Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
ActiveX security faces storm before calm
Robert Lemos, SecurityFocus 2006-07-31

HD Moore is at it again.

Comments Mode:
ActiveX security faces storm before calm 2006-07-31
Anonymous
What does IE 7 mean for SSL VPN solutions that rely on ActiveX for security services applets....

[ more ]  [ reply ]
ActiveX Opt-In Overrated 2006-07-31
Matthew Murphy
There's already one system designed to forcibly "opt-out" users from dangerous ActiveX code -- it's called the IObjectSafety interface. It's used to indicate that code is or is not safe for initialization and scripting in a browser environment.

This posed a few problems:

First, some controls...

[ more ]  [ reply ]
ActiveX security faces storm before calm 2006-08-01
Anonymous
And dropping IE and going Firefox is not an option because...?

...

[ more ]  [ reply ]
Micro$oft, microsecurity 2006-08-01
assurbanipal
What if there was no HD Moore (and other independent researchers) tinkering with Micro$oft crappy software? We'd have to stick with the smelly, buggy software forever!

It's unbelievable how such a giant corporation NEGLECTS any real action to achieve security (I'm not talking about marketing fluff,...

[ more ]  [ reply ]
ActiveX security faces storm before calm 2006-08-01
Anonymous (2 replies)
IE WHY??

If any of my employees used Internet Explorer I would terminate them immediately (luckily I don't have any). If corporate America had any courage they would lauch a $500 billion class action lawsuit against Microsoft for intentionally allowing criminal access to our computers.

...

[ more ]  [ reply ]
Re: ActiveX security faces storm before calm 2006-08-01
Anonymous
The class action lawsuit would go nowhere. Read the EULA! Microsoft specifically disclaims responsibility for damages a user may incur. Accepting the terms means YOU willingly assume the risk.

Don't like it? Don't use their software. You may have problems though using anyone's software since...

[ more ]  [ reply ]
Re: ActiveX security faces storm before calm 2006-08-09
Anonymous
you seem very wise. You should start the lawsuit - people are bound to listen to you ;-)...

[ more ]  [ reply ]
ActiveX security faces storm before calm 2006-08-03
Juha-Matti Laurio
Switching to Beta releases of Internet Explorer 7 is not a realistic alternative in most company environments, as we know very well.

You can always apply a list of Trusted Web Sites to Internet Explorer and use MSIE only on these sites, very often ActiveX based sites....

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus