All Things Microsoft > Microsoft Software

Another MS security problem arises

(1/2) > >>

preacher:
******************
Microsoft Security Bulletin MS02-060: Flaw in Windows XP Help and Support Center Could Enable File Deletion (Q328940)

Title: Flaw in Windows XP Help and Support Center Could Enable
File Deletion (Q328940)
Date: 16 October 2002
Software: Microsoft Windows XP
Impact: Delete files on the user's system
Max Risk: Moderate
Bulletin: MS02-060
 
A security vulnerability is present in the Windows XP version of Help
and Support Center, and results because a file intended only for use
by the system is instead available for use by any web page. The
purpose of the file is to enable anonymous upload of hardware
information, with the user's permission, so that Microsoft can
evaluate which devices users are not currently finding device drivers
for. This information is then used to work with hardware vendors and
device teams to improve the quality and quantity of drivers available
in Windows. By design, after attempting to upload an XML file
containing the hardware information, the system deletes it.
******************

So simply put MS "SPYWARE" has put its users in danger. Why does MS need to upload your hardware info, or any of your info anywhere from your pc without your permission? What else are they uploading? Your mailing address, so they can better serve you by selling it to computer manufacturers so they can flood you with junk mail. Better yet, they should just take your credit card number off of your pc, then upload new versions of MS products right onto your pc, and then you can be pleasantly surprised when you get the bill.

Pantso:
I think they fixed that in SP1 but nonetheless it's a terrible flaw just like any other flaw that arises from that pitifull excuse of an OS   :D

Zombie9920:

quote:Originally posted by ThePreacher:
******************
Microsoft Security Bulletin MS02-060: Flaw in Windows XP Help and Support Center Could Enable File Deletion (Q328940)

Title: Flaw in Windows XP Help and Support Center Could Enable
File Deletion (Q328940)
Date: 16 October 2002
Software: Microsoft Windows XP
Impact: Delete files on the user's system
Max Risk: Moderate
Bulletin: MS02-060
 
A security vulnerability is present in the Windows XP version of Help
and Support Center, and results because a file intended only for use
by the system is instead available for use by any web page. The
purpose of the file is to enable anonymous upload of hardware
information, with the user's permission, so that Microsoft can
evaluate which devices users are not currently finding device drivers
for. This information is then used to work with hardware vendors and
device teams to improve the quality and quantity of drivers available
in Windows. By design, after attempting to upload an XML file
containing the hardware information, the system deletes it.
******************

So simply put MS "SPYWARE" has put its users in danger. Why does MS need to upload your hardware info, or any of your info anywhere from your pc without your permission? What else are they uploading? Your mailing address, so they can better serve you by selling it to computer manufacturers so they can flood you with junk mail. Better yet, they should just take your credit card number off of your pc, then upload new versions of MS products right onto your pc, and then you can be pleasantly surprised when you get the bill.
--- End quote ---



*The
purpose of the file is to enable anonymous upload of hardware
information, with the user's permission, so that Microsoft can
evaluate which devices users are not currently finding device drivers
for.*

Nuff said, it only uploads the info with user permission. So how is that spyware? The only reason MS wants to get a larger database of commonly used unsupported by Windows default drivers hardware is so they can include more drivers in future SPs and future releases of Windows(therefore making tthe users Out Of the Box experience better).

Calum:
bollocks.

gods, you are gullible, zombie. what if you want to disable this "feature"? do you automatically give your "permission" by "accepting" the microsoft windows end user licence agreement?

also the fact remains that it is a fucking security liability that could have been fixed a year ago if windows was open source.

dumbass.

[ October 17, 2002: Message edited by: Calum ]

Doctor V:
For real, once you sign the EULA you give M$ the right to do whatever with your comp they want.  Looking at M$'s record, why would anyone in their right mind believe they are going to use this hidden system code to help people get what they want.  You pro-M# pro-RIAA people are tards.

V

Navigation

[0] Message Index

[#] Next page

Go to full version