1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Microsoft announce some patches - Win2000, Server2003, XP

Discussion in 'Security and Privacy' started by Hugh Jarss, 2004/07/02.

Thread Status:
Not open for further replies.
  1. 2004/07/02
    Hugh Jarss

    Hugh Jarss Inactive Thread Starter

    Joined:
    2002/07/22
    Messages:
    908
    Likes Received:
    6
    Hi all

    from SANS
    from Microsoft:
    "Microsoft recommends that customers immediately install this configuration change to the Windows XP, Windows Server 2003 and Windows 2000 operating systems in order to improve system resiliency to protect against the Download.Ject attack.... "link to this press release

    best wishes, HJ
     
  2. 2004/07/02
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    I wonder if the Windows Update patch is simply an automated way of doing This registry tweak from the link Joe gave. At work now with updates disabled so can't check.
     
    Newt,
    #2

  3. to hide this advert.

  4. 2004/07/02
    Hugh Jarss

    Hugh Jarss Inactive Thread Starter

    Joined:
    2002/07/22
    Messages:
    908
    Likes Received:
    6
    Newt, I think you're probably right

    they make it confusing though, don't they?

    870669 says it "Applies To" several flavours of IE and MDAC...

    ...the press release says XP, server2003, Win2000 but makes no mention of IE or MDAC

    :(

    best wishes, HJ
     
  5. 2004/07/02
    dobhar Lifetime Subscription

    dobhar Inactive

    Joined:
    2002/05/24
    Messages:
    924
    Likes Received:
    3
    Here the excerpt from my Lavasoft AdWatch log after running the WindowsUpdate for ADODB.Stream

    AdWatch:
    Registry modification detected.
    Root:HKEY_LOCAL_MACHINE
    Key:Software\Microsoft\Windows\CurrentVersion\RunOnce
    Value:wextract_cleanup0
    Data:
    New Data:rundll32.exe C:\WINDOWS\System32\advack.dll,DelNodeRunDLL32 "C:\Documents and Settings\Kent\Local Settings\Temp\IXP000.TMP\ "
    Attempt to alter the autostart section (Accepted)
     
  6. 2004/07/02
    dobhar Lifetime Subscription

    dobhar Inactive

    Joined:
    2002/05/24
    Messages:
    924
    Likes Received:
    3
    After rebooting my PC I went into Registry and now have under Registry key ActiveX Compatibility the {00000566-0000-0010-8000-00AA006D2EA4} key with the DWORD value Compatibility Flags mentioned in the manual method.
     
  7. 2004/07/02
    Jeane

    Jeane Inactive

    Joined:
    2004/05/07
    Messages:
    148
    Likes Received:
    0
    critical update

    I have windows 2000 pro and use as a standalone computer. Should I do this update? I'm assuming if it scans my computer and says I need it, then I do. Is this correct? I ask because the subject matter is difficult for me to understand.

    Thank you
     
  8. 2004/07/02
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Especially since they have released the fix as an item you get from Windows Update, I'd say you absolutely should apply it. I intend to do just that when I get home and will do the manual registry hack here at work since domain security here blocks any updates/patches from the Microsoft site.
     
    Newt,
    #7
  9. 2004/07/03
    JoeHobart

    JoeHobart Inactive Alumni

    Joined:
    2004/05/19
    Messages:
    919
    Likes Received:
    1
    ADO streams are pretty complex web objects. The problem is that its a vector for some pretty rampant malware. The WU patch just automates the reg key mentioned in the KB article, they all do the same thing, just different levels of idiotproofing er.. deployment. :D If you are internet connected, this patch is for you. If you never connect to the net, and its corpnet only, your not in very much risk, but thats a decision you need to make for yourself. When it doubt, roll it out!
     
  10. 2004/07/03
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
    As of this AM, the patch (labelled Critical Update) is also available for Win98 and WinME at Windows Update.
    And yes, as dobhar has mentioned, the patch does what the manual method in 870669 does.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.