Skip to content
View in the app

A better way to browse. Learn more.

MSFN

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Is anyone aware of this vulnerability on Windows XP? (CVE-2019-1489)

Featured Replies

This CVE indicates that the attacker would connect into the computer using RDP and then run a program.

How to handle this would depend if you are using RDP or not. If not, you can disable it and while the exploit would still exist, the ability to use it would not.

  • Author

 Tripredacus Thanks for helping me and how to deal with it, because I use RDP too, will do as you suggested by turning off RDP.

If you do have to use RDP then there are some mitigations. First you have to know that this would be something that would happen in an attack on a high value target. Because the attacker would need to know this information:
- the IP or identifier of your computer
- the username and password

If the computer is not connected directly to the internet or in DMZ, it is less likely to be found. What you can do if you want to use RDP (may need XP Pro or use other methods to do this on Home) :

- do not have Guest account enabled. If you are hosting network shares, you'll need to set an account for authentication.
- create a new user group, this group should not have admin access but does have RDP access.
- create a new user that is not admin, add it to that group.
- set RDP to only allow logins from that user group.

There are other ways to handle it.

  • Author
10 minutes ago, Tripredacus said:

If you do have to use RDP then there are some mitigations. First you have to know that this would be something that would happen in an attack on a high value target. Because the attacker would need to know this information:
- the IP or identifier of your computer
- the username and password

If the computer is not connected directly to the internet or in DMZ, it is less likely to be found. What you can do if you want to use RDP (may need XP Pro or use other methods to do this on Home) :

- ไม่ได้เปิดใช้งานบัญชี Guest ไว้ ถ้าคุณกําลังโฮสต์เครือข่ายที่ใช้ร่วมกัน คุณจะต้องตั้งค่าบัญชีผู้ใช้สําหรับการรับรองความถูกต้อง
กลุ่มนี้ไม่ควรมีสิทธิ์การเข้าถึงระดับผู้ดูแลระบบ แต่มีการเข้าถึง RDP
- สร้างผู้ใช้ใหม่ที่ไม่ใช่ผู้ดูแลระบบ ให้เพิ่มผู้ใช้นั้นลงในกลุ่มนั้น
- ตั้งค่า RDP ให้อนุญาตเฉพาะล็อกอินจากกลุ่มผู้ใช้นั้นเท่านั้น

มีวิธีอื่นในการจัดการ

Thank you for helping me today.  I'm currently creating an account like you suggested. :worship:

  • 2 weeks later...

RDP, IE, WMP... no go. The first things to disable/cripple. IMHO.

Create an account or sign in to comment

Recently Browsing 0

  • No registered users viewing this page.

Account

Navigation

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.