Welcome Guest ( Log In | Register)



 
Reply to this topicStart new topic
> Internet Vulnerabilities
Joe2Chance
post Mar 28 2006, 09:33 PM
Post #1


Member [Level 2]
*****

Group: Members
Posts: 75
Joined: 28-March 06
Member No.: 20,895



Ok, I was doing some research on the net on various flaws and vulnerabilities that hackers use to warm our computers, and i've made a list of some interesting points (some of them i've never heard) and decided to post here:

As i said, i've made a big research and to each vulnerabilitie iīve included links to additional information useful for correcting or preventing the security flaws.

Top Vulnerabilities in Windows Systems

1. Windows Services
  1. MSDTC and COM+ Service
  2. Print Spooler Service
  3. Plug and Play Service , see this too
  4. Server Message Block Service, see this too
  5. Exchange SMTP Service
  6. Message Queuing Service
  7. License Logging Service
  8. WINS Service
  9. NNTP Service
  10. NetDDE Service
  11. Task Scheduler

2. Internet Explorer
  1. Cumulative Security Update for Internet Explorer
  2. Cumulative Security Update for Internet Explorer
  3. JView Profile Remote Code Execution
  4. Cumulative Security Update for Internet Explorer
  5. Cumulative Security Update for Internet Explorer
  6. Cumulative Security Update for Internet Explorer
  7. Windows Shell Remote Code Execution
  8. Cumulative Security Update for Internet Explorer
  9. Cumulative Security Update for Internet Explorer
  10. Cumulative Security Update for Internet Explorer

3. Windows Libraries
  1. Windows Graphics Rendering Engine Remote Code Execution
  2. Microsoft DirectShow Remote Code Execution
  3. Microsoft Color Management Module Remote Code Execution
  4. HTML Help Remote Code Execution, see this, and this too
  5. Web View Remote Code Execution
  6. Windows Shell Remote Command Execution , this, this, and this too
  7. Windows Hyperlink Object Library Remote Code Execution
  8. PNG Image Processing Remote Code Execution
  9. Cursor and Icon Processing Remote Code Execution
  10. Windows Compressed Folder Remote Code Execution
  11. JPEG Processing Remote Code Execution

4. Microsoft Office and Outlook Express
  1. Cumulative Security Update for Outlook Express
  2. Microsoft OLE and COM Remote Code Execution
  3. Microsoft Office XP Remote Code Execution

5. Anti-virus Software
  1. AhnLab , see this too
  2. Avast! , see this too
  3. AVIRA
  4. BitDefender
  5. ClamAV
  6. Computer Associates
  7. HAURI
  8. F-Secure
  9. Kaspersky , see this, and this too
  10. Mcafee, see this too
  11. Sophos
  12. Symantec
  13. Trend Micro
  14. ZoneAlarm


6. PHP-based Applications
  1. See this
  2. Also this
  3. And this

7. File Sharing Applications
  1. Skype
  2. NapShare 1.2
  3. eMule 0.42d
  4. PeerCast 0.1211


8. DNS Software
  1. See this
  2. And this

9. Media Players
  1. RealPlayer and Helix Player, see this, and this
  2. iTunes, and this
  3. Winamp, and this
  4. Quicktime, this, and this
  5. Windows Media Player, and this


And for now is all, hope this become useful to anyone!
There are so many vulnerabilities that is impossible to name them all, when i was doing my research at a point i just had to stop because there are so many that i almost got crazy!!! blink.gif

I think that it would be interesting to place posts here of "things" that already have happened you or of the possible flaws that you guys have knowledge of some programs that all we use daily, so that us can prevent future attacks.

Stay well.
Notice from jlhaslip:
List such as these should be contained inside some bbcode tags.
Preferably the [ list ] tags, but it was too much work for a list this size, so next time, please research the use of bbcode lists. Thanks.


jlhaslip, i've changed the post to the [list] tag form, please confirm itīs ok now, if don't i'll post it the way you left it!


