What happened to the Messenger Plus! forums on msghelp.net?
Shoutbox » MsgHelp Archive » General » Forum & Website » Mistruth in FAQ

Mistruth in FAQ
Author: Message:
Burningmace
Junior Member
**


Posts: 20
Joined: Sep 2008
O.P. RE: RE: Mistruth in FAQ
quote:
Originally posted by ShawnZ
burningmace: who the hell says "your box is owned"?

Do you mean "who uses that phrase?" or "why does that mean your box is owned?"

To answer both:
Who uses that phrase? - I use that phrase, and so do a lot of people. In fact, Microsoft's own Steve Riley uses it liberally in his presentations at TechEd.

Why does that mean your box is owned? - You have to assume any machine that has had an exploit run on it is completely under the control of the attacker - it is completely and utterly compromised.

I would also like to state that I am not disputing the standard of security in Messenger Plus. I am simply being realistic. I write code every day and I'm 110% sure that somewhere along the line I've written something that can be exploited in some way. I accept that. Any software developer that doesn't accept the fact that somewhere along the line their software or the libraries that it relies on will contain an exploitable bug is, frankly, a moron. What I'm trying to say is despite the fact that at current their are no known vulnerabilities (with an exception - see note below) in Messenger Plus, there is no way to tell if there are unknown vulnerabilities and you need to cover yourself from and inform your users of such eventualities.

Note regarding vulns - The exception is the obvious, practically unavoidable DNS/ARP spoofing man-in-the-middle attacks on the update socket, that (as far as I am aware in the case of Messenger Plus) has never been performed.

This post was edited on 09-23-2008 at 10:04 PM by Burningmace.
09-23-2008 09:51 PM
Profile E-Mail PM Find Quote Report
« Next Oldest Return to Top Next Newest »

Messages In This Thread
Mistruth in FAQ - by Burningmace on 09-23-2008 at 07:46 PM
RE: Mistruth in FAQ - by matty on 09-23-2008 at 08:09 PM
RE: Mistruth in FAQ - by Burningmace on 09-23-2008 at 08:15 PM
RE: Mistruth in FAQ - by matty on 09-23-2008 at 08:32 PM
RE: Mistruth in FAQ - by Burningmace on 09-23-2008 at 09:00 PM
RE: Mistruth in FAQ - by ShawnZ on 09-23-2008 at 09:35 PM
RE: RE: Mistruth in FAQ - by Burningmace on 09-23-2008 at 09:51 PM
RE: Mistruth in FAQ - by riahc4 on 09-23-2008 at 10:02 PM
RE: RE: Mistruth in FAQ - by Burningmace on 09-23-2008 at 10:11 PM
RE: Mistruth in FAQ - by Voldemort on 09-23-2008 at 10:05 PM
RE: Mistruth in FAQ - by ShawnZ on 09-23-2008 at 10:22 PM
RE: RE: Mistruth in FAQ - by Burningmace on 09-23-2008 at 10:27 PM
RE: Mistruth in FAQ - by foaly on 09-23-2008 at 10:44 PM
RE: Mistruth in FAQ - by Burningmace on 09-23-2008 at 11:01 PM
RE: RE: Mistruth in FAQ - by segosa on 09-23-2008 at 11:41 PM
RE: Mistruth in FAQ - by Link_of_Hyrule on 09-23-2008 at 11:09 PM
RE: Mistruth in FAQ - by ShawnZ on 09-23-2008 at 11:24 PM
RE: Mistruth in FAQ - by Burningmace on 09-23-2008 at 11:31 PM
RE: Mistruth in FAQ - by Burningmace on 09-23-2008 at 11:58 PM
RE: RE: Mistruth in FAQ - by segosa on 09-24-2008 at 12:21 AM
RE: Mistruth in FAQ - by ShawnZ on 09-24-2008 at 12:10 AM
RE: Mistruth in FAQ - by Burningmace on 09-24-2008 at 12:20 AM
RE: Mistruth in FAQ - by WDZ on 09-24-2008 at 12:35 AM
RE: Mistruth in FAQ - by Burningmace on 09-24-2008 at 12:37 AM
RE: RE: Mistruth in FAQ - by segosa on 09-24-2008 at 01:10 AM
RE: Mistruth in FAQ - by Lou on 09-24-2008 at 01:10 AM
RE: RE: Mistruth in FAQ - by Burningmace on 09-24-2008 at 10:09 AM
RE: Mistruth in FAQ - by Menthix on 09-24-2008 at 11:25 AM
RE: Mistruth in FAQ - by Spunky on 09-24-2008 at 01:38 PM


Threaded Mode | Linear Mode
View a Printable Version
Send this Thread to a Friend
Subscribe | Add to Favorites
Rate This Thread:

Forum Jump:

Forum Rules:
You cannot post new threads
You cannot post replies
You cannot post attachments
You can edit your posts
HTML is Off
myCode is On
Smilies are On
[img] Code is On