Re: OCX and Digital Certificates question ( Problems with PKCS7 after Q328145 in Win2K)

From: David Cross [MS] (dcross@online.microsoft.com)
Date: 09/29/02


From: "David Cross [MS]" <dcross@online.microsoft.com>
Date: Sun, 29 Sep 2002 08:52:40 -0700


This is correct.

--
David B. Cross [MS]
--
This posting is provided "AS IS" with no warranties, and confers no rights.
http://support.microsoft.com
"Michel Gallant (MVP)" <neutron@istar.ca> wrote in message
news:3D9716AF.71148976@istar.ca...
> Alex and Mauricio,
>
> The related security patch for CEnroll (MS02-048) fixes some security
issues associated
> with being able to script that control from a web page context. You appear
to
> have that installed (version 5,131,3659,0)
> Details at:
>
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/
bulletin/MS02-048.asp
>
> So, if you are scripting from html, most methods will not work now ..
better ActiveX security :-)
>
> However, I have verified that the new verion of xenroll.dll works properly
> from trusted standalone wsh scripts, like:
>     http://home.iSTAR.ca/~neutron/wsh/capicom/pvkcerts/PVKCertsWMI.vbs
> which uses oXenroll.enumContainers().  This method, which used to work
from
> scripted html,  now fails from html after applying the patch above.
>
>  - Michel Gallant   MVP Security
>
> "Alex K. Angelopoulos (MVP)" wrote:
>
> > Mauricio,
> >
> > Does the same thing happen if you use the following code instead of an
object
> > tag?
> >
> > Set CEnroll = CreateObject("CEnroll.CEnroll")
> > CEnroll.installPKCS7(Str)
> >
> > There do appear to be some changes in how this works.  I'm including the
main
> > security groups in this response since they may have a good idea of what
is
> > actually happening here.
> >
> > In news:9e7801c2665d$ef5bfcd0$36ef2ecf@tkmsftngxa12,
> > Mauricio Reveco typed:
> > > I install in my win2k the Q328145 security update,
> > > described in Microsoft Security Bulletin MS02-
> > > 050 "Certificate Validation Flaw Could Enable Identity
> > > Spoofing (Q328145)"
> > >
> > > After the installation the next code didn't work anymore
> > > _______________________________________
> > > <OBJECT classid="clsid:43F8F289-7A20-11D0-8F06-
> > > 00C04FC295E1"  codebase="xenroll.dll#Version=5,131,2146,1"
> > > id="control"></OBJECT>
> > > <script language="vbscript">
> > > control.installPKCS7 <String parameter>
> > > </script>
> > > _____________________________________________________
> > > the script throw an error message about nonexistent
> > > method called "installPKCS".
> > >
> > > I replace the <OBJECT> Tag by the next sentence:
> > > _________________________________________________
> > > <OBJECT classid="clsid:5B9169C0-DB65-42AA-A38A-
> > > 0726846AAEB3"  codebase="xenroll.dll#Version=5,131,3659,0"
> > > id="control"></OBJECT>
> > > _________________________________________________
> > >
> > > but it didn't work, I get the Class ID and Version from
> > > the new  xenroll.dll installed in my Windows/system32
> > > directory.
> > >
> > > Can you help with this?
> > >
> > > Thanks!
> >
> > --
> > Please respond in the newsgroup so everyone may benefit.
> >  http://dev.remotenetworktechnology.com
> >  ----------
> >  Subscribe to Microsoft's Security Bulletins:
> >  http://www.microsoft.com/technet/security/bulletin/notify.asp
>


Relevant Pages

  • Re: OCX and Digital Certificates question ( Problems with PKCS7 after Q328145 in Win2K)
    ... Alex and Mauricio, ... The related security patch for CEnroll fixes some security issues associated ... with being able to script that control from a web page context. ...
    (microsoft.public.security)
  • SUMMARY WAS: OT? Philosophical Question on SA responsibilities
    ... helpful for managers interested in hiring new administrators. ... Would you go thru the 14,600 messages in root and admin ... If I was a new SA I would if encountering a security hole, ... I can see some use for the passwd -s part of the crontab script, ...
    (SunManagers)
  • Re: Clarification-Win2k Netstat sockets interpretation
    ... snip.. ... Before I could manually download every security upate and servicepack from MS.com but now...they send you a bit of Cop-code that fails to run unless ALL defences are down ... Are you sure the script from ntsvcfg is benign in addition to being useful? ... You are absolutely correct there HAL, er ah, Sebastian. ...
    (alt.computer.security)
  • [NT] Flaw in Windows Script Engine Could Allow Code Execution
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The Windows Script Engine provides Windows operating systems with the ... blocked by Outlook Express 6.0 and Outlook 2002 in their default ...
    (Securiteam)
  • Re: BUG with RES/SCRIPT/XP-SP2
    ... I consider JavaScript (known to security people as JavaVirus) as one of the Really Top ... to have a bad script cause damage to my machine. ... This security feature is called the "Local Machine Zone Lockdown". ... Tags, and the CDHtmlDialog class in this forum, and got no response. ...
    (microsoft.public.vc.mfc)