MSN Messenger Security Update 838512

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Porch Monkey (prchMnky_at_webtv.net)
Date: 03/11/04


Date: Wed, 10 Mar 2004 23:25:03 -0800 (PST)

Just a few questions, trying to figure out if this update is really
necessary or not.

http://www.microsoft.com/technet/security/bulletin/ms04-010.mspx

Does the user have to give the "attacker"
permission to start a conversion for the said attacker to exploit this
flaw? In other words wouldn't you know someone is using the Messenger,
the attacker could not use the flaw just because you were simply online
correct?

Will having a good firewall also prevent this attack?

Thanks in advance!!

Monkey



Relevant Pages

  • Re: mounting /bin /sbin read only
    ... They should have only write permission for root. ... the attacker can remount them rw as well. ... Ie, this accomplishes nothing not ...
    (alt.os.linux.suse)
  • MSN Messenger Security Update 838512
    ... Does the user have to give the "attacker" permission to start a ... conversion for the said attacker to exploit this flaw? ... Will having a good firewall also prevent this attack? ... Monkey ...
    (microsoft.public.windowsxp.messenger)
  • MSN Messenger Security Update 838512
    ... Does the user have to give the "attacker" permission to start a ... conversion for the said attacker to exploit this flaw? ... Will having a good firewall also prevent this attack? ... Monkey ...
    (microsoft.public.windowsxp.messenger)
  • MSN Messenger Security Update 838512
    ... Does the user have to give the "attacker" ... permission to start a conversion for the said attacker to exploit this ... Will having a good firewall also prevent this attack? ... Monkey ...
    (microsoft.public.windowsupdate)
  • RE: Is this as bad as it seems?
    ... The network being protected by the router or firewall is still vulnerable to ... > circumvented - the administrator has explicitly allowed HTTP traffic on ... this exploit has the effect of allowing the attacker to send *INBOUND* HTTP ... The HTTP server (located on the internal network or anywhere else that is ...
    (Security-Basics)