- TalkBack 11 of 24:
- Next »
- « Previous
- Thread View
- Flat View
- Absolute nonsense.
-
Linux is just as susceptible to worms, virus and trojans.
Only operating systems that incorporate the conmpletely unsandboxed ActiveX are going to be as vulnerable. And for now that's only OSes from Microsoft. ActiveX is the result of a boneheaded decision made by Microsoft back in the early 90's to place customer security in the back seat in favor of usurping the Web through adding irresistible bells and whistles to Windows and Internet Explorer. Despite the warnings of numerous security experts down the years and wave after wave of ActiveX-enabled attacks, the company has refused to do what is required to completely fix the problem: remove it.
H D Moore, founder of the Metasploit malware toolkit, created a "fluffer" tool for locating potentially exploitable weaknesses in ActiveX controls:
http://metasploit.com/users/hdm/tools/axman/
A recent article about Mr. Moore has this frightening quote:
"Moore claims that, while he found more than 100 vulnerabilities in standard ActiveX components, almost another 100 exist in the ActiveX components installed by popular applications, such as Microsoft Office. While most of the issues discovered by Moore, who is also the founder of the Metasploit Project, are simple denial-of-service problems, about a dozen are remotely exploitable issues in ActiveX controls for Internet Explorer, he said.
"There are a couple of classes that have so many vulnerabilities that I had to black list the entire class," Moore said."
Although this particular worm doesn't appear to need ActiveX help on its initial install, reading F-Secure's description, we find:
The worm can modify Active Desktop files in order to launch another copy of itself named 'WinZip_Tmp.exe' using the ActiveX control.
First ActiveX-enabled exploit to appear in the wild: 1993
Latest ActiveX-enable exploit in the wild: out now and currently unpatched. - Posted by: UserLand Posted on: 11/09/06 You are currently: a Guest | Members login | Terms of Use
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
What do you think?
SponsoredWhite Papers, Webcasts, and Downloads
- Why Isn't Server Virtualization Saving Us More? A Few Small Changes May Dramatically Increase Your Efficiency VMware Companies have rapidly adopted server virtualization over the past few ... Download Now
- Five Steps to Determine When to Virtualize YourServers VMware Server virtualization isn't just for big companies. Entry-level ... Download Now
- VMware Infrastructure: A Guide to Bottom-Line Benefits VMware Frustrated by the costs of maintain ever larger data centers?or building ... Download Now
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- Keep Up With The Latest In Document Management with The DocuMentor.
-
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
- Learn more >>
- Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
-
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.

- Learn more about the free, six-month trial offer >>
- New Online Dashboard for IT Leaders
-
Read about top issues IT decision-makers face every day, plus get cost-effective solutions to real-life IT problems.
- Learn more >>
- The best support in the Linux business
-
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.

- Learn more >>
Meet Doc
-
Here to help you with your Document Management Needs
- Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
- To learn more about this mysterious figure check out his blog on ZDNet. You’ll be glad you did.
-
Produced by
ZDNet and







