GOOGLE SPILLS THE BEANS AND DISCLOSES ANOTHER 0-DAY THAT MAKES ALL WINDOWS USERS VULNERABLE

0-DAY IS BEING A.C.T.I.V.E.L.Y EXPLOITED IN THE WILD
thehackernews.com/2016/10/google-windows-zero-day.html

>According to a blog post by Google's Threat Analysis Group, the reason behind going public is that it has seen exploits for the vulnerability in the wild and according to its internal policy, companies should patch or publicly report such bugs after seven days.
The zero-day is a local privilege escalation vulnerability that exists in the Windows operating system kernel. If exploited, the flaw can be used to escape the sandbox protection and execute malicious code on the compromised system.
>The flaw "can be triggered via the win32k.sys system call NtSetWindowLongPtr() for the index GWLP_ID on a window handle with GWL_STYLE set to WS_CHILD," Google's Neel Mehta and Billy Leonard said in a blog post.
Chrome actually blocked the vulnerability for itself using win2k sandboxing, since winpajeets failed to fix this themselves

""""Microsoft is not at all happy about the disclosure.""""

>Microsoft said Google's disclosure has potentially placed customers at risk, adding that the company believes in coordinated vulnerability disclosure.

C U C K E D
A G A I N,
W I N C U C K S

Other urls found in this thread:

computerworld.com/article/3108618/security/1-4-billion-android-devices-vulnerable-to-hijacking-thanks-to-linux-tcp-bug.html
theregister.co.uk/2016/10/28/windows_atom_tables_popped_by_security_researchers/
wikileaks.org/podesta-emails/emailid/37262
wikileaks.org/plusd/cables/07KYIV1205_a.html
0x0.st/My
0x0.st/Mt
twitter.com/AnonBabble

kek
someone count the days until this gets fixed if ever
if it was on linux it would be fixed already but windows is a closed source spaghetti

A lot of these exploits aren't just magical bullets. You still need to access the system in the first place.

>Coordinated vulnerability disclosure

Aka if no big client get hit,and only a few non emprise fag ignore it

Negro please, I keep Windows fully updated, avoid malicious websites and torrents, and have a reputable AV in charge of my system.

THIS is why you NEVER run windows outside VMs

>windows
>""anti"" virus
lmao go back to

Fucking lol, to exploit this you need win32k.sys access. If you let an app get that kind of access, you have way more serious problems than this exploit.

Also, can't be exploited through Edge (Firefox not yet confirmed)... but can be abused through Chrome that has system access.

Malicious botnet browser by a malicious and evil company. That the day would come that I hate google more than MS. Fucking lol, pathetic excuses for human beings...

So being proactive is considered Sup Forums? What are you smoking?

>le google this
>le google that
>i read up about le google every day

honestly wish a bullet was put through your head

I don't use Chrome. Firefox I don't use any suspicious add-ons and ublock keeps the fishy websites away.

You have to be really dumb to fall for exploits and wreck your system.

Videogaming is not being productive

I work in Finance and need Excel, QuickBooks and ERP related software for financial reporting.

These are Windows exclusive.

WINCUCCS REKT AGAIN

>windows is a closed source spaghetti

you're darn tootin'

>ERP
SAP faggot detected

>erp

kill yourself you lonely faggot

...

IT'S OVER
MICROKEK IS FINISHED AND BANKRUPT
WINPOOKEKS ON SUICIDE WATCH

>darn
>tootin'

(((Autism Speaks)))

Name one major company that does not rely on Oracle and SAP modules. Everything is interconnected so data can be processed real time for daily reporting.

THIS IS GOOGLE DAMAGE CONTROL

GOOGLE KNOWS 99% OF ANDROID DEVICES HAVE AN UNFIXABLE VULNERABILITY AT KERNEL LEVEL

THEY ARE TRYING TO SAY HEY DON'T LOOK AT US, LOOK AT THEM

IT'S PATHETIC AND IRRESPONSIBLE

1.4 billion Android devices vulnerable to hijacking thanks to Linux TCP bug
8 out of 10 Android devices vulnerable to spying since they are vulnerable to the Linux TCP bug.

computerworld.com/article/3108618/security/1-4-billion-android-devices-vulnerable-to-hijacking-thanks-to-linux-tcp-bug.html

...

>being THIS autistic

>Proud of being a data cruncher
:/

Google will be going bankrupt any day now.

Who cares?

THIS IS MICROPOO DAMAGE CONTROL

100% OF WINDOWS DEVICES HAVE AN UNFIXABLE EXPLOIT AT KERNEL LEVEL

THEY ARE TRYING TO SAY HEY DON'T LOOK AT US, LOOK AT THEM

IT'S PATHETIC AND IRRESPONSIBLE

An UNFIXABLE windows bug has been exploited. So easy anyone can do it....

it provides you with the program you need to exploit the bug, as well as the instructions, which are easy enough for everyone here to follow. With it you can gain full priviledges from a guest account!


Apperantly this is unfixable right now and MS does not even consider it a flaw/bug.

theregister.co.uk/2016/10/28/windows_atom_tables_popped_by_security_researchers/

see

>SAP
don't you have a few computer systems to take down so they don't crash and burn during the DST transition?

WHY HAVEN'T WE FUCKING ENDED FLASH YET
KILL THIS CANCER RIGHT FUCKING NOW REEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEE

>Playing sand andreas multiplayer at work

Get a life you fucking manchild

We did, like 5-10 years ago. I'm guessing you missed the memo and forgot to uninstall flash?

