BleepingComputer.com: Survey: Wmf Vulnerablility

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Survey: Wmf Vulnerablility How many of us have installed the unofficial patch from hexblog?

#1 User is offline   BanditFlyer 

  • Forum Regular
  • PipPipPip
  • Find Topics
  • Group: Members
  • Posts: 283
  • Joined: 25-October 05

Posted 04 January 2006 - 02:04 PM

I installed the patch and then had some second thoughts. Is the patch going to create problems?

So I thought I'd post a poll and find out how many of the people who know what they are doing have also installed the patch.

Here is a link with some discussion about the prs and cons of using unofficial patches:
http://www.sans.org/newsletters/newsbites/...sue=1&rss=Y#200

Edit: looks like I messed up with the poll. Oh well. In that case, please just hit the reply button

This post has been edited by BanditFlyer: 04 January 2006 - 02:07 PM


#2 User is offline   boopme 

  • To Insanity and Beyond
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 48,775
  • Joined: 10-September 04
  • Gender:Male
  • Location:NJ USA

Posted 04 January 2006 - 02:18 PM

I installed used grinlers app...I feel good .says I'm clean...I wouldn't go out to get something that grinler posted for us to use..
How do I get help? Who is helping me?
Staying Updated Calendar of Updates.
For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....
Become a BleepingComputer fan: Facebook

#3 User is offline   BanditFlyer 

  • Forum Regular
  • PipPipPip
  • Find Topics
  • Group: Members
  • Posts: 283
  • Joined: 25-October 05

Posted 04 January 2006 - 02:53 PM

I probably should've done that :thumbsup:

So, we've got one so far(because I'm guessing Grinlers app just repackages the unofficial patch???

Or did grinlers utility just unregister the thingy(that's a technical term!) that microsoft said to unregister?? Shame on me for not having the time to fully read up on this - it's been a busy week ).

Anyone else?

#4 User is offline   Datababe 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 10
  • Joined: 21-November 05

Posted 05 January 2006 - 01:04 PM

Ilfak's patch was pushed out at my work yesterday, surprisingly as they are usually cautious to the point of inertia about new technologies (it was only a few years ago I was still supporting some OS2 machines *cough*), and it promptly broke $Major_Marketing_App and had to be removed from the pcs which use that (luckily only a few). The push has been left running, though, so I guess the PHB's have decided the risk of breaking a few apps is the lesser of two evils (and considering the ad and junkware littered websites many of our users insist on frequenting, I have to agree).

I would have no qualms about installing Ilfak's patch on my home Windows XP machine, but I also have no motivation to do so. I can keep "Lazarus" offline until MS comes out with their patch, while "Velma" (my Cube), "Precious" (my Powerbook), and I watch the show from the safety of OSX. :thumbsup:

#5 User is offline   Scarlett 

  • Bleeping Diva
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 7,479
  • Joined: 25-April 04
  • Gender:Female
  • Location:As always I'm beside myself ;)

Posted 05 January 2006 - 02:34 PM

I have not installed Ilfak's patch, but only because I run ME. If I was able to I would.

He is an admired member in the tech community. As a matter of fact his site was down this past Wednesday, citing bandwidth issues.
There lies your answer BanditFlyer. :thumbsup:
Also, the SANS Institute's Internet Storm Center recommends applying the patch, so....
An informative read: http://www.informationweek.com/software/sh...cleID=175801150
Excerpt:

Quote

While Microsoft has chosen to patch the WMF vulnerability during its normal Patch Tuesday download, this comes well after it should have. "They have historically released patches on special occasions, and this is clearly one of those occasions,"

I agree.
Pretty bad when ever a third party has to roll up his sleeves to do what M$ should of been doing all along.

Shame, shame. Shame's thier name.
Posted Image

#6 User is offline   Dollyeyes 

  • Forum Regular
  • PipPipPip
  • Find Topics
  • Group: Members
  • Posts: 226
  • Joined: 06-September 05
  • Gender:Female
  • Location:Nottingham, England town!

