# XP exploit found

**URL:** <https://boards.straightdope.com/t/xp-exploit-found/127819>\
**Category:** Factual Questions\
**Created:** [September 10, 2002, 5:27pm UTC](https://boards.straightdope.com/t/xp-exploit-found/127819 "2002-09-10T17:27:15Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![cykrider](https://avatars.discourse-cdn.com/v4/letter/c/f19dbf/32.png) [@cykrider](https://boards.straightdope.com/u/cykrider)\
**Post date:** [September 10, 2002, 5:27pm UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/1 "2002-09-10T17:27:15Z")

</div>

I heard of a big XP exploit that micro$oft knew about for about 11 weeks. Although I don’t know the how it works, apparently merely clicking on a link can wipe out whole directories. Supposedly you only need to d/l Service Pack 1 or search and delete the file: uplddrvinfo.htm in order to protect yourself from it. If anyone has any more information on this, that would be great. Is merely deleting the file get the job done or do you really need to get service pack 1 (or get a linux box 🙂 )

---

<div class="post-metadata">

**Author:** ![Padeye](https://avatars.discourse-cdn.com/v4/letter/p/a9a28c/32.png) [@Padeye](https://boards.straightdope.com/u/Padeye)\
**Post date:** [September 10, 2002, 5:48pm UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/2 "2002-09-10T17:48:20Z")

</div>

This is not news for MS operating systems. IMHO it’s a direct consequence of not having open source. At any rate I wasn’t aware service pack 1 was out yet though I did see an article on MSNBC that said part of the pack will be to fulfill court ordered changes.

---

<div class="post-metadata">

**Author:** ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)\
**Post date:** [September 10, 2002, 6:13pm UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/3 "2002-09-10T18:13:39Z")

</div>

I have not used XP but unless supported by some credible evidence this has all the marks of a hoax. How can deleting an HTML file do anything of the sort?

---

<div class="post-metadata">

**Author:** ![kanicbird](https://avatars.discourse-cdn.com/v4/letter/k/5f8ce5/32.png) [@kanicbird](https://boards.straightdope.com/u/kanicbird)\
**Post date:** [September 10, 2002, 6:46pm UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/4 "2002-09-10T18:46:58Z")

</div>

It sound like the hoax that causeed many people to delete a semicritical file for windows that had to do with long file names.

Service pack one has more to do with software copying prevention then security of XP. It contains a function to repair any crack to XP activation, Prevent windows XP edition that has no activation required, that has leaked into file swapping networks, from accepting furture updates, Also had the DoJ’s mandate that will let the user select ‘non- MS middleware’ products such as Netscape instead of IE as the default.

---

<div class="post-metadata">

**Author:** ![mythil](https://avatars.discourse-cdn.com/v4/letter/m/c4cdca/32.png) [@mythil](https://boards.straightdope.com/u/mythil)\
**Post date:** [September 10, 2002, 7:35pm UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/5 "2002-09-10T19:35:00Z")

</div>

This is not a Hoax. It has been on bug track lists ofr about 3 weeks now, and the TV show The Screensavers on TechTV did a demo of how it can wipe files on your computer. The fix is in SP1 or you can delete/rename the file as suggested above to stop this. For more information goto [www.thescreensavers.com](http://www.thescreensavers.com) click on Mondays show links and scroll down to the boot camp section.

---

<div class="post-metadata">

**Author:** ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)\
**Post date:** [September 10, 2002, 7:57pm UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/6 "2002-09-10T19:57:52Z")

</div>

[http://grc.com/default.htm](http://grc.com/default.htm) says to install SP1 but does not mention deleting the HTM file as a solution. Can anyone show any credible support for this solution or explain to me how deleting an HTM file would do anything? The idea that MS would issue a 30 MB patch and say it does the same thing as deleting a single file HTM file sounds very difficult to swallow. Can anybody who has XP tell us what this uplddrvinfo.htm file contains?

---

<div class="post-metadata">

**Author:** ![kanicbird](https://avatars.discourse-cdn.com/v4/letter/k/5f8ce5/32.png) [@kanicbird](https://boards.straightdope.com/u/kanicbird)\
**Post date:** [September 10, 2002, 8:30pm UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/7 "2002-09-10T20:30:11Z")

</div>

Doing a search for uplddrvinfo.htm in google turned up nothing in english - this whole thing looks suspicious. Cnet says nothig of such a security flaw - here’s their review

> **[Services and Software](https://www.cnet.com/tech/services-and-software/?tag=rev-rev)**
>
> All the news and tips you need to get the most out of the services, apps and software you use every day.

---

<div class="post-metadata">

**Author:** ![kanicbird](https://avatars.discourse-cdn.com/v4/letter/k/5f8ce5/32.png) [@kanicbird](https://boards.straightdope.com/u/kanicbird)\
**Post date:** [September 10, 2002, 8:38pm UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/8 "2002-09-10T20:38:17Z")

</div>

From the above site

> [@](#):
>
> If, for whatever reason, you don’t or can’t download the service pack, there is an alternative. There’s a file you can rename or delete to fix the security hole. Here are the steps:
> 
> Perform a search for a file on your C drive called “uplddrvinfo.htm.”

