| Compaq Computer said ActiveX programs that ship with its popular desktop and
notebook Presario lines contain a flaw which could allow hackers to
over-write files on users' machines if they visit a specially-constructed
Web page or read a booby-trapped HTML e-mail.
MS Access 2000 Command Buttons:: creat a command button to open and activex control such as calendar to enter a IT Hardware and Software Purchasing Policy. Your IT Budget is tight. http://techrepublic.com.com/5208-6230-0.html?forumID=52&threadID=108303HOME |
In an advisory issued late yesterday, Compaq said it includes the ActiveX
controls on Presarios to perform customer support tasks. The company
classified the threat as a denial of service vulnerability.
October 1-December 31 Additions to Bob Jensens Bookmarks File:: It will continue to be the human-machine civilization taking the next step in evolution. HEAT milk, water, and 1/4 cup margarine until hot to touch, 125F-130F. http://www.trinity.edu/rjensen/book99q4.htmHOME | the Onda by Antonio Rodriguez:: or even 5 to when Mac OS X first shipped, and think about why today the This is the main reason why taking any old desktop application and webifying it http://theonda.org/articles/2007HOME |
The system bugs were first publicized two years ago by Richard Smith, chief
technology officer for the Privacy Foundation, in
a message to
the NTBugTraq mailing list.
Usage Statistics for spcug.org - October 2004 - Search String:: folder icons 2 0.02% black taskbar 2 0.02% block website group policy 2 0.02 .com viruses 1 0.01% accept unsigned active x control 1 0.01% access 2003 book http://www.spcug.org/webstats/search_200410.htmlHOME | Reality News:: Active X. And more features, time permitting. Beyond Rhapsody 1.0 taking current MacOS applications and turning them into MacOS 10.x applications. http://www.appleinsider.com/archives/051198/news.shtmlHOME |
Earlier this year, Smith sent the computer manufacturer a note saying that
his new Compaq Presario 1700 series laptop had come shipped with about a
dozen pre-installed ActiveX controls which were marked "safe for scripting."
"Many of these controls," he wrote were "hardly safe."
In fact, Smith argues that the Compaq Presario and operating systems,
including Windows 98 and Windows Me, contain Active X methods for writing
files to hard drives with controls that can easily be tampered with from
HTML e-mail messages, Web pages, or rogue code.
all Notebook and Laptop FAQ - dslreports.com:: desktop for almost all of their needs, while taking up a fraction of the space. DSLR thread: Acer puts Active X hole on laptops http://www.dslreports.com/faq/note/allHOME | Community Content | The Buckminster Fuller Institute:: thats probably because I dont have ActiveX installed, as I used Virtual PC for There is always plenty of water somewhere on the planet. http://www.bfi.org/our_programs/bfi_community?page=4HOME |
By definition, an Active X control can be automatically downloaded and
executed by a Web browser. Programmers can develop ActiveX controls in a
variety of languages, including C, C++, Visual Basic and Java.
"They ship something like eleven ActiveX controls that can write to the hard
drive and over-write files," Smith said in an interview with InternetNews.com.
"So the term 'denial of service' is kind of a misnomer. It can destroy data
or the operating system. So I think this is
a bigger deal."
For its part, a Compaq spokesperson said the company issued a patch to about
2 million users through a Compaq services connection.
The spokesperson also added that all Presario computers contained ActiveX
controls. And with so many users at risk, Compaq has started a security
mailing list service to keep users up-to-date. So far, 260,000 people have
signed up.
So while Compaq is certainly taking an active interest in the problem,
perhaps most startling is Smith's contention that PC vendors continue to
sell computers that can be tweaked by hackers.
"PC vendors don't seem to understand ActiveX security and have shipped
software preinstalled on computers that create backdoors that open people's
machines wide open to hackers," he said.
What's disturbing to Smith, and countless other users, is that ActiveX
controls have full access to the Windows operating system. To control this
risk, Microsoft developed a registration system so that browsers can
identify and authenticate an ActiveX control before downloading it.
Compaq says it has no plans to ask vendors to stop shipping Presario
computers.
*Brian McWilliams of InternetNewsRadio also
contributed to this story.
Hackers Succeed in Breaching Shopping Cart Software
Globbing Function Leaves Some FTP Servers Vulnerable |