The release of Windows XP could mean the end of the Internet as we know it!

BD2003

Lifer
Oct 9, 1999
16,815
1
81
Woohoo, bring out the whistleblowers! Hehe, wasnt y2k supposed to cause mass anarchy worldwide? What happened in the end? A gas pump in austraila failed.
 

DeepBlue

Member
May 26, 2001
101
0
0


<< Woohoo, bring out the whistleblowers! Hehe, wasnt y2k supposed to cause mass anarchy worldwide? What happened in the end? A gas pump in austraila failed. >>


LOL, which gas pump was that?
 

Noriaki

Lifer
Jun 3, 2000
13,640
1
71
Jeez will it never end?

Unix has support &quot;Raw Sockets&quot; for years and years.

All you need is one machine that can spoof source IPs that has a decently fast connection....there are LOTS of available unix machines to do that.

If you can't find one...set one up...so you have a bunch of PCs that can do it now to. Big deal. Win2000 and I'm pretty sure NT4 can do it to....sure the average home user won't know how to protect themselves...but then the Firewall is set up by default so most users will have &quot;ignorance protection&quot; because they won't know how to disable the firewall (or need to).

Why is XP the target of so much FUD? I admit I've fallen prey to it a bit as well...but seriously...Raw Sockets? That's realllllllly stretching for something to beat on...

This guy is, either:
A) Very Paranoid
B) Has a beef with MS (penis envy I would say)
C) Has nothing better to do that try to stir up sh*t
D) Some or All of the above
 

juiio

Golden Member
Feb 28, 2000
1,433
4
81
What a fool. I'd like to echo Noriaki's comments. Unix has had raw socket support for a long time.
 

DoctorPizza

Banned
Jun 4, 2001
106
0
0
The concern that Steve Gibson has is that machines running XP are more likely to be compromised by Sub7-style trojans, and so the raw sockets ability is hence more dangerous.

I'd respond to this by making the point that whilst versions of Windows prior to Windows 2000 don't support the IP_HDRINCL socket option, they do still provide mechanisms for spoofing IP packets (you can inject them through NDIS/TDI, which are lower-level parts of the networking driver stack).

That is to say, even on Windows 9x -- an OS that has no security mechanisms whatsoever (Win2K/XP restrict SOCK_RAW to Administrators) -- it is possible, and has been possible for a number of years, to spoof IP headers.

So he's being paranoid, reactionary, and quite ridiculous in his casting of blame.
 

00aStrOgUy00

Banned
Apr 18, 2001
598
0
0
damn if there were never these ?&ugrave;&ccedil;k&icirc;&ntilde;g hackers we would never have these problems!!! DAMN WHY CAN'T YOU DAMN HACKERS JUST FOLLOW THE RULES AND PLAY IT NICE?!?! I HAVE BEEN HACKED BY 11 DIFFERENT KINDS OF TROJANS BEFORE!!
 

Condor Beedee

Member
Nov 19, 1999
62
0
0
You should read his description of a Denial of Service attack against his website. I found it very interesting, and it gives background to some of his claims (although I must admit I have no idea exactly why XP will be worse than 98). Still, it is a very interesting article.

http://grc.com/dos/grcdos.htm

Condor Beedee
 

DeepBlue

Member
May 26, 2001
101
0
0


<< Jeez will it never end?

Unix has support &quot;Raw Sockets&quot; for years and years.

All you need is one machine that can spoof source IPs that has a decently fast connection....there are LOTS of available unix machines to do that.

If you can't find one...set one up...so you have a bunch of PCs that can do it now to. Big deal. Win2000 and I'm pretty sure NT4 can do it to....sure the average home user won't know how to protect themselves...but then the Firewall is set up by default so most users will have &quot;ignorance protection&quot; because they won't know how to disable the firewall (or need to).

Why is XP the target of so much FUD? I admit I've fallen prey to it a bit as well...but seriously...Raw Sockets? That's realllllllly stretching for something to beat on...

This guy is, either:
A) Very Paranoid
B) Has a beef with MS (penis envy I would say)
C) Has nothing better to do that try to stir up sh*t
D) Some or All of the above
>>


Actually I think it stems from the fact that his site was shut down by a 13 year old and he said if the machines had Raw Sockets it would have been much worse. He wrote a LONG article that tells the story of him getting hacked by the kid.
 

DoctorPizza

Banned
Jun 4, 2001
106
0
0


<< damn if there were never these ?&ugrave;&ccedil;k&icirc;&ntilde;g hackers we would never have these problems!!! DAMN WHY CAN'T YOU DAMN HACKERS JUST FOLLOW THE RULES AND PLAY IT NICE?!?! I HAVE BEEN HACKED BY 11 DIFFERENT KINDS OF TROJANS BEFORE!! >>


Sorry, 'fraid not.

You don't get &quot;hacked&quot; by trojans. If you run a trojan, you have no-one to blame but yourself. The only person who compromised the machine is yourself, for running the trojan. That's the nature of trojans. *You* have to run them. *You* have to compromise your machine.
 

BlvdKing

Golden Member
Jun 7, 2000
1,173
0
0
I too have read the article about &quot;Wicked&quot;. Most people are unaware that they are opening up these trojans in thier email and making thier machine a zombie. This WindowsXP situation with a full socket will probably have some consequences, but probably not as extreme as the author has written.