>ADOBE FIXES BUG BEFORE WINSHIT
LMFAO

*squeezes your balls really hard*

Fuck you

>Falling for the winpoo meme
We warned you, Sup Forums

Ow, now why would you do that? You have nobody to blame but yourself for using flash

At least I am employed

So am I, and my workplace routinely makes fun of SAP for being so terrible

Not everybody grows up to be an IT monkey restarting servers because SAP crashed

W-Will Microsoft die soon, lads?

>using win2k sandboxing
So, Win2000 was the host?
>Win2000 is safer despite being 17 years old
kek

>Google are the good guys

wikileaks.org/podesta-emails/emailid/37262

THIS

FUCKING GOOGLE SHILLS

↑ ↑ ↓ ↓ ← → ← → holy shit i'm in

why are we still making these threads? All OSes have a shitload of vulnerabilities, or are we pretending they don't? Anyone dedicated can break into your computer in minutes

apply for janitor then fatass

it's not the fact that windows has vulnerabilities, it's the fact that google is shitting on microsoft for not fixing their shit fast enough

>Microsoft are good guys

wikileaks.org/plusd/cables/07KYIV1205_a.html

>All OSes have a shitload of vulnerabilities

thanks for proving my point I guess

>I can't read

>Microsoft
1754
>Apple
672
>Adobe
1225
>Google
316
>Linux
32

spot a pattern?

I guess I can't. Which OS are you shilling and does it show 0 on the list?

>to exploit this you need you need win32k.sys access
L M A O
Get a book on how your operating system works before talking about it.

Any application will be able to exploit this and escalate privileges. And most applications will be able to get used as leverage for a remote attacker.

Shilling against the one that has the most vulnerability by the largest margin

yeah I do, one OS has 50x the usage share of the other and is more actively targeted, therefore many more vulnerabilities are known

>anything above 0 is a shitload
shifted those goalposts real fast, didn't you?

Google has x150 usage than Micropoo

Neither is spending all your time ricing or trying to figure out how to change the most basic shit.

what the hell is "google"? Android? Wasn't there a critical Android kernel vulnerability discovered just last week?

Didn't say that.
>link
Going after pirates is pretty mild compared to other shit they've done

Google Vs M$ is like comparing the merits of two diseases (or Trump vs Clinton)

You mean the thing that happens to windows everyday?

>yeah I do, one OS has 50x the usage share of the other
Linux has the largest market share by far, among both consumers and enterprise servers etc.

yeah. See my point now?

Not really, All I see is windows getting hit by vulnerabilities 24/7

source? Especially the consumer part

google "android marketshare"

Linux has no "market share" at all since it's not on the fucking market.

Say Linux is the most used and we'll believe you but there will be no way to prove

>proactive

I hate you.

Android has more usage than Windows? Please off yourself for that comment

>Linux has 5.5% of the critical vulnerabilities versus Windows at 7.9%

holy shit I use Linux but this is way closer than I want it to be

That's weighed average
so average vuln level of linux is 6 while on windows it's 9/10

That we know of on winblows

like I said shockingly close

I would have thought Windows is 10/10 and Linux is like a 3.

and that we know on Lelnix. Like I said, way more people are looking on one than the other

Whats worse,
Being spied on for years on end by corporations that want to manipulate you
or,
A security breach by a criminal?

One could drain your bank account, the other
can manipulate voter opinion, track your thoughts as they develop, and influence society.

>One could drain your bank account
that one

Mememememme

>android phones aren't sold commercially

Here's your (You)

Guessing you can't read?

>Linux 2%
>Windows 41%

>Windows 4300 vulnerabilities
>Linux 1350
>The bug-ridden piece of shit PajeetOS has barely 3 times as many critical bugs

AAHAHAHAHAHAHAHAHA

ok now take those stats back to the early 1990s for this to be relevant

>fishy websites
>visits Sup Forums
Top kek m8 here's your (You)

the huge difference is in how fast they get fixed.

like that Linux kernel bug that has been there for 9 years?

Those stats are since the early 2000s

Also, Microsoft still generates about 10 as many critical vulnerabilities to this day. Stats since 2016:

0x0.st/My
0x0.st/Mt

Most of those Linux vulernabilities are low-score (i.e. mostly harmless) ones.

Most of those Windows vulnerabilities are high-score (i.e. your shit can get rooted remotely) ones.

I never said Microsoft doesn't develop turds

I said, unless you download .exes from Russian websites, the realistic danger for you is 0, unless someone serious wants to get into your computer, at which point you're fucked whatever OS you use

Sure, just keep pretending security vulnerabilities don't happen and maybe you won't even notice whenever your internet seems to be slow because you're part of a DDoS botnet

...

I run security scans often enough. That plus the security patches takes care of the low-effort infiltration and as for the high-effort - you might be in a botnet right now without knowing it

>damage control/10

>I run security scans often enough.
yes goy, give your $$$ to symantec, i'm sure it will keep you safe :^^)

learn to read, I'm not gonna spoonfeed you

not an argument. How's that botnet on your computer?

Been there is not the same as being there and having been disclosed.

it's under active exploit so it sounds like whoever needed disclosing got it

keep up the good work, Rajesh. everyone at Microsoft is counting on you.

>can't even reply to the right post
the Linux power user, everybody

>Sup Forums is one person
the Microsoft evangelist, everybody.