Posted 05 January 2006 - 02:58 PM

:inlove: Hi Scarlett? I have downloaded Ilfaks patch as per Grinler instructions...do Microsoft have theirs out yet then...and will they contact me ie. when i do an update on IE? I have kept Grinlers instructions regarding uninstalling and reinstalling the other...er..thingy he said to do.. :thumbsup: :flowers: sorry...me in blonde mode tonight!! Oh..and Happy New Year too...x

:trumpet: oops...just looked around and seen that Microsoft have indeedy released theirs today and have uninstalled Ilfaks patch and did the DLL thingy..(love my knowledge of computer speak I do!!)so apologies...should read more!!

This post has been edited by Dollyeyes: 05 January 2006 - 03:39 PM

Posted Image
Of all the things Ive lost...I miss my mind the most!

#7 User is offline   Datababe 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 10
  • Joined: 21-November 05

Posted 05 January 2006 - 07:45 PM

I asked on another forum if anyone was considering installing Ilfak's patch rather than the Microsoft one, permanently. I'm frankly on the fence as to which I feel more comfortable "trusting"...but I'll admit at this point I'm leaning in the former direction. A well respected programmer really pouring his all into his code and inviting everyone to check it out sways me more than a monopoly corporation scrambling to save face. :thumbsup:

#8 User is offline   jgweed 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 27,609
  • Joined: 11-April 04
  • Gender:Male
  • Location:Chicago, Il.

Posted 05 January 2006 - 08:12 PM

Now that MS has been goaded into doing what it should have done in the first place, namely issueing a patch to a major security vulnerability in a timely manner, this question is rather moot.

All Windows users owe Ilfak an immense thanks both for his concern over the vulnerabilty, and by publishing it, his forcing MS to take some action. I also note that several commentators have also raised the question about MS's sluggishness after Ilfak published his solution.

Regards,
John
Whereof one cannot speak, thereof one should be silent.

#9 User is offline   Scarlett 

  • Bleeping Diva
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 7,479
  • Joined: 25-April 04
  • Gender:Female
  • Location:As always I'm beside myself ;)

Posted 05 January 2006 - 08:21 PM

Quote

Ilfak Guilfanov is far from a household name.

But that may soon change as the Russian software developer's unauthorized Microsoft security patch is increasingly installed onto computers worldwide......



Why do you think your unofficial patch has been so popular with users?
I cannot tell for sure, but most likely because of my reputation as the author of IDA Pro disassembler...Second, the fix comes with the source code. This makes much easier to verify it--this is what exactly happened at the SANS Institute. The experts confirmed that the fix does exactly what it is supposed to do and approved it.


Full interview here:
http://news.com.com/Beating+Microsoft+to+t....html?tag=carsl

This post has been edited by Scarlett: 05 January 2006 - 08:34 PM

Posted Image

#10 User is offline   boopme 

  • To Insanity and Beyond
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 48,775
  • Joined: 10-September 04
  • Gender:Male
  • Location:NJ USA

Posted 06 January 2006 - 01:42 AM

Microshaft probably pinched his to get their's out faster... IMHO :thumbsup:

Thank you Ilfak Guilfanov for your selfless efforts I owe you a dinner :flowers:
How do I get help? Who is helping me?
Staying Updated Calendar of Updates.
For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....
Become a BleepingComputer fan: Facebook

#11 User is offline   tos226 

  • BleepIN--BleepOUT
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 1,423
  • Joined: 21-October 04
  • Gender:Female
  • Location:LocalHost

Posted 15 January 2006 - 10:51 PM

View Postjgweed, on Jan 5 2006, 08:12 PM, said:

All Windows users owe Ilfak an immense thanks both for his concern over the vulnerabilty, and by publishing it, his forcing MS to take some action. I also note that several commentators have also raised the question about MS's sluggishness after Ilfak published his solution.

Regards,
John

It's now history, isn't it? But for the record and the poll, I installed Ilfak's patch the day it came out. It installed well, It had CLEAR instruction about installing, uninstalling, and then after MS decided to slooooooooooooooowly follow suit of one HERO TO US all, it uninstalled cleanly. (I did not do the DLL tweaking, Ilfak explained it wasn't too good)

THANK YOU, ILFAK!! Way to go. Keep at it.

Hey, moderators, perhaps we should send this thread to Ilfak
:thumbsup:

This post has been edited by tos226: 15 January 2006 - 10:53 PM


Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users