---

<div class="post-metadata">

**Author:** ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)\
**Post date:** [September 10, 2002, 9:30pm UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/9 "2002-09-10T21:30:48Z")

</div>

\>\> the service pack weighs in at a whopping 133MB

Yikes! Bloatware alert! Man, am I happy I did not switch to XP.

I am still curious as to what uplddrvinfo.htm contains and does. The name sounds like “upload driver info” but I am surprised the OS would use an HTML file for system use. I did a search and it seems the process is that the malicious link causes the OS to launch a program which is used when some driver cannot be found. The program sends to MS the hardware and driver configuration of the machine which is probably stored in that HTM file. If you terminate the program you are safe. I guess deliting that HTM file has the same effect.

---

<div class="post-metadata">

**Author:** ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)\
**Post date:** [September 10, 2002, 9:33pm UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/10 "2002-09-10T21:33:09Z")

</div>

I did a search for uplddrvinfo.htm but the only page I could find with a good explanation of this is in Spanish:  
[http://www.vsantivirus.com/xp-files-del.htm](http://www.vsantivirus.com/xp-files-del.htm)

---

<div class="post-metadata">

**Author:** ![Crusoe](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@Crusoe](https://boards.straightdope.com/u/Crusoe)\
**Post date:** [September 10, 2002, 9:35pm UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/11 "2002-09-10T21:35:41Z")

</div>

A badly-translated Google page I saw suggested that it is involve in the XP ‘Help and Support Centre’ and has the ability to delete local files. Because it is not subject to normal browser security settings there is a risk that a malicious piece of HTML could achieve the same results:

(excuse the translation)

> [@](#):
>
> "The successor of the on-line assistance, the Tool “assistance and support center”, in Windows XP lets itself be brought with a line HTML for deleting local files. Debt to it are special treatment routines for HCL minutes, which Microsoft for the on-line assistance created and built into XP. If a surfer loads a particularly prepared web page or if it clicks on an appropriate left, a window with “assistance for hardware devices” appears. If it closes this window, the “assistance and support center” deletes in left coded local files. The HTML code does not have necessarily over the Browser at the PC to arrive, but could also in a HTML Mail to be.
> 
> The usual safeguard mechanisms of a Browser do not seize with this kind of attack, because Microsoft does not let the assistance and support center actually run with the safety attitudes selected for the Browser. The URL coded in the HTML code refers to a locally stored HTML side (under C:\WINDOWS\PCHEALTH\HELPCTR\System\DFS ) with the name uplddrvinfo.htm . It serves to convey at Microsoft information if one does not get equipment partout for running. Exactly this side within the assistance contains also Javascript code, which can delete local files. By call of the side with appropriate parameters almost arbitrary files on a XP system – however only those, which the announced user also could delete, can be deleted. In addition the name of the files must admits to be; the function does not destroy whole listings."

---

<div class="post-metadata">

**Author:** ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)\
**Post date:** [September 10, 2002, 9:41pm UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/12 "2002-09-10T21:41:25Z")

</div>

I forgot to say, the malicious link will start that program to send to MS your computer’s config and a screen pops up – if you terminate it from the task manager at this point you are safe. Deleting the HTM file has the same effect as the program cannot continue. If the program is allowed to continue then a list of files contained whose names are in the malicious link will be deleted.

It seems only system files would be vulnerable as their names and paths are standard. of maybe wildcards are valid. In any case, it seems the service patch closes a lot of other holes so that would be the way to go.

---

<div class="post-metadata">

**Author:** ![AZCowboy](https://avatars.discourse-cdn.com/v4/letter/a/97f17d/32.png) [@AZCowboy](https://boards.straightdope.com/u/AZCowboy)\
**Post date:** [September 10, 2002, 11:16pm UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/13 "2002-09-10T23:16:58Z")

</div>

[Here](http://archives.neohapsis.com/archives/bugtraq/2002-08/0129.html) are the gory details in english (eh, sorry, techno-english). Only MS could come up with such a gaping security vulnerability in the “Help” capabilities.

If you read through it, notice how administrators can fix the problem by using the exploit themselves! Bloody great.

For those of you, like me, that find I must use Windows for various reasons, this should be a good example of why you should never load a MS operating system until AT LEAST the first service pack has come out.

---

<div class="post-metadata">

**Author:** ![DougC](https://avatars.discourse-cdn.com/v4/letter/d/7feea3/32.png) [@DougC](https://boards.straightdope.com/u/DougC)\
**Post date:** [September 11, 2002, 12:53am UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/14 "2002-09-11T00:53:27Z")

</div>

> [@](#):
>
> , -this should be a good example of why you should never load a MS operating system until AT LEAST the first service pack has come out…

- 
  - 
    - Um, no, you wait until the _last_ service pack comes out. Win98 works pretty good these days; Win2K does well also I’m told…  
~

---

<div class="post-metadata">

**Author:** ![Monstre](https://avatars.discourse-cdn.com/v4/letter/m/e274bd/32.png) [@Monstre](https://boards.straightdope.com/u/Monstre)\
**Post date:** [September 11, 2002, 5:29am UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/15 "2002-09-11T05:29:15Z")

</div>

> [@](#):
>
> The idea that MS would issue a 30 MB patch and say it does the same thing as deleting a single file HTM file sounds very difficult to swallow.

