The latest flaw with a major Microsoft product shows Redmond is unlikely to have anything that approximates to secure software until 2004 at the earliest. That's the damning assessment of analysts Gartner in response to a serious, but little publicised, vulnerability with FrontPage Server Extensions that emerged last week.

The vulnerability could be used in denial-of-service attack or possibly manipulated to run arbitrary code on vulnerable servers. MS has released a patch to fix the problem, which arises in a buffer overrun flaw with the SmartHTML Interpreter component of FrontPage Server Extensions.

That's nothing particularly out of the ordinary, Gartner sagely notes, but it does provide evidence that "Microsoft has a long way to go before it can deliver on its much-publicised promise of Trustworthy Computing". Gartner Research Director Rich Fogull forecasts that, "due to legacy code and resistance to cultural change, Microsoft will not deliver necessary security improvements before 2004".

The assessment is noteworthy because it was Gartner's assessment that it was time to consider an alternative to IIS in the wake of worms like Nimda and Code Red, that caused Microsoft to formulate its Trustworthy Computing push in the first place. In fairness security is an issue for the whole industry, and Microsoft is always prime target for miscreants. That's the territory that goes with being the world's biggest software company.

News source: The Reg
View: The full story




Once a PC is infected, VirusScan may not be able to run as the virus can terminate the process before any scanning/removal is accomplished. The following steps will allow for proper VirusScan scanning/removal, by using the command-line scanner.
  1. Ensure that you are using the minimum DAT specified or higher.
  2. Close all running applications
  3. Disconnect the system from the network.
  4. Go to a command prompt, then change to the VirusScan engine directory:
    • Win9x/ME - Click START | RUN, type command and hit ENTER.
      Type cd progra~1common~1networ~1viruss~140~1.xx and hit ENTER.
    • WinNT/2K/XP - Click START | RUN, type cmd and hit ENTER.
      Type cd progra~1common~1networ~1viruss~14.0.xx and hit ENTER
  5. Rename SCAN.EXE to CLEAN.EXE to prevent the virus from terminating the process and deleting files. Type, ren scan.exe clean.exe and hit ENTER.
  6. First, scan the system directory.
    • Win9x/ME - Type clean.exe %windir%systemwin*.exe and hit ENTER.
    • WinNT/2K/XP - Type clean.exe %windir%system32win*.exe and hit ENTER.
  7. Once the scan has completed, Type clean.exe /adl /clean and hit ENTER.
  8. Rename scan.exe. Type, ren clean.exe scan.exe and hit ENTER.
  9. After scanning and removal is complete, reboot the system
Apply Internet Explorer patch if necessary.Klez can delete anti-virus software files. It may be necessary to reinstall VirusScan after cleaning a system.



There is 1 additional comment
Advertisement


Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.


Scroll to the Top
....
My Preferences
....
Communicating with server
Loading
Please Wait...
....
Loading
 X 
....