EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

05.29.09

Reader’s Article: Does Microsoft Create Security FUD Against Rivals?

Posted in Apple, FUD, GNU/Linux, Microsoft, Security, Windows at 3:06 am by Roy Schestowitz

“Working behind the scenes to orchestrate “independent” praise of our technology, and damnation of the enemy’s, is a key evangelism function during the Slog. “Independent” analyst’s report should be issued, praising your technology and damning the competitors (or ignoring them). “Independent” consultants should write columns and articles, give conference presentations and moderate stacked panels, all on our behalf (and setting them up as experts in the new technology, available for just $200/hour). “Independent” academic sources should be cultivated and quoted (and research money granted). “Independent” courseware providers should start profiting from their early involvement in our technology. Every possible source of leverage should be sought and turned to our advantage.”

Microsoft, internal document [PDF]

Reader’s summary: Microsoft first to fix pool overruns vulnerability, or is it?

Microsoft invents a ‘fix’ for some bogus security bug and ‘Independent Security Evaluator’ heaps praise on Microsoft and talks up the ‘vulnerability’ in Mac OS X and GNU/Linux.

The article is a little short on any actual details of the exploit. I thought ‘Safe unlinking’ of ‘doubly linked lists’ was de regur on any information processing system.

“The article is a little short on any actual details of the exploit.”I hadn’t heard the term before, and I do try and keep up. Are there any actual examples of ‘pool overruns’, in the public domain, that can be successfully run on Mac OS X and GNU/Linux?

To quote: “Independent Security Evaluators has successfully exploited weaknesses in Windows, OS X and Linux. “I think they’re trying to stay ahead of the curve” [...] This simple check blocks the most common exploit technique for pool overruns

Where and how did Microsoft come out with a fix so quickly and why not design a MMU that isn’t vulnerable to ‘pool overruns’ rather than having to check for them, after the fact, so to speak?

To quote again: “It doesn’t mean pool overruns are impossible to exploit, but it significantly increases the work for an attacker

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • StumbleUpon
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Propeller
  • Slashdot
  • Technorati
  • TwitThis
  • Webnews
  • YahooMyWeb

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channel. To use your own IRC client, join channel #boycottnovell in FreeNode.

Pages that cross-reference this one

4 Comments

  1. saulgoode said,

    May 29, 2009 at 11:14 am

    Gravatar

    Are there any actual examples of ‘pool overruns’, in the public domain, that can be successfully run on Mac OS X and GNU/Linux?

    The article doesn’t actually state that the “pool overruns” exploit has ever been a problem for OS X or GNU/Linux, only that the independent security evaluator who reported on the Microsoft problem has (at some point in his career) “exploited weaknesses” on those systems. From the wording of the article it should not be presumed that said weaknesses had anything to do with “pool overruns” (or even that they were serious).

    Roy Schestowitz Reply:

    Some say it’s just a fancy name for “buffer overflows”.

    Sabayon User (YGUG) Reply:

    You really have no idea what you’re talking about, do you?

  2. aeshna23 said,

    May 29, 2009 at 11:41 am

    Gravatar

    I’m way out of my area of knowledge here, but I did have one guess about what’s going on here. It’s my understanding that the applications and the operating system are as not as isolated from each in Windows as in Unix based operating systems. Since pool overruns exploit OS bugs, could it be that Windows needs safe unlinking much more than any other OS? Are they just fixing a problem created by the original poor design of Windows?

What Else is New


  1. Windows 'Battery Killer' (Vista 7) Also Has USB Data Transfer Issues and Stability Problems, Does Not Sell Well

    Vista 7 is plagued by serious bugs and new patches from Microsoft are said to be making things even worse; Microsoft is still unable to formulate a response to the new problems and Vista 7 sales continue to disappoint, so more vapourware and fake "leaks" are being used instead



  2. Norwegian Agency for Public Management and eGovernment Slams Microsoft OOXML

    The authorities in Norway justify the country's decision to reject Microsoft's standards-hostile ploy



  3. Steve Ballmer Visits Obama Once Again as His Fight Against Google Continues

    Updates on the competition between Microsoft and Google -- a rivalry that takes political form



  4. Microsoft's Hostile Takeover of the Healthcare System

    Microsoft wants to make medical records and management of patients a lot more dependent on Windows and its own private servers



