The Haus

Thursday, November 21, 2002

Microsoft IE/IIS Vulnerabilities

There's a new problem that's been discovered with a Microsoft ActiveX control that allows anyone to run arbitrary code on any non-XP version of Windows. A fix is available here. The problem is that since the old control is signed by Microsoft, a website could knowingly or unknowingly give you the old, vulnerable version right back. The only solution? Remove Microsoft from your list of trusted publishers. Eeek.

This comes on the heels of another IE security hole that would allow someone to run arbitrary code on any Windows box. The really bad thing here is that Bugtraq posted working code showing how to exploit that bug to reformat someone's hard drive. Sheesh. That article has a link to a patch that may or may not completely fix that bug. Get patching! Thanks Slashdot.

J.t.Qbe comments: Speaking of Microsoft, there was an interesting article at The Register this morning: an internal Microsoft document about the (attempted) switch of Hotmail from FreeBSD to Win2K. Microsoft recognizes the benefits Unix fans have been touting for years, but of course can't publicly present them as benefits. Very interesting reading.

News for 11/21/2002

Recent Headlines

January 5, 2015: It Returns!
August 10, 2007: SCO SUCKS IT DOWN!
July 5, 2007: Slackware 12.0 Released
May 20, 2007: PhpBB 3.0 RC 1 Released
February 2, 2007: DOOM3 1.31 Patch

January 27, 2007: Join the World Community Grid
January 17, 2007: Flash Player 9 for Linux
December 30, 2006: Darkness over Daggerford 1.2
December 19, 2006: Pocket Tunes 4.0 Released
December 9, 2006: WRT54G 1.01.1 Firmware OK with Linux/Mac

All original information on this website is copyright © TheHaus.Net, 1999-2005. The use of original images, text, and/or code from this website without expressed written consent is prohibited. The authors of this site cannot be held responsible for any damage, real or imagined, which comes from the use of information presented on this site. All trademarks used are the properties of their respective owners. This site is not to be used as a floatation device (but if you try, I want a video tape of it).