Network and Computer Security

The Network and Computer Security Blog

Bookmark this site!

November 15, 2006

November 15th edition of Bruce Schneier’s CRYPTO-GRAM

Filed under: Articles, Newsletters — SecuNews @ 1:12 pm

The November 15th issue of Bruce Schneier’s Crypto-Gram newsletter is out. In those mid-terms voting times, this newsletter appropriately contains 4 very good and comprehensive (as usual) articles about electronic votes and voting in general.
Here’s the full newsletter summary:

Voting Technology and Security
More on Electronic Voting Machines
The Inherent Inaccuracy of Voting
The Need for Professional Election Officials
Perceived Risk vs. Actual Risk
Crypto-Gram Reprints
Total Information Awareness Is Back
Forge Your Own Boarding Pass
News
The Death of Ephemeral Conversation
Airline Passenger Profiling for Profit
Counterpane News
Architecture and Security
The Doghouse: Skylark Utilities
Heathrow Tests Biometric ID
Please Stop My Car
Air Cargo Security
Cheyenne Mountain Retired
Comments from Readers

November 6, 2006

Microsoft XMLHTTP ActiveX Control Code Execution Vulnerability

Filed under: News, Vulnerabilities, Windows, Articles — SecuNews @ 2:58 pm

A vulnerability has been reported in Microsoft XML Core Services, which can be exploited by malicious people to compromise a users system.

The vulnerability is caused due to an unspecified error in the XMLHTTP 4.0 ActiveX Control.

Successful exploitation allows execution of arbitrary code when a user e.g. visits a malicious website using Internet Explorer.

Microsoft Advisory & Suggested Workarounds: http://www.microsoft.com/technet/security/advisory/927892.mspx