Slashdot Mirror


Another Critical Microsoft Hole

gmuslera writes "Not was enough that recent vulnerability in IE that can run any program in an unpatched windows system. Now there is another related to an ActiveX control that can make IE and IIS to run any code in the system. The Microsoft solution? kill the related ActiveX control and replace it with a safe one. The Microsoft problem? As this control is Microsoft signed, any site can require it, upload it and replace the "good" one with the vulnerable one. The final recomendation from Microsoft? Don't trust/run ActiveX controls signed by Microsoft." Gimble points to the appropriate locations on Microsoft's website: "Another buffer overrun (that allows arbitrary code to be run) has been admitted to by MS, and it affects IIS and IE on clients (but not on XP), and they have a patch available here Security Hotfix for Q329414. The kicker is that a patched system can be rendered vulnerable again by a hostile web site or HTML email. The 'solution' from MS in Microsoft Security Bulletin MS02-065 recommends that you remove MS from the list of Trusted Publishers."

7 of 597 comments (clear)

  1. A Toast!! by Anonymous Coward · · Score: -1, Offtopic

    ...to the HOST who BOASTS the MOST first POSTS!

  2. Re:why? by SnAzBaZ · · Score: -1, Offtopic

    I am also sick of it.

  3. The wonderful world of gay computing by Anonymous Coward · · Score: -1, Offtopic
    As everybody knows, geeks - regardless of whether they are math, comp or physics geeks - tend to live sexually frustrated lives because of their lack of social skills and personal hygiene.

    As is well known from other human subcultures such as strict religious communities, where even normal behaviour like masturbation is controlled and punished, the lack of sex is channeled into an obsessive behaviour. Some geeks like to play with differential geometry, some of the code free software and some of them waste time simulating something on the computer.

    Yet, one thing sets them apart from the religious subgroup.

    All of them are gay.

    Yes. Regardless of the outward appearances, the lack of female appreciation eventually drives these unfortunates into seeking sexual release amongst their fellow geeks in a fashion not unlike that obseved in prisons.

    During years of painstaking research, following subsubgroups have been observed within the gay computing community (GCC).

    Apple users ... these are perhaps the happiest of all the computer users. Financially secure and not afraid to spend their money. They thrive on colourful, creatively designed computers and user friendly software. While some of them still deny their gay identity, most of them are at least aware of their true preferences.

    PC users ... the majority of computer users are in this category. Conservative, price conscious and typically afraid to stand out of the crowd under any circumstances. Hence, boring beige computer cases, commodity hardware and free software. As far as their gay identity, they truly are in denial and often resort to bashing Apple users as gays.

    Amiga, PPC, Alpha ... this strange group forms the fringe element of computer users. As they are a minory within a minority they tend to be highly reclusive, eccentric even hostile towards the other computer users. High gayness factor, but unfortunately in a strongly suppressed form.

  4. Re:dammit by Anonymous Coward · · Score: -1, Offtopic

    Mod this up... it's hilarious!!... Although have been smokin' the wacky tabcy... i need timtams... what was i saying?

  5. Re:Not true... by kalidasa · · Score: 1, Offtopic

    ...you could run it on Solaris too.

    What, does the Solaris Ocean do something to prevent MS operating systems from sucking? Man, that's wild.

    (Gratuitous Lem joke)

  6. Re:WTF ? by Violet+Null · · Score: 0, Offtopic

    The OP is +5 insightful, and the parent is 1, unmoderated? Mod parent up.

  7. Re:I realize most /.ers use IE, but... by Dog+and+Pony · · Score: 2, Offtopic

    Because Opera is not evil, just Norwegian? ;-)

    I just noticed that Opera 7 is out in a Beta. I think I'll go give it a spin right away...