Application Security

Microsoft Delays Windows XP Antivirus Doomsday

Security Essentials for XP gets 15-month extension, but some antivirus vendors promise updates through 2017 and beyond.

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
anon6040656171
50%
50%
anon6040656171,
User Rank: Apprentice
4/21/2014 | 2:46:43 PM
No, sorry, wrong - plug well and truly pulled...
Er... Looks like Micro$oft didn't read this website. They pulled the plug on all the XP installed Security Essentials boxes I am running. Maybe they were kidding this website?
Gary_EL
50%
50%
Gary_EL,
User Rank: Apprentice
1/17/2014 | 12:23:51 AM
Smart move on Microsoft's Part
The timing here is absolutely amazing. I need to buy a backup machine, and, not wanting to spend serious money on a decent Windows 7 box, I was going to buy a Chrombook. This would have been a huge move for me, because aside from some dabbling with Ubuntu, I'm a pure Microsoft user. Now, I don't have to venture from the comfy home I've been warm and happy in since 1985. So, no Chromebook, but a $60 Pentium IV from Craigslist, and one relieved customer will stay exclusively onboard with Bill and the Redmond crew.
global-george
50%
50%
global-george,
User Rank: Apprentice
1/16/2014 | 4:32:31 PM
Re: I have too many XP machines to upgrade them all
New hardware is not required for Robolinux, that in itself saved us a fortune. However as the more aging pc's break, yes we will then purchase new machines on an as needed basis. As far as mobile is concerned Linux is inherently very strong in this space so no issue there.
global-george
100%
0%
global-george,
User Rank: Apprentice
1/16/2014 | 4:21:46 PM
Re: I have too many XP machines to upgrade them all
$3700? You apparently are not in IT or your math skills are lacking. For starters the XP apps won't run on 8 and Windows 7 requires New hardware.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
1/16/2014 | 4:20:59 PM
Re: I have too many XP machines to upgrade them all
Are you planning to refresh the hardware? Does Robolinix support mobile platforms? This is all very interesting to me! Thanks!
global-george
100%
0%
global-george,
User Rank: Apprentice
1/16/2014 | 4:15:01 PM
Re: I have too many XP machines to upgrade them all
Our internal IT folks are busy porting all of our custom applications to either SAAS or native Linux applications. We did the math and the savings are significant. So yes we plan to keep Robolinux which our Users really love as it is much faster and is way more secure than any Windows OS, especially Windows 7.
GAProgrammer
0%
100%
GAProgrammer,
User Rank: Guru
1/16/2014 | 4:00:13 PM
Re: I have too many XP machines to upgrade them all
Really? You have 26 (or more) employees yet can't afford $3700 in software and maybe the same amount in consulting fees? I understand that no one likes to spend money, but $7500 in upgrade costs for someone with that many computers seems more than reasonable. By the way, that is retail pricing, not even OEM pricing.

I hear people whining about Microsoft and their costs, but it all seems reasonable to me. To be on XP still, especially as a small business, just sounds like poor planning to me. While I disagree with your lack of enthusiam for Windows 8, there is no good business reason not to move to Windows 7.
Marilyn Cohodas
100%
0%
Marilyn Cohodas,
User Rank: Strategist
1/16/2014 | 3:58:04 PM
Re: I have too many XP machines to upgrade them all
That's an interesting approach. Has the experience sold you on Robolinux OS going forward. Or do you see your organization migrating back to Windows for you next client refresh. What's your strategy?
global-george
50%
50%
global-george,
User Rank: Apprentice
1/16/2014 | 3:10:15 PM
I have too many XP machines to upgrade them all
Since my office has 26 Windows XP machines I cannot afford to upgrade all of them to Windows 7 and no one here likesWindows 8, so I hired an IT Consultant who recommended a very polished Linux operating system called Robolinux which runs XP or 7, inside it, making our XP machines completely immune to all viruses and malware, requiring absolutely no updates or anti virus or anti malware software purchases. The Robolinux OS was a 7 minute install per PC. Also extremely easy for our users to operate it. It saved our company thousands of dollars. At first I was skeptical but my local IT Guru explained to me how the advanced Robolinux VM technology operates and it made perfect sense to me. So far after 6 months not one of our 26 Windows XP boxes have been infected by any viruses or malware. I hope this helps others who just can't afford to upgrade.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
DevOps’ Impact on Application Security
DevOps’ Impact on Application Security
Managing the interdependency between software and infrastructure is a thorny challenge. Often, it’s a “developers are from Mars, systems engineers are from Venus” situation.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4807
Published: 2014-11-22
Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 9.3.0 before FP8 allows remote authenticated users to cause a denial of service (CPU consumption) via a '\0' character.

CVE-2014-6183
Published: 2014-11-22
IBM Security Network Protection 5.1 before 5.1.0.0 FP13, 5.1.1 before 5.1.1.0 FP8, 5.1.2 before 5.1.2.0 FP9, 5.1.2.1 before FP5, 5.2 before 5.2.0.0 FP5, and 5.3 before 5.3.0.0 FP1 on XGS devices allows remote authenticated users to execute arbitrary commands via unspecified vectors.

CVE-2014-8626
Published: 2014-11-22
Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone field in a date, leading to improper XML-RPC encoding...

CVE-2014-8710
Published: 2014-11-22
The decompress_sigcomp_message function in epan/sigcomp-udvm.c in the SigComp UDVM dissector in Wireshark 1.10.x before 1.10.11 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet.

CVE-2014-8711
Published: 2014-11-22
Multiple integer overflows in epan/dissectors/packet-amqp.c in the AMQP dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2 allow remote attackers to cause a denial of service (application crash) via a crafted amqp_0_10 PDU in a packet.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?