  5. More Mono and Patent Poison from Novell

    “Pinta” comes from Novell staff and software patents tax (on SLE*) comes from Microsoft in the form of vouchers



  6. Patents Roundup: EFF Defends VoIP; Google, Apple, and Black Duck Stifle Progress; Microsoft Joins RPX

    A quick look at some patent news from the past week, ranging from defence to offence



  7. United Nations and World Bank Help Bill Gates and Microsoft Colonise Africa

    Microsoft's and Gates' incursions in Africa are backed by self-serving Western agenda of patents and proprietary software



  8. IRC: #boycottnovell @ FreeNode: February 8th, 2010

    IRC Log for February 8th, 2010



  9. Links 8/2/2010: Linux 2.6.33 RC7 and Parsix GNU/Linux 3.0r2 Released

    Links for the day



  10. Xbox 360 Still Under Many Lawsuits

    Lawsuits from many fronts add to the trouble that Microsoft's Xbox 360 already faces



  11. Facebook and Microsoft Revisited; New Examples of Microsoft Entryism

    A look at Facebook's relationship with Microsoft in 2010; Microsoft employees have an effect in competitors of Microsoft, so this issue is addressed too



  12. Microsoft Still Exploits the Taxpayers-Funded NASA to Spread Silver Lie and Close Down Research

    Microsoft-imposed corruption of NASA's obligation to the public carries on as it strives to capture academia too



  13. Microsoft 'Cloud' Falls Offline for a Quarter of a Day, Zune 'Cloud' Deletes Music, Microsoft Shop Also Kaput

    Microsoft continues to give online operations and online storage a bad name because of its sheer incompetence



  14. Ubuntu Perspectives: Signs of Change

    Analysis of Canonical's latest moves, which are being defended by some and severely criticised by others



  15. Apple's Newton Executive Negative About Apple's Latest Attempts at a Shinier Newton

    Apple's iPad still faces sometimes-overwhelming criticism, even from the company's own supporters and existing/former staff



  16. Microsoft Loses Another Vice President, Management Vacuum Alarms the Press

    Another Microsoft Vice President has just left Microsoft, joining the ranks of many more



  17. IRC: #boycottnovell @ FreeNode: February 7th, 2010

    IRC Log for February 7th, 2010



  18. Links 07/2/2010: Linux Mint 8 KDE, Linus on Nexus One

    Links for the day



  19. Patents Roundup: Extortion, Protection Rackets, Patent Trolling, and Small Victory for Mozilla

    Johnson and Johnson's multi-billion-dollar patent fine, patents' harms to real science and life, patent trolls thrive, and Mozilla's opposition to patent-encumbered codecs gradually pays off



  20. The Microsoft Apologists and Boosters Really, Really Like Novell!

    A complete list of news articles about Moonlight 3.0 preview shows that its biggest fans are Microsoft fans



  21. iPad is Like Zune

    iPad -- like Zune -- might not reach the European Union (EU), possibly due to lukewarm reception and lack of appeal, not trademarks



  22. Microsoft Shows Yet Again That It is Allergic to GNU/Linux

    Microsoft's hatred of GNU/Linux, as demonstrated in this weekend's news



  23. Michael Arrington a Hypocrite: Bribed by Microsoft Yet Fires Bribed Bloggers

    Another fine example of an influential blogger who sells out to Microsoft yet does not apply to himself the same standards that he applies to colleagues



  24. Microsoft Refuses to Comment About (Deny) the Sex Parties, Drug Use

    No denial from Microsoft in the face of very strong allegations



  25. Another Misdirected Response from the Government to the Company “Not Engineered for Security”

    Another terrible month for Microsoft insecurity and the government is still unable to respond sensibly to the threat



  26. IRC: #boycottnovell @ FreeNode: February 6th, 2010

    IRC Log for February 6th, 2010



  27. Links 6/2/2010: GNOME Journal Released, ARM CEO Sees Bright Future

    Links for the day



  28. Novell Executives Still Cannot Write Blog Posts?

    New evidence of ghostwriters in Novell's own Web site



  29. Microsoft Wants More Licensing Instead of Windows Bans

    At the World Economic Forum in Davos, Microsoft super-lobbyist Craig Mundie requests new laws that complicate the Internet and ignore the real problem (Microsoft negligence)



  30. Oracle Gates

    A look back at nonsensical predictions and lack of foresight from Microsoft's Nostradamus


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts