[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

GOOGLE SPILLS THE BEANS AND DISCLOSES ANOTHER 0-DAY THAT MAKES

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 117
Thread images: 18

File: 1467167537894.jpg (2MB, 2000x2000px) Image search: [Google]
1467167537894.jpg
2MB, 2000x2000px
0-DAY IS BEING A.C.T.I.V.E.L.Y EXPLOITED IN THE WILD
https://thehackernews.com/2016/10/google-windows-zero-day.html

>According to a blog post by Google's Threat Analysis Group, the reason behind going public is that it has seen exploits for the vulnerability in the wild and according to its internal policy, companies should patch or publicly report such bugs after seven days.
The zero-day is a local privilege escalation vulnerability that exists in the Windows operating system kernel. If exploited, the flaw can be used to escape the sandbox protection and execute malicious code on the compromised system.
>The flaw "can be triggered via the win32k.sys system call NtSetWindowLongPtr() for the index GWLP_ID on a window handle with GWL_STYLE set to WS_CHILD," Google's Neel Mehta and Billy Leonard said in a blog post.
Chrome actually blocked the vulnerability for itself using win2k sandboxing, since winpajeets failed to fix this themselves

""""Microsoft is not at all happy about the disclosure.""""

>Microsoft said Google's disclosure has potentially placed customers at risk, adding that the company believes in coordinated vulnerability disclosure.

C U C K E D
A G A I N,
W I N C U C K S
>>
kek
someone count the days until this gets fixed if ever
if it was on linux it would be fixed already but windows is a closed source spaghetti
>>
A lot of these exploits aren't just magical bullets. You still need to access the system in the first place.
>>
>>57351441
>Coordinated vulnerability disclosure

Aka if no big client get hit,and only a few non emprise fag ignore it
>>
File: meme.jpg (62KB, 816x431px) Image search: [Google]
meme.jpg
62KB, 816x431px
>>57351441
Negro please, I keep Windows fully updated, avoid malicious websites and torrents, and have a reputable AV in charge of my system.
>>
>>57351441
THIS is why you NEVER run windows outside VMs
>>
>>57351470
>windows
>""anti"" virus
lmao go back to >>>/v/
>>
Fucking lol, to exploit this you need win32k.sys access. If you let an app get that kind of access, you have way more serious problems than this exploit.

Also, can't be exploited through Edge (Firefox not yet confirmed)... but can be abused through Chrome that has system access.

Malicious botnet browser by a malicious and evil company. That the day would come that I hate google more than MS. Fucking lol, pathetic excuses for human beings...
>>
>>57351479
So being proactive is considered /v/? What are you smoking?
>>
>>57351441
>le google this
>le google that
>i read up about le google every day

honestly wish a bullet was put through your head
>>
>>57351489
I don't use Chrome. Firefox I don't use any suspicious add-ons and ublock keeps the fishy websites away.

You have to be really dumb to fall for exploits and wreck your system.
>>
>>57351492
Videogaming is not being productive
>>
>>57351503
I work in Finance and need Excel, QuickBooks and ERP related software for financial reporting.

These are Windows exclusive.
>>
WINCUCCS REKT AGAIN
>>
File: microsoft copy.png (1MB, 1300x4704px) Image search: [Google]
microsoft copy.png
1MB, 1300x4704px
>>57351452
>windows is a closed source spaghetti

you're darn tootin'
>>
>>57351506
>ERP
SAP faggot detected
>>
>>57351506
>erp

kill yourself you lonely faggot
>>
File: o i am laffin.jpg (11KB, 250x250px) Image search: [Google]
o i am laffin.jpg
11KB, 250x250px
>>57351441
>>
IT'S OVER
MICROKEK IS FINISHED AND BANKRUPT
WINPOOKEKS ON SUICIDE WATCH
>>
>>57351512
>darn
>tootin'

(((Autism Speaks)))
>>
>>57351513
>>57351520
Name one major company that does not rely on Oracle and SAP modules. Everything is interconnected so data can be processed real time for daily reporting.
>>
File: CsMyhF4UkAAkvSA.jpg (138KB, 900x1200px) Image search: [Google]
CsMyhF4UkAAkvSA.jpg
138KB, 900x1200px
THIS IS GOOGLE DAMAGE CONTROL

GOOGLE KNOWS 99% OF ANDROID DEVICES HAVE AN UNFIXABLE VULNERABILITY AT KERNEL LEVEL

THEY ARE TRYING TO SAY HEY DON'T LOOK AT US, LOOK AT THEM

IT'S PATHETIC AND IRRESPONSIBLE

1.4 billion Android devices vulnerable to hijacking thanks to Linux TCP bug
8 out of 10 Android devices vulnerable to spying since they are vulnerable to the Linux TCP bug.

http://www.computerworld.com/article/3108618/security/1-4-billion-android-devices-vulnerable-to-hijacking-thanks-to-linux-tcp-bug.html
>>
File: nickle.jpg (304KB, 1220x1480px) Image search: [Google]
nickle.jpg
304KB, 1220x1480px
>>57351535
>>
>>57351536
>being THIS autistic
>>
>>57351536
>Proud of being a data cruncher
:/
>>
Google will be going bankrupt any day now.

Who cares?
>>
File: 1263269503.jpg (90KB, 1024x989px) Image search: [Google]
1263269503.jpg
90KB, 1024x989px
>>57351537
THIS IS MICROPOO DAMAGE CONTROL

100% OF WINDOWS DEVICES HAVE AN UNFIXABLE EXPLOIT AT KERNEL LEVEL

THEY ARE TRYING TO SAY HEY DON'T LOOK AT US, LOOK AT THEM

IT'S PATHETIC AND IRRESPONSIBLE

An UNFIXABLE windows bug has been exploited. So easy anyone can do it....

it provides you with the program you need to exploit the bug, as well as the instructions, which are easy enough for everyone here to follow. With it you can gain full priviledges from a guest account!


Apperantly this is unfixable right now and MS does not even consider it a flaw/bug.

http://www.theregister.co.uk/2016/10/28/windows_atom_tables_popped_by_security_researchers/
>>
>>57351553
see >>57351534
>>
>>57351513
>>57351536
>SAP
don't you have a few computer systems to take down so they don't crash and burn during the DST transition?
>>
>>57351441
WHY HAVEN'T WE FUCKING ENDED FLASH YET
KILL THIS CANCER RIGHT FUCKING NOW REEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE
>>
>>57351536
>Playing sand andreas multiplayer at work

Get a life you fucking manchild
>>
>>57351580
We did, like 5-10 years ago. I'm guessing you missed the memo and forgot to uninstall flash?
>>
>>57351580
>ADOBE FIXES BUG BEFORE WINSHIT
LMFAO
>>
>>57351588
*squeezes your balls really hard*

Fuck you
>>
File: 1457127921342.jpg (10KB, 200x200px) Image search: [Google]
1457127921342.jpg
10KB, 200x200px
>Falling for the winpoo meme
We warned you, /v/
>>
>>57351602
Ow, now why would you do that? You have nobody to blame but yourself for using flash
>>
File: enough.jpg (70KB, 393x325px) Image search: [Google]
enough.jpg
70KB, 393x325px
>>57351548
>>57351543
>>57351577
>>57351586
At least I am employed
>>
>>57351626
So am I, and my workplace routinely makes fun of SAP for being so terrible

Not everybody grows up to be an IT monkey restarting servers because SAP crashed
>>
File: 1467503302857.jpg (151KB, 736x937px) Image search: [Google]
1467503302857.jpg
151KB, 736x937px
W-Will Microsoft die soon, lads?
>>
>>57351441
>using win2k sandboxing
So, Win2000 was the host?
>Win2000 is safer despite being 17 years old
kek
>>
>Google are the good guys

https://wikileaks.org/podesta-emails/emailid/37262
>>
>>57351659

THIS

FUCKING GOOGLE SHILLS
>>
↑ ↑ ↓ ↓ ← → ← → holy shit i'm in
>>
why are we still making these threads? All OSes have a shitload of vulnerabilities, or are we pretending they don't? Anyone dedicated can break into your computer in minutes
>>
>>57351678
apply for janitor then fatass
>>
>>57351678
it's not the fact that windows has vulnerabilities, it's the fact that google is shitting on microsoft for not fixing their shit fast enough
>>
>>57351659
>Microsoft are good guys

