Re: on-line Messenger Service exploitation in Windows XP

From: Gary Flynn (flynngn@jmu.edu)
Date: 12/12/02


From: "Gary Flynn" <flynngn@jmu.edu>
Date: Thu, 12 Dec 2002 14:07:32 -0500


"Alun Jones" <alun@texis.com> wrote in message
news:Iy4K9.2563$tm.859659406@newssvr12.news.prodigy.com...
> In article <OsJoX7foCHA.1612@TK2MSFTNGP10>, "George Hester"
> <hesterloli@hotmail.com> wrote:
> >It is a security flaw like it or not.
>
> Yes. It indicates that you're not running a firewall, and thus anyone and
> everyone has access to your shares. Disabling Messenger covers up the symptom
> without curing the problem; rather like putting a band-aid over a melanoma.

The problem is a service allowing unauthenticated, unsolicited connections.
Removing the service solves the problem.
Adding a firewall covers it up...like bandaid covering up a port.



Relevant Pages

  • Re: on-line Messenger Service exploitation in Windows XP
    ... >> Removing the service solves the problem. ... >> Adding a firewall covers it up...like bandaid covering up a port. ... > Service closes one of these ports, ...
    (microsoft.public.security)
  • Re: spyware removal problem
    ... firewall installed or, at the very least, do you have the XP firewall turned ... there's no way of knowing if removing it might cause some ... ripple effect on your system and that brings us back to clean install. ... >> installing a first-rate Internet Security program to help protect ...
    (microsoft.public.windowsxp.basics)
  • Re: on-line Messenger Service exploitation in Windows XP
    ... >The problem is a service allowing unauthenticated, unsolicited connections. ... Removing the service is beneficial if there is likely to be an attempt to ... >Adding a firewall covers it up...like bandaid covering up a port. ... far more worrisome than just Messenger (which is irritating, ...
    (microsoft.public.security)
  • RE: [fw-wiz] Securing a Linux Firewall
    ... What I have done in the past is a bit of a compromise between removing all unused binaries and just disabling them, ... This is a bit of "Security by obscurity" but why not move all unused binaries to a separate unmounted partition, while still leaving them on the system. ... If it is not setuid, and not setgid, it _can't_ grant you extra privs ... > programs the firewall needs and only put those on the jumpstart CD". ...
    (Firewall-Wizards)
  • Re: How to prevent my IP address from being bcast
    ... >but verifying that your firewall is doing it's job. ... ISPs are not taking ... >responsibility for removing the people that are violating their AUPs, ...
    (comp.security.firewalls)

Quantcast