ANTICHAT.XYZ    VIDEO.ANTICHAT.XYZ    НОВЫЕ СООБЩЕНИЯ    ФОРУМ  
Баннер 1   Баннер 2
Antichat снова доступен.
Форум Antichat (Античат) возвращается и снова открыт для пользователей. Здесь обсуждаются безопасность, программирование, технологии и многое другое. Сообщество снова собирается вместе.
Новый адрес: forum.antichat.xyz
Вернуться   Форум АНТИЧАТ > Оффтоп > Forum for discussion of ANTICHAT
   
Ответ
 
Опции темы Поиск в этой теме Опции просмотра

Microsoft criticized for silent patches
  #1  
Старый 18.04.2006, 01:43
Аватар для NeMiNeM
NeMiNeM
Постоянный
Регистрация: 22.08.2005
Сообщений: 540
Провел на форуме:
4372175

Репутация: 1221


По умолчанию Microsoft criticized for silent patches

Some security researchers took issue last week with little-documented changes made by Microsoft to Windows in the last batch of security updates, but the software giant responded in a blog posting on Saturday that sometimes less information means better security.

The criticism focused on two issues in Microsoft's security bulletin documenting the changes to Windows systems by a patch released last Tuesday. The advisory stated that the vulnerability being fixed was privately reported but that a "variation" of the flaw had been publicly disclosed in May 2004. Microsoft should have stated that the original vulnerability--more than 700 days old--had been fixed as well as a more recent, privately disclosed flaw, vulnerability researcher Matthew Murphy stated in a blog post.

"The information as published is extremely misleading and Microsoft’s choice not to document a publicly-reported vulnerability is not one that will be for the benefit of its customers’ security," wrote Murphy. The security researcher, a student in the information systems program at Missouri State University, is currently working with Metasploit founder HD Moore to find flaws in Internet Explorer and other browsers using data fuzzing techniques.

Murphy and others also took issue with the lack of details about Microsoft's other security enhancements, including defense-in-depth changes and changes to how ActiveX controls are run.

However, Microsoft defended the software changes.

"As is our normal practice for security bulletins, we document the existence of any additional defense in depth product behavioral changes, as well as the area of functionality where the change occurred so that customers can assess the impact to their environments," Stephen Toulouse, security program manager for Microsoft, wrote Saturday on the Microsoft Security Response Center (MSRC) blog. "However, providing more detail on internal product changes could serve to aid attackers."

Robert Lemos
http://www.securityfocus.com
 
Ответить с цитированием
Ответ



Похожие темы
Тема Автор Раздел Ответов Последнее сообщение
Microsoft ограничит функциональность пиратских копий Windows Vista dinar_007 Мировые новости 9 06.10.2006 18:17
Обновление от Microsoft калечит компьютеры dinar_007 Мировые новости 6 17.04.2006 17:54
Windows Vista - "Новые возможности" от Microsoft Hitman_2 Мировые новости 0 28.03.2006 01:31
ЕС поставит Microsoft "на счетчик" dinar_007 Мировые новости 0 22.12.2005 21:30



Здесь присутствуют: 1 (пользователей: 0 , гостей: 1)
 


Быстрый переход




ANTICHAT.XYZ