https://wikileaks.org/plusd/cables/07KYIV1205_a.html
>>
>>57351678
>All OSes have a shitload of vulnerabilities
>>
>>57351698
thanks for proving my point I guess
>>
>>57351704
>I can't read
>>
>>57351704
>Microsoft
1754
>Apple
672
>Adobe
1225
>Google
316
>Linux
32

spot a pattern?
>>
>>57351707
I guess I can't. Which OS are you shilling and does it show 0 on the list?
>>
>>57351489
>to exploit this you need you need win32k.sys access
L M A O
Get a book on how your operating system works before talking about it.

Any application will be able to exploit this and escalate privileges. And most applications will be able to get used as leverage for a remote attacker.
>>
>>57351711
Shilling against the one that has the most vulnerability by the largest margin
>>
>>57351710
yeah I do, one OS has 50x the usage share of the other and is more actively targeted, therefore many more vulnerabilities are known
>>
>>57351711
>anything above 0 is a shitload
shifted those goalposts real fast, didn't you?
>>
>>57351720
Google has x150 usage than Micropoo
>>
>>57351503
Neither is spending all your time ricing or trying to figure out how to change the most basic shit.
>>
>>57351729
what the hell is "google"? Android? Wasn't there a critical Android kernel vulnerability discovered just last week?
>>
>>57351694
Didn't say that.
>link
Going after pirates is pretty mild compared to other shit they've done

Google Vs M$ is like comparing the merits of two diseases (or Trump vs Clinton)
>>
>>57351739
You mean the thing that happens to windows everyday?
>>
>>57351720
>yeah I do, one OS has 50x the usage share of the other
Linux has the largest market share by far, among both consumers and enterprise servers etc.
>>
>>57351744
yeah. See my point now?
>>
>>57351755
Not really, All I see is windows getting hit by vulnerabilities 24/7
>>
>>57351749
source? Especially the consumer part
>>
>>57351774
google "android marketshare"
>>
>>57351749
Linux has no "market share" at all since it's not on the fucking market.

Say Linux is the most used and we'll believe you but there will be no way to prove
>>
>>57351492
>proactive

I hate you.
>>
>>57351781
Android has more usage than Windows? Please off yourself for that comment
>>
>>57351698
>Linux has 5.5% of the critical vulnerabilities versus Windows at 7.9%

holy shit I use Linux but this is way closer than I want it to be
>>
>>57351797
That's weighed average
so average vuln level of linux is 6 while on windows it's 9/10
>>
>>57351797
That we know of on winblows
>>
>>57351810
like I said shockingly close

I would have thought Windows is 10/10 and Linux is like a 3.
>>
>>57351814
and that we know on Lelnix. Like I said, way more people are looking on one than the other
>>
>>57351470
Whats worse,
Being spied on for years on end by corporations that want to manipulate you
or,
A security breach by a criminal?

One could drain your bank account, the other
can manipulate voter opinion, track your thoughts as they develop, and influence society.
>>
>>57351886
>One could drain your bank account
that one
>>
>>57351892
Mememememme
>>
>>57351783
>android phones aren't sold commercially
>>
File: eFq.png (9KB, 1375x289px) Image search: [Google]
eFq.png
9KB, 1375x289px
>>57351789
Here's your (You)
>>
>>57351797
Guessing you can't read?

>Linux 2%
>Windows 41%
>>
>>57352215
>Windows 4300 vulnerabilities
>Linux 1350
>The bug-ridden piece of shit PajeetOS has barely 3 times as many critical bugs

AAHAHAHAHAHAHAHAHA
>>
>>57352202
ok now take those stats back to the early 1990s for this to be relevant
>>
>>57351502
>fishy websites
>visits 4chan
Top kek m8 here's your (You)
>>
>>57351816
the huge difference is in how fast they get fixed.
>>
>>57352308
like that Linux kernel bug that has been there for 9 years?
>>
>>57352257
Those stats are since the early 2000s

Also, Microsoft still generates about 10 as many critical vulnerabilities to this day. Stats since 2016:

http://0x0.st/My
http://0x0.st/Mt
>>
>>57352251
Most of those Linux vulernabilities are low-score (i.e. mostly harmless) ones.

