Re: OT: Gone from topic, now on security Re: For PGP Users-Likes and Dislikes of PGP
- From: Mike Amling <nospam@xxxxxxxxxx>
- Date: 14 Aug 2006 15:34:23 EDT
David Wagner wrote:
Joseph Ashwood wrote:Going back to the same earlier argument, is Sony's rootkit uninstaller an issue with Microsoft? It is not, but that is exactly what you are claiming (the uninstaller was an ActiveX control, so it is precisely within this).
I don't know enough about Sony's rootkit uninstaller.
Here are the assumptions I'll make about it:
- Sony's ActiveX control contained a vulnerability that could
be exploited;
Yes. The ActiveX control was capable of downloading and installing arbitrary software, and it did nothing to confirm that the arbitrary software it was downloading was from Sony or Sony's DRM vendor. It would happily retrieve from www.malwarez.ru.
- If you visited a malicious web page with MSIE, the malicious web
page could download Sony's ActiveX control, execute it, and exploit
its vulnerability;
Not quite. The (initial version of the) DRM/rootkit uninstaller required that the ActiveX control in question be downloaded and installed. And the uninstaller left the ActiveX control installed after it was done, where it could be invoked by web pages from any web site.
- If you read a malicious email with Outlook Express, the same is true.
If these assumptions are wrong, let me know. Otherwise, I'll proceed
with my analysis under these assumptions.
I don't know myself if it was invocable from e-mail, but if OE treats e-mail message HTML like IE treats HTML from a web site, then the ActiveX control could be invoked by e-mailed HTML.
--Mike Amling
.
- References:
- For PGP Users-Likes and Dislikes of PGP
- From: jinx28
- Re: OT: Gone from topic, now on security Re: For PGP Users-Likes and Dislikes of PGP
- From: Joseph Ashwood
- Re: OT: Gone from topic, now on security Re: For PGP Users-Likes and Dislikes of PGP
- From: David Wagner
- Re: OT: Gone from topic, now on security Re: For PGP Users-Likes and Dislikes of PGP
- From: Joseph Ashwood
- Re: OT: Gone from topic, now on security Re: For PGP Users-Likes and Dislikes of PGP
- From: David Wagner
- For PGP Users-Likes and Dislikes of PGP
- Prev by Date: Re: For PGP Users-Likes and Dislikes of PGP
- Next by Date: Re: The METHOD of creating RSA key
- Previous by thread: Re: OT: Gone from topic, now on security Re: For PGP Users-Likes and Dislikes of PGP
- Next by thread: Re: OT: Gone from topic, now on security Re: For PGP Users-Likes and Dislikes of PGP
- Index(es):
Relevant Pages
|