Tuesday, June 19, 2007

IE At Risk To New Unpatched Bug

Exploit code for an unpatched vulnerability in Microsoft's Internet Explorer is circulating, a security company said Friday, but the danger remains low as the current attack only crashes the browser.

Fully-patched Windows XP SP2 and Windows 2000 SP4 systems are open to the new attack, said David Cole, director of Symantec's security response group. "This is proof-of-concept code, we haven't seen any active exploits," said Cole. "Whether it grows into something bigger is heavily linked to if it gets remote code execution [capabilities]," he added.

The news comes just three days after Microsoft released its newest security updates. On Tuesday, however, the company's browser was not patched; an August fix that ended up being released three different times, most recently this week, was the last IE update.

There is no patch now available for the bug, which Microsoft acknowledged it is investigating. In a security advisory issued Thursday, the Redmond, Wash. developer said that it would either release a patch in its regularly-scheduled monthly update, or as an out-of-cycle fix. Windows Server 2003 is not at risk.

The new IE problem is related to an ActiveX control (Microsoft DirectAnimation Path) that's part of the "daxctle.ocx" COM object. An attacker who successfully exploited the vulnerability could hijack the computer, Microsoft acknowledged, without any interaction once a user had been enticed to a malicious Web site.

Microsoft patched ActiveX controls several times last year as attackers discovered that Windows wasn't properly checking to see whether data passed to controls was within allowed parameters. In the case of the proof-of-concept code now available, JavaScript passes unacceptable data to the control, which then results in a heap overflow.

Cole said it wasn't a shock that ActiveX continues to have issues. "The more functionality [in code], the more likely there's an error in it," he said. "Complexity is the enemy of security. It's a difficult problem to solve. Developers try to balance rich functionality with security."

Even though an actual in-the-wild exploit has not been spotted, some security organizations sounded the alarm. Danish vulnerability tracker Secunia, for example, ranked the IE flaw as "Extremely critical, it's more serious warning.

With a patch unavailable, Symantec recommended that users check out Microsoft's advice, which included setting the "kill bit" for the ActiveX control to disable it. That, however, requires users to edit the Windows Registry, something many are unprepared to do. In the past, Microsoft's suggestions to set specific kill bits have been taken up by third-party researchers, who have cranked out automated tools for turning off the control.

Another tactic, said Microsoft, is to disable all ActiveX controls in Internet Explorer from the dialog that appears after selecting Tools|Internet Options.

Internet Explorer 7, which Microsoft will release later this year for Windows XP (and early next bundled with Windows Vista), may stymie similar vulnerabilities in the future, said Cole. "There's some promising signs," said Cole, "but to think that IE 7 will eliminate all these vulnerabilities is ignoring the history of computer security."

In fact, there are growing signs that attackers may soon target Web 2.0 applications written in Ajax. Among Ajax-based sites and services, Cole counted the popular social network MySpace, as well as new versions of Web-based e-mail from Microsoft and Yahoo.

"We're already seen a little bit of interest," said Cole. "The MySpace worm, and the Yamanner worm that attacked Yahoo Mail [in June]. They're not being exploited rampantly, but then neither is Ajax being used widespread.

"We'll find out a lot more about how vulnerability Ajax is in the not-too-distant future."

Source - Tech Web

Stephen, der feilbietet, um ein Filmstar zu werden
Bluegrass Gospel Song Lyrics

Monday, June 11, 2007

RingCube software squeezes PC onto iPod

Mobile computing just got more portable. Making even the latest pocketbook-sized ultra-mobile personal computers look more like lumbering giants, RingCube Technologies Inc. unveiled software that can virtually squeeze a PC onto an iPod, USB keychain drive, cell phone or any gizmo with digital storage space.

RingCube's MojoPac software mirrors a computer's personal settings, programs and data on a storage device. Then, when it's connected to any computer running Microsoft Corp.'s Windows XP operating system, the virtual desktop will run in a window of the underlying PC.

"You're taking your digital soul with you on any portable storage device," said Shan Appajodu, chief executive and co-founder of RingCube.

A user could toggle between the two computing environments. The company contends that everything you do with your MojoPac PC will remain private: the underlying host PC won't retain any of the files or cache copies of what you did on MojoPac, the company said.

The software can be downloaded and tested at no cost for 30 days. If bought within a month of the product's release, it will cost $29.99 with up to three additional licenses for $14.99 each. After the introductory period, the price will jump to $49.99, with up to three extra licenses costing $24.99 each.

MojoPac will be shown off at the DEMOfall 2006 conference, an elite showcase of emerging technologies being held this week in San Diego.

"I lug my laptop around with me everywhere and the idea that I could bring my work environment around with me on a USB key is really attractive," said DEMO producer Chris Shipley.

The software works by creating a virtual operating system that runs the programs users load onto the storage device. RingCube says MojoPac supports any off-the-shelf applications, including PC video games and applications such as Adobe Photoshop or Microsoft Office.

The idea is to transform any computer found at Internet cafes, dorm rooms, libraries or business offices into your personal computer, said Appajodu, who started developing the product more than two years ago.

Mountain View-based RingCube also hopes to introduce a prepackaged version of MojoPac such as on a keychain drive as a low cost computing alternative in developing nations, where many can't afford their own computers. Many people in those areas can't afford personal computers but have access to Internet kiosks.

MojoPac is available as a software download for $49.99 at http://www.mojopac.com.

iPod Book: Doing Cool Stuff with the iPod and the iTunes Music Store

Perch� gli uomini presi Flirt