BetaONE will rise again!


Reply
  #1  
Old 11th Sep 02, 04:28 AM
saratogaSiX's Avatar
saratogaSiX saratogaSiX is offline
Member
 
Join Date: Nov 2001
Posts: 35
saratogaSiX
Found this on another forum, This might be of interest to someone...


Biggest Security Hole Ever ....read This

it is very simple to execute this. Someone could easily delete your windows folder just by you visiting a webpage.

If you can't install SP1 do the following

1. Perform a search for a file on your C drive called "uplddrvinfo.htm."

2. Once you've found the file, delete it or rename it. Doing so will not hinder your ability to use Windows XP.




Attention Windows XP Users


A little-known but critical vulnerability exists in Windows XP.

It has recently been repaired in Service Pack 1.

This vulnerability allows the files contained in any specified directory on your system to be deleted if you click on a specially formed URL. This URL could appear anywhere: sent in malicious eMail, in a chat room, in a newsgroup posting, on a malicious web page, or even executed when your computer merely visits a malicious web page. It is likely to be widely exploited soon.

This vulnerability is so dangerous that it would be irresponsible for me to say more. Microsoft has known of this problem for months and has, inexplicably, done nothing before now. Although XP's Service Pack 1 is not small (approx 30 MB for express installation or 140 MB for the network install), and even though a much quicker and easier solution to this problem exists, the only thing I can safely recommend (without revealing too much) is to urge all XP users to somehow obtain and install Service Pack 1 immediately. (If you have a slow Internet connection, perhaps a friend can download the executable Service Pack file and burn it onto a CD for you?)

This problem does not affect any systems other than Windows XP. If you have any friends or co-workers running Windows XP, please urge them to update their systems' too.


the file is in this location.

*:\windows\pchealth\helpctr\system\dfs\
Replace * with the correct drive letter

Info from national tv airing at.

_http://www.techtv.com/screensavers/shownotes/story/0,24330,3398516,00.html

"Please! No live links!"
}---



Last edited by tubebuoy at Today at 5:23 pm
Reply With Quote
  #2  
Old 11th Sep 02, 04:42 AM
Bads's Avatar
Bads Bads is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: Quebec
Posts: 1,710
Bads is an unknown quantity at this point
Hum........

I have the latest SP1 installed and I have this file

Why this file is on my computer if I have apply the SP1 ?

Is this a trick from M$ ?

Thanks for your comments
__________________
Reply With Quote
  #3  
Old 11th Sep 02, 04:49 AM
pcservicetech's Avatar
pcservicetech pcservicetech is offline
Senior Member
 
Join Date: Dec 2002
Location: United States
Posts: 280
pcservicetech is an unknown quantity at this point
Yikes
Reply With Quote
  #4  
Old 11th Sep 02, 02:11 PM
Jupiter2k Jupiter2k is offline
Member
 
Join Date: Oct 2001
Posts: 93
Jupiter2k
Thanks for the info

to be safe BAD1 .. just rename the file regardless?
Reply With Quote
  #5  
Old 11th Sep 02, 02:47 PM
pcservicetech's Avatar
pcservicetech pcservicetech is offline
Senior Member
 
Join Date: Dec 2002
Location: United States
Posts: 280
pcservicetech is an unknown quantity at this point
Correct I just watched the program and yes sp1 does fix it here is the video link to the tech tv show

_http://cgi.techtv.com/mediamodule?action=view&version=20020910095425&vid eo_src=/thescreensavers/2002/ss020909c&width=320&height=240&vidsection=3200042& add_date=1031641200&start=&end=&duration=&bitrates =']http://cgi.techtv.com/mediamodule?action=v...&bitrates='[/url]

Please! No Live links!

}---



Last edited by tubebuoy at Today at 5:25 pm
Reply With Quote
  #6  
Old 11th Sep 02, 04:05 PM
VP's Avatar
VP VP is offline
BetaONE Supporter
 
Join Date: Jul 2001
Posts: 188
VP is an unknown quantity at this point
Holy shit
Reply With Quote
  #7  
Old 11th Sep 02, 04:19 PM
User Needs User Needs is offline
Administrator
 
Join Date: Aug 2001
Posts: 950
User Needs has disabled reputation
Done
Reply With Quote
  #8  
Old 11th Sep 02, 04:20 PM
stumuzz stumuzz is offline
Member
 
Join Date: Oct 2001
Posts: 67
stumuzz
Thanks for the heads up ,
I have this file also .

Its gone now.

Stumuzz
Reply With Quote
  #9  
Old 11th Sep 02, 04:29 PM
Grzyb's Avatar
Grzyb Grzyb is offline
Super Moderator
 
Join Date: Jul 2001
Posts: 397
Grzyb is an unknown quantity at this point
Bl**dy M$.....

More Holes & leaks than ever....

Why do they keep doing this to US!!!!!!

THANKS FOR THE HEADS UP ON THIS ONE......
__________________
HELPING EVERYONE TO HELP THEMSELVES

Grzyb

Super Moderator BetaONE

Grzyb@betaone.net




Reply With Quote
  #10  
Old 11th Sep 02, 05:12 PM
Sony's Avatar
Sony Sony is offline
M.I.A.
 
Join Date: Nov 2001
Location: Down Under
Posts: 319
Sony will become famous soon enoughSony will become famous soon enough
Send a message via ICQ to Sony Send a message via MSN to Sony
Ways to fix this issue:

Delete/rename the "uplddrvinfo.htm" file (located in C:\WINDOWS\PCHEALTH\HELPCTR\System\DFS).

Or, open it , find, and delete the following section of code:

var oFSO = new ActiveXObject ( "Scripting.FileSystemObject" );
try
{
oFSO.DeleteFile( sFile );
}

Or unregister the hcp protocol handler.

Deleting the section of code breaks the exploit (I have verified it myself) and it is highly recommended that anyone here using XP take steps to fix this.



Last edited by sony at Today at 3:13 pm
__________________
[img]http://www.bbstyles.com/sony.php[/img]
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows XP "Reloaded" FAQ Alpine BetaONE News 0 2nd Nov 04 05:10 AM
IE URL Spoofing Bug; SP2 Users Not Affected NewsBot NeoWin News 0 31st Oct 04 12:00 AM
Windows XP Release 2 coming NewsBot NeoWin News 0 24th Oct 04 04:00 AM
Windows XP Release 2 coming NewsBot BetaONE News 0 24th Oct 04 04:00 AM
Speed up system. greasemonkey Hardware Support 6 6th Nov 01 08:32 PM


All times are GMT +1. The time now is 10:24 AM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.