Came across this today, can't believe what I'm reading, but it seems microsoft have put in a backdoor to the XP SP2 Firewall! check out this link
- posted
18 years ago
Came across this today, can't believe what I'm reading, but it seems microsoft have put in a backdoor to the XP SP2 Firewall! check out this link
On Thu, 11 Nov 2004 19:49:55 GMT, John Jones spoketh
Two caveats:
1) The user needs to run the malicious program on his computer, and 2) The user needs to be logged in as administrator.Lars M. Hansen
So, you're spamming the internet with your sales ad?
"We are offering this product for a small donation $2 (£1.20). We do this only to cover our costs and we will provide any subsequent versions to you free of charge."
Interesting. But a $ 2.00 *donation* through PayPal to buy it? Strange.
On Fri, 12 Nov 2004 14:00:42 +0100, Thomas Wolf spoketh
The issue here is that this is a "vulnerability" with all software firewalls. Any firewall and/or anti-virus software can be shut of or even deleted when someone who are logged in as an administrator runs a program that they shouldn't have been running (either intentionally or accidentally by executing an attachment received via e-mail). The difference here, to some extent, is that this particular vulnerability allows for alteration of the firewall configuration rather than simply shutting it down, but the end result is pretty much the same. The firewall which was supposed to protect you no longer are...
Also, people shouldn't normally be logged in as administrators, and people shouldn't normally run random programs. But, there's a big difference between what people should do and what they actually do...
Lars M. Hansen
... and therefore nobody would stop the evil program to just kill the famous 'Firewall Monitor'. I would strongly suggest to install another program that constantly checks if the monitor is still running, alerting the user when it goes down ;-)
Thomas
Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.