Quantcast
PCWorld.com is upgrading some back-end systems. Some site features, such as user registration, may be temporarily unavailable.

Blogs

    Bugs and Fixes

  • Contributing Editor Stuart J. Johnston advises you on how to fix the latest problems affecting your operating system, your browser, your other software, and your hardware.
  • Subscribe to this blog

Bugs & Fixes: Windows XP--XPect Hassles

Stuart J. Johnston

Thinking about getting Windows XP? Maybe you should wait until the dust settles. My e-mail in-box has been flooded with reports of bad "XPeriences" with the new operating system (see our news story for more details on XP's specific problems).

One serious snag: If you purchased a new PC with Windows XP preinstalled, and you subsequently reinstall, repair, or upgrade XP, Microsoft says that you may lose some important files and settings, including files you store in XP's Shared Documents folder. This bug does not affect users who upgrade to XP from another OS.

Microsoft issued a patch to fix the problem. Unfortunately, the fix cannot retrieve your lost data and settings--another good argument for frequent backups. Download the patch or go to Windows Update to grab XP's Critical Updates.

XP Security Threats

What else is wrong with Windows XP? This: It allows crackers to get access to your computer through the Universal Plug and Play feature.

Universal Plug and Play is an extension of the Plug and Play system that has been around for years. Plug and Play is meant to let you automatically use devices connected to your computer--like printers and scanners--without having to futz around with installation disks and device drivers. Universal Plug and Play allows your machine to find and use devices connected anywhere on a network.

However, a pair of flaws in the way that Universal Plug and Play "discovers" devices could enable a bad guy to crash your system, or even take complete control of it.

Devices compatible with Universal Plug and Play send out messages, called notifications, to tell XP that they're available for use. A hacker bent on sabotaging your PC could send you a message that is designed to look like a genuine notification. In reality, though, the false message would contain too much data, causing Universal Plug and Play to overflow. The malevolent hacker could then run code that circumvents XP's security protections.

A second hole also involves bogus Universal Plug and Play notifications sent over the Net, but is less serious. However, it could also affect Windows Me users if they have enabled Universal Plug and Play. (Windows 98 users would be affected only if they have installed the Windows XP version of Internet Connection Sharing.)

Legitimate Universal Plug and Play notifications sometimes contain the URL of a server where Windows can find information that lets the OS use the device. A fake notification could contain a URL that sends Windows too much information. Fortunately, this hack would only cause your computer to slow drastically or crash. Microsoft's patch takes care of both problems. Visit Windows Update or download the patch.

Stuart J. Johnston is a contributing editor for PC World.

Bugged?

Found a hardware or software bug? Tell us about it via e-mail at bugs@pcworld.com.

  • Recommend this story?
  • 0 Yes
    0 No
  • Great year-end deals for small business!
  • Get 24/7 live remote AT&T Tech Support 360* service along with select Lenovo* PCs (with Intel® Core™ 2 Duo processors and save up to 200!

    Learn more

  • HP EliteBook* 6930p Notebook with Intel® vPro™ technology and a free HP Basic Docking Station - $641 instant savings!

    Learn more

Dell Fast Track

Focus on Personal Productivitysponsored by Microsoft

  • Personal Finance 2.0 These free and fee-based Web services not only aggregate data from your online bank accounts, they give you tools for managing your money.
  • High-Tech Travel Tips Plenty of stories provide advice for elite mobile professionals. But what about you, the unproductive traveler?

People who read this also read:

Bugs and Fixes

All PC World Blogs

  • 15 Minutes to a Secure Business Get the Secure in 15 toolkit starting with the "15 Minutes Month-at-a-Glance" calendar. McAfee will send you additional tools and tricks to stay protected around the clock.
  • A Buyer's Guide to Data Protection Implementing data protection products and processes can be daunting. Make the right decisions by exploring what is available and what makes sense for your organization. Use this simple guide to evaluate different vendor offerings.

Sponsored Links