Re: ActiveX

From: Dave Killion (dave.killion_at_gmail.com)
Date: 08/29/05

  • Next message: Wil.Allsopp_at_ins.com: "RE: ActiveX"
    Date: Mon, 29 Aug 2005 10:15:01 -0700
    To: Andres Molinetti <andymolinetti@hotmail.com>
    
    

    Here's an ActiveX control vulnerability:

    http://secunia.com/advisories/13578/
    http://securitytracker.com/alerts/2004/Dec/1012626.html

    (Both links refer to the same issue)

    Basically, a malicious website using an ActiveX control created by
    Windows Media Player can, without any warning, verify the existence of
    arbitrary files on a target machine, and in the case of WMA files,
    change their contents.

    No pop-ups, no 'ActiveX Installation' warnings - it just does it.

    This is a realitively benign example - there are others that are much
    more nasty - but this should suffice for a customer demonstration.

    Enjoy,

    -- 
    Dave Killion, CISSP
    Contributing Author, Configuring NetScreen Firewalls
    

  • Next message: Wil.Allsopp_at_ins.com: "RE: ActiveX"

    Relevant Pages

    • Help for ActiveX (2)
      ... I was very busy in the last days with other business problems, ... ready to solve the problem about ActiveX control and the security warning on ... correctly and import ed the certificate in the Trusted Root Certification ... PC I have already the explorer warning. ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: VBScript causes ActiveX warning
      ... What is your VBScript doing? ... If it's using an ActiveX control, ... warning can't be disabled. ... "Rob Collins" wrote in message ...
      (microsoft.public.security)
    • Failure in On Click event
      ... Find & Preview Report. ... there was below warning after I click the ... I do not have any OLE server and unsure if I have used any ActiveX Control. ...
      (microsoft.public.access.formscoding)
    • Re: ActiveX error message
      ... to run a troubleshooter in Help and Support Center ... 'An ActiveX control on this page is not safe. ... The warning is just under the tool menu, ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: Outlook 2002 SP3 ActiveX warning
      ... I started to paste the paragraph line by line until the warning was ... the activeX control is that is causing the warning in the first place. ... > Greets, Helmut Obertanner ...
      (microsoft.public.outlook.interop)