This post has been edited by Joe2Chance: Mar 28 2006, 10:41 PM
Go to the top of the page
 
+Quote Post
jlhaslip
post Mar 28 2006, 09:45 PM
Post #2


A computer once beat me at chess, but it was no match for me at kick boxing.
Group Icon

Group: [MODERATOR]
Posts: 3,882
Joined: 24-July 05
From: In Trouble Again... still?
Member No.: 9,787
Spam Patrol



I guess you don't run a Mac?
Go to the top of the page
 
+Quote Post
Joe2Chance
post Mar 28 2006, 09:55 PM
Post #3


Member [Level 2]
*****

Group: Members
Posts: 75
Joined: 28-March 06
Member No.: 20,895



QUOTE(jlhaslip @ Mar 28 2006, 10:45 PM) *

I guess you don't run a Mac?


No i don't!!! Why do you ask? huh.gif

QUOTE
List such as these should be contained inside some bbcode tags.
Preferably the [ list ] tags, but it was too much work for a list this size, so next time, please research the use of bbcode lists. Thanks.


Sorry for my ignorance, but what are "bbcode lists"? blink.gif

This post has been edited by Joe2Chance: Mar 28 2006, 09:50 PM
Go to the top of the page
 
+Quote Post
jlhaslip
post Mar 28 2006, 09:58 PM
Post #4


A computer once beat me at chess, but it was no match for me at kick boxing.
Group Icon

Group: [MODERATOR]
Posts: 3,882
Joined: 24-July 05
From: In Trouble Again... still?
Member No.: 9,787
Spam Patrol



Go to the top of every page where the Shoutbox is displayed and click on the link titled 'bbcodes' then scroll down a couple of pages.
Go to the top of the page
 
+Quote Post
Canada Eh895
post Mar 28 2006, 09:59 PM
Post #5


Newbie [Level 2]
**

Group: Members
Posts: 28
Joined: 27-March 06
Member No.: 20,836



Wow, thats quite a list you have there.

You may have included it already, but have you got the one in which hackers could hack a computer through Images?

Macs are a way better operating system. I don't want to start a whole debate, but thats how it is. There is almost no vulnerabilities that I can think of off of the top of my head.

Anyway, great list, thanks for it
Canada Eh895
Notice from jlhaslip:

Signing off your posts with a name or other salutation is frowned upon and may have you receiving a warning (or a ban if you continue to use them once warned verbally) and this is your verbal warning. Signatures are to be placed in your Signature Block through the modifying the Profile for each user.
Please look in the Tutorial section if you are not certain how to modify the Signature Block of your Profile. Thanks.
Go to the top of the page
 
+Quote Post
savge17
post Mar 28 2006, 10:48 PM
Post #6


Super Member
*********

Group: [HOSTED]
Posts: 381
Joined: 1-December 05
From: Xempt..T17 GFX Crew
Member No.: 15,202
T17 GFX Crew



security-wise I dotn think ive ever had a problem with these such programs, only viruses are my only source for problems with my computer.
Go to the top of the page
 
+Quote Post
htdefiant
post Mar 29 2006, 12:00 PM
Post #7


Advanced Member
*******

Group: Members
Posts: 126
Joined: 21-February 06
Member No.: 18,973



Neither have I. Although, I do not use the biggest culprit, IE. I hardly run it.
Go to the top of the page
 
+Quote Post
gameratheart
post Mar 29 2006, 07:05 PM
Post #8


Super Member
*********

Group: [HOSTED]
Posts: 492
Joined: 14-November 05
From: Britannia!
Member No.: 14,287



Of course, these only affect people who use Windows (which I do), and base their browsing on Internet Explorer and NetScape browsers (which I don't).

Luckily (with exception of Media Players), all of the things from list 4 to list 7 are optional for your computer. So you only need to worry about these if you actually have them - and I for one do not have any of them.

That is not to say that not having AntiVirus is reccomended however - in fact, you should get a Virus scanner as soon as you can! I refer to virus scanners being "optional" in the way that you have free will choosing which one to use.

For lists 1 - 3, patches and fixes are available. However older versions of windows may not have these because they are no longer updated. My advice is: be careful when on the net, and don't do anything stupid.

This post has been edited by NDPA: Mar 29 2006, 07:09 PM