Most of those Windows vulnerabilities are high-score (i.e. your shit can get rooted remotely) ones.
>>
>>57352325
I never said Microsoft doesn't develop turds

I said, unless you download .exes from Russian websites, the realistic danger for you is 0, unless someone serious wants to get into your computer, at which point you're fucked whatever OS you use
>>
>>57352334
Sure, just keep pretending security vulnerabilities don't happen and maybe you won't even notice whenever your internet seems to be slow because you're part of a DDoS botnet
>>
File: gary attack.gif (871KB, 320x180px) Image search: [Google]
gary attack.gif
871KB, 320x180px
>>57351441
>>
>>57352374
I run security scans often enough. That plus the security patches takes care of the low-effort infiltration and as for the high-effort - you might be in a botnet right now without knowing it
>>
>>57352334
>damage control/10
>>
>>57352395
>I run security scans often enough.
yes goy, give your $$$ to symantec, i'm sure it will keep you safe :^^)
>>
>>57352404
learn to read, I'm not gonna spoonfeed you
>>
>>57352407
not an argument. How's that botnet on your computer?
>>
>>57352316
Been there is not the same as being there and having been disclosed.
>>
>>57352423
it's under active exploit so it sounds like whoever needed disclosing got it
>>
>>57352404
keep up the good work, Rajesh. everyone at Microsoft is counting on you.
>>
>>57352490
>can't even reply to the right post
the Linux power user, everybody
>>
>>57352500
>/g/ is one person
the Microsoft evangelist, everybody.
>>
>>57352542
so there's more than one retard in this thread. Not surprising
>>
File: 1325536774534.jpg (12KB, 150x132px) Image search: [Google]
1325536774534.jpg
12KB, 150x132px
>all this windows damage control
Ebin
>>
File: 1474601675599.jpg (80KB, 766x960px) Image search: [Google]
1474601675599.jpg
80KB, 766x960px
ITT: /g/ posters = /v/ posters
>>
>>57352547
>0day vulnerability
>not a realistic danger
But you are the retard, anon.
>>
Should I get an AMD 480 or a Geforce GTX 1080 ??
>>
File: 1477988774881.jpg (152KB, 518x510px) Image search: [Google]
1477988774881.jpg
152KB, 518x510px
>>57352647
Is this a joke or a serious question?
>>
>To exploit this vulnerability, an attacker requires local access to an affected computer.

Wew, it's fucking nothing.
>>
>>57352940
>what is privilege escalation
>>
There's usually a vurn like this avaliable, it's not a surprise.
>>
>>57352940
>zero days are nothing
Easiest way to spot the pajeet
>>
>>57352973
>what is common sense
>>
File: 120.jpg (54KB, 800x804px) Image search: [Google]
120.jpg
54KB, 800x804px
>>57351441

>Google spills beans about Microsoft wangblows being insecure
>meanwhile, lagdroid has over 1 billion insecure android phones because Google is being lazy and cheap and doesn't manage the security updates centralized and instead leave it to the phone manufacturers to update their phones.

stagefright and dirty cow anyone??
>>
>>57353009
Privilege escalation means you need to be running code already to use it. Your comment is simply redundant and incorrect, it doesn't have to be physical access.
>>
File: 1383763479987.png (128KB, 308x308px) Image search: [Google]
1383763479987.png
128KB, 308x308px
>>57353022
>talks about android being insecure
>uses red hat vulnerability as proof
>>
>>57353054
Actually for these vulnerabilities it does.
>>
It would be irresponsible to not disclose a vulnerability that is being actively used against people. Microsoft needs to step up their game.
>>
>>57353201
Red hat vulnerability?
Thread posts: 117
Thread images: 18


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.