In general, the service packs contain many fixes for various things – not just a single fix for a single bug – so their sizes are often going to be large. Personally, I don’t think I would care to trust a new Micro$oft OS until at least service pack 5 or 6.

Example: Win NT 4.0 had a major hole exploited through their IIS software that wasn’t patched until service pack 6. If you were running the IIS server on NT 4.0 service pack 5 or less, somebody running the exploit could gain Administrator access to your network! (I don’t have a link, but I believe that the bugtraq site was one of the places I was found information about it when I was researching a SysAdmin course a few years ago).

Personally, I won’t be trying out XP for a while.

---

<div class="post-metadata">

**Author:** ![Monstre](https://avatars.discourse-cdn.com/v4/letter/m/e274bd/32.png) [@Monstre](https://boards.straightdope.com/u/Monstre)\
**Post date:** [September 11, 2002, 5:29am UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/16 "2002-09-11T05:29:15Z")

</div>

> [@](#):
>
> The idea that MS would issue a 30 MB patch and say it does the same thing as deleting a single file HTM file sounds very difficult to swallow.

In general, the service packs contain many fixes for various things – not just a single fix for a single bug – so their sizes are often going to be large. Personally, I don’t think I would care to trust a new Micro$oft OS until at least service pack 5 or 6.

Example: Win NT 4.0 had a major hole exploited through their IIS software that wasn’t patched until service pack 6. If you were running the IIS server on NT 4.0 service pack 5 or less, somebody running the exploit could gain Administrator access to your network! (I don’t have a link, but I believe that the bugtraq site was one of the places I was found information about it when I was researching it for a SysAdmin course a few years ago).

Personally, I won’t be trying out XP for a while.

---

<div class="post-metadata">

**Author:** ![Monstre](https://avatars.discourse-cdn.com/v4/letter/m/e274bd/32.png) [@Monstre](https://boards.straightdope.com/u/Monstre)\
**Post date:** [September 11, 2002, 5:32am UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/17 "2002-09-11T05:32:20Z")

</div>

Arggh! :::holding out hand to accept the slap on the wrist for the double post:::

Sorry… (stupid browser timeouts… :::grumble:::🙂😉

---

<div class="post-metadata">

**Author:** ![Alereon](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@Alereon](https://boards.straightdope.com/u/Alereon)\
**Post date:** [September 11, 2002, 1:03pm UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/18 "2002-09-11T13:03:05Z")

</div>

I’d just like to mention to those crying “bloat!” that 130MB isn’t very large for a service pack. Windows XP installed is over 1GB, and SP1 contains ALL fixes up to date combined in one file. I bet all windows update fixes to date probably total more than 100MB. A significant number of files are updated, and a lot of new functionality is added (most of it invisible, but it all requires code).

Windows XP Pro’s install packages total under 500MB, which is smaller than any OS I know of with a similar number of included applications. Most Linux distributions come on at least 2 CDs.

---

<div class="post-metadata">

**Author:** ![kanicbird](https://avatars.discourse-cdn.com/v4/letter/k/5f8ce5/32.png) [@kanicbird](https://boards.straightdope.com/u/kanicbird)\
**Post date:** [September 11, 2002, 1:24pm UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/19 "2002-09-11T13:24:15Z")

</div>

> [@](#):
>
> Windows XP Pro’s install packages total under 500MB

But after installing on a new HD WIN XP pro takes up about 1.5gb - much more then the linux versions I tried, much more then any other version of windows i’ve tried (3.1,3.11,95, 95rc2, 98, 98se, me, nt (not 2000)

---

<div class="post-metadata">

**Author:** ![tourbot](https://avatars.discourse-cdn.com/v4/letter/t/e95f7d/32.png) [@tourbot](https://boards.straightdope.com/u/tourbot)\
**Post date:** [September 13, 2002, 2:22am UTC](https://boards.straightdope.com/t/xp-exploit-found/127819/20 "2002-09-13T02:22:28Z")

</div>

> [@](#):
>
> \*Originally posted by FDISK \*  
> \*\*Windows XP Pro’s install packages total under 500MB, which is smaller than any OS I know of with a similar number of included applications. Most Linux distributions come on at least 2 CDs. \*\*

Hardly a fair comparison, when you consider that your average Linux distro includes a full office suite, multiple xwindow systems, multiple web browsers, games, multiple graphics and multimedia packages, several IDE’s and utilities for every major programming language (except, of course, VB), web server, ftp server, Samba server, MS windows emulation software.

Plus the source code for most of the above.

I’ll agree that 130MB isn’t terribly huge for a service pack these days… for a server OS. For home users on dial-up, that has to be a nightmare. The OS itself, however, definitely qualifies as bloatware, for the simple fact that there is no way not to install many features that I would never want, especially in a business setting. (MSN messenger comes to mind.)
