Winamp & Shoutcast Forums

Winamp & Shoutcast Forums (http://forums.winamp.com/index.php)
-   General Discussions (http://forums.winamp.com/forumdisplay.php?f=1)
-   -   URL can delete any file on WinXP (http://forums.winamp.com/showthread.php?t=104693)

kernal32 11th September 2002 08:07

URL can delete any file on WinXP
 
This ones ugly and serious.

If you are running XP beware. There is a security issues that is very dangerous. Basically a hacker "gives" you a URL. Once click or launched a hackers choice of files are deleted.

The "URL" is to Windows Help Centre (which is in built into XP). This URL calls WHC. It can be sent via e-mail, chat, hell even a forum posting or auto meta refreshing page! Beware for urls starting with HCP://

SP1 for windows XP appears to fix this problem.
More details and an "example" test for yourself is at http://www.surasoft.com/egflaws/xpurlflaw.htm

Curi0us_George 11th September 2002 08:33

Not if you're running Mozilla 1.2a. :)

n_ick2000 11th September 2002 17:32

You know, I am very close to going back to Win2k. It seems that really the only thing going for WinXP is it's new gui. I do have sp1 for XP, but I am wondering how many more of these huge exploites (sp?) will be found.

james 11th September 2002 17:38

I've already gone back to 2000 - I'm running Advanced Server on one box and Pro on another... the lack of visual w00tness is more than made up for by the increased stability and security :)

SNYder 11th September 2002 18:10

XP SP1 4 LIFE

c2R 11th September 2002 18:16

Quote:

Originally posted by n_ick2000
You know, I am very close to going back to Win2k. It seems that really the only thing going for WinXP is it's new gui. I do have sp1 for XP, but I am wondering how many more of these huge exploites (sp?) will be found.
I ran XP for a while at work - the XP styled GUI was the first thing I turned off - it's truely horrible! If that's all that it's got going for it you may as well fdisk now :D

psychoticguyver 11th September 2002 20:25

whats sp1 and where do you get it (in a very polite and crazy voice)

golferboy32531 11th September 2002 20:28

The laptops that my school has issued to we students use WinXP. I've killed the pretty, yet bloaty GUI down to Win95/98 levels. Gotta love options!!!

Reaper 11th September 2002 20:31

You don't even need SP1 to fix this problem, just follow the steps below.

1. Perform a search for a file on your C drive called "uplddrvinfo.htm".

2. Once you have found the file, delete it or rename it.

eleet-2k2 11th September 2002 20:57

Quote:

Originally posted by Reaper
You don't even need SP1 to fix this problem, just follow the steps below.

1. Perform a search for a file on your C drive called "uplddrvinfo.htm".

2. Once you have found the file, delete it or rename it.

Good ol' tech tv.

Actually, I'd recommend XP SP1 regardless because it fixes a whole bunch of other issues as well.

SNYder 11th September 2002 21:01

plus it has that new cool "set program accesss and defaults" in 'control panel/add or remove programs' that the courts made them put in. :)

XP SP1 r0x

Reaper 11th September 2002 21:03

Quote:

Originally posted by 31337-2k2
Good ol' tech tv.

Actually, I'd recommend XP SP1 regardless because it fixes a whole bunch of other issues as well.

Yup, yup, that's from TechTV. The Service Pack is a definite recommended download for XP. But if some people aren't that crazy about downloading it immediatly and are worried about the url problem, that's a quick fix.

Aeroe 11th September 2002 21:07

my XP irritation
 
i love those random messenger service spam popups, it's a default service that loads with XP (maybe just pro/server?) that allows messages to be sent by dos. it's always good to just turn it off. many people harvest IPs from sites and p2p.

i just got two this week and i didn't even know what they were until today. first reaction was it was something missed by kazaa lite, but it wasn't running. adaware didn't show anything either so i was even more confused.

to see how they work, goto Dos and type "net send <your IP> <message>" that's obviously if you want to see it for yourself. most XP users probably never turned off the service, maybe scare your friends :)


All times are GMT. The time now is 11:56.

Copyright © 1999 - 2010 Nullsoft. All Rights Reserved.