refer to an article by Swa Frantzen at SANS ISC:
http://isc.sans.org/diary.php?storyid=1024


For more non-marketing information on GRC please refer to:
http://www.grcsucks.com/

Regards,

Denis Jedig
syneticon networks GbR



Relevant Pages

  • Re: Virus in microsoft Patch
    ... "Windows must restart because the Remote Procedure Call ... your system and install the patch mentioned above. ... You can also configure Automatic Updates to automatically ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Is running a patch that changes something in Windows XP permis
    ... again for a Microsoft MVP: I have been trying to understand what the ... Windows XP versions before SP2 the system was recognised as SP2 RC1. ... > some things to quote here that tell us that the patch probably does not ... > change the value of TcpNumConnections in the registry and that there isn't ...
    (microsoft.public.windowsxp.general)
  • Re: Daylight Savings Time 2007 and Windows 2000 Server...
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... support older versions of their software as well as Microsoft. ... patch for this problem but to also thoroughly test it and develop the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Learning process
    ... a million users on Windows would be ... Most of the patches are fixes for problems in security and a lot of ... pile of games or the SQL blaster which required 2 patchs - patch 1, ... holes *aren't* patched almost immediately. ...
    (alt.comp.lang.learn.c-cpp)
  • Using Windows Update "SteppingMode" to grab patches and see silen t install switches.
    ... > I have received numerous messages about these two Security ... > Bulletins. ... Having the patch only be available on Windows Update is highly annoying ...
    (NT-Bugtraq)