<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Windows 7: Released with known critical bug</title>
	<atom:link href="http://www.news.software.coop/windows-7-released-with-known-critical-bug/807/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.news.software.coop/windows-7-released-with-known-critical-bug/807/</link>
	<description>Updates seen at the co-operative for Software</description>
	<lastBuildDate>Mon, 28 Jun 2010 11:51:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Jon</title>
		<link>http://www.news.software.coop/windows-7-released-with-known-critical-bug/807/comment-page-1/#comment-16836</link>
		<dc:creator>Jon</dc:creator>
		<pubDate>Fri, 30 Oct 2009 15:32:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.news.software.coop/?p=807#comment-16836</guid>
		<description>It&#039;s not clear whether this bug is exploitable with a factor-default windows 7 configuration, or whether the user must first turn on file/printer sharing and/or mark a directory as shared. I think that has a bearing on how critical this bug is.</description>
		<content:encoded><![CDATA[<p>It&#8217;s not clear whether this bug is exploitable with a factor-default windows 7 configuration, or whether the user must first turn on file/printer sharing and/or mark a directory as shared. I think that has a bearing on how critical this bug is.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Simon Waters</title>
		<link>http://www.news.software.coop/windows-7-released-with-known-critical-bug/807/comment-page-1/#comment-16755</link>
		<dc:creator>Simon Waters</dc:creator>
		<pubDate>Thu, 29 Oct 2009 17:47:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.news.software.coop/?p=807#comment-16755</guid>
		<description>I think the confusion is there are so many vulnerabilities in the SMB2 protocol stack that it is hard to keep track of them.

Microsoft fixed 3 issues in MS09-050 which were critical or important on all relevant platforms.

But this is a critical SMB vulnerability that wasn&#039;t fixed in MS09-050 as the article linked to explains.

From a practical perspective it is mostly irrelevant, in that anyone exposing protocols like SMB that are intended for office users, hasn&#039;t got the idea of minimizing the exposed services. Although viruses could exploit some of these to spread within a network once in, most of these are DoS issues.

Such a large number of vulnerabilities being discovered before release, does suggest that Microsoft coding practices are not exceeding industry standards. The bigger story here is that they aren&#039;t patching quickly when they know of issues, and they aren&#039;t backporting to &quot;supported&quot; operating systems quickly.</description>
		<content:encoded><![CDATA[<p>I think the confusion is there are so many vulnerabilities in the SMB2 protocol stack that it is hard to keep track of them.</p>
<p>Microsoft fixed 3 issues in MS09-050 which were critical or important on all relevant platforms.</p>
<p>But this is a critical SMB vulnerability that wasn&#8217;t fixed in MS09-050 as the article linked to explains.</p>
<p>From a practical perspective it is mostly irrelevant, in that anyone exposing protocols like SMB that are intended for office users, hasn&#8217;t got the idea of minimizing the exposed services. Although viruses could exploit some of these to spread within a network once in, most of these are DoS issues.</p>
<p>Such a large number of vulnerabilities being discovered before release, does suggest that Microsoft coding practices are not exceeding industry standards. The bigger story here is that they aren&#8217;t patching quickly when they know of issues, and they aren&#8217;t backporting to &#8220;supported&#8221; operating systems quickly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MJ Ray</title>
		<link>http://www.news.software.coop/windows-7-released-with-known-critical-bug/807/comment-page-1/#comment-16730</link>
		<dc:creator>MJ Ray</dc:creator>
		<pubDate>Thu, 29 Oct 2009 10:21:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.news.software.coop/?p=807#comment-16730</guid>
		<description>starting to?  ;-)  This isn&#039;t a new thing for me.  Three of the cooperative principles are &quot;education, training and information&quot;, &quot;cooperation among cooperatives&quot; and &quot;concern for community&quot;. http://www.ica.coop/coop/principles.html#5 - I&#039;m concerned that the co-op community may sleepwalk into Windows 7, so let&#039;s get some educational information about the alternatives out there.</description>
		<content:encoded><![CDATA[<p>starting to?  <img src='http://www.news.software.coop/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />   This isn&#8217;t a new thing for me.  Three of the cooperative principles are &#8220;education, training and information&#8221;, &#8220;cooperation among cooperatives&#8221; and &#8220;concern for community&#8221;. <a href="http://www.ica.coop/coop/principles.html#5">http://www.ica.coop/coop/principles.html#5</a> &#8211; I&#8217;m concerned that the co-op community may sleepwalk into Windows 7, so let&#8217;s get some educational information about the alternatives out there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: btw</title>
		<link>http://www.news.software.coop/windows-7-released-with-known-critical-bug/807/comment-page-1/#comment-16686</link>
		<dc:creator>btw</dc:creator>
		<pubDate>Wed, 28 Oct 2009 18:55:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.news.software.coop/?p=807#comment-16686</guid>
		<description>you&#039;re starting to sound like an annoying evangelical.</description>
		<content:encoded><![CDATA[<p>you&#8217;re starting to sound like an annoying evangelical.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MJ Ray</title>
		<link>http://www.news.software.coop/windows-7-released-with-known-critical-bug/807/comment-page-1/#comment-16661</link>
		<dc:creator>MJ Ray</dc:creator>
		<pubDate>Wed, 28 Oct 2009 12:50:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.news.software.coop/?p=807#comment-16661</guid>
		<description>in Windows 7?  Got link? If so, why hasn&#039;t anyone told cert-bund.de yet?</description>
		<content:encoded><![CDATA[<p>in Windows 7?  Got link? If so, why hasn&#8217;t anyone told cert-bund.de yet?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alphager</title>
		<link>http://www.news.software.coop/windows-7-released-with-known-critical-bug/807/comment-page-1/#comment-16654</link>
		<dc:creator>Alphager</dc:creator>
		<pubDate>Wed, 28 Oct 2009 10:02:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.news.software.coop/?p=807#comment-16654</guid>
		<description>The SMB2-Vulnerability was fixed two weeks ago...</description>
		<content:encoded><![CDATA[<p>The SMB2-Vulnerability was fixed two weeks ago&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MJ Ray (mjray) 's status on Wednesday, 28-Oct-09 07:06:33 UTC - Identi.ca</title>
		<link>http://www.news.software.coop/windows-7-released-with-known-critical-bug/807/comment-page-1/#comment-16647</link>
		<dc:creator>MJ Ray (mjray) 's status on Wednesday, 28-Oct-09 07:06:33 UTC - Identi.ca</dc:creator>
		<pubDate>Wed, 28 Oct 2009 07:06:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.news.software.coop/?p=807#comment-16647</guid>
		<description>[...] Published Windows 7: Released with known critical bug http://www.news.software.coop/windows-7-released-with-known-critical-bug/807/ [...]</description>
		<content:encoded><![CDATA[<p>[...] Published Windows 7: Released with known critical bug <a href="http://www.news.software.coop/windows-7-released-with-known-critical-bug/807/">http://www.news.software.coop/windows-7-released-with-known-critical-bug/807/</a> [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
