Reply to post: Re: @Destroy All Monsters - you got pwned

Sysadmins, patch now: HTTP 'pings of death' are spewing across web to kill Windows servers

tom dial Silver badge

Re: @Destroy All Monsters - you got pwned

But the implicit point was that we have multiprogramming operating systems partly to isolate tasks from each other and from the kernel to prevent spread of corruption from errors. By putting the probably avoidable error in kernel mode code when it was not functionally necessary, Microsoft committed an additional error. Other posters have noted that Apache has errors, as does IIS. However, Apache does not run as a privileged user, and its errors there will not, as will CVE-2015-1635 in unpatched IIS I if I understand correctly, allow *your least favorite sigint agency or criminal enterprise* to install malicious software of its choice into your operating system.

Putting the erroneous code in the kernel was a mistake.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon