Updated: 8/6/2008; 10:18:43 PM.
Mark O'Neill's Radio Weblog
        

Wednesday, August 15, 2007

Today Microsoft issued a patch for a buffer overflow vulnerability in their Core XML Services.

Description from: http://www.zerodayinitiative.com/advisories/ZDI-07-048.html :

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of various Microsoft software. User interaction is required to exploit this vulnerability in that the target must visit a malicious page.

The specific flaw exists in the substringData() method available on the TextNode JavaScript object. When specific parameters are passed to the method, an integer overflow occurs causing incorrect memory allocation. If this event occurs after a different ActiveX object has been instantiated, an exploitable condition is created when the ActiveX object is deallocated which can result in the execution of arbitrary code.

The fix was distributed as an automatic Windows Update today:

[more details on other XML vulnerabilities in Vordel's knowledgebase, e.g. here: http://www.vordel.com/knowledgebase/vordel_view5.html ]


9:29:55 AM    comment []

Alan Mather mentioned that he has "taken to snapping shots of whiteboards in meeting rooms dotted around the country as I travel between companies, departments, roles and engagements." He posts two amusing (but confounding) examples below:

As Alan notes, writeboards are usually wiped at the start of meetings, making them (counter-intuitively) a relatively safe place to post confidential information.

This is another effect of the Cameraphone. Most people walking around a corporate office building are now armed with a camera. Only some facilities actually check for them (e.g. a US Govt nuclear research center did this, when I visited, and I was impressed with that). I've never had the nerve to photograph pre-written boards like Alan has, but i have used a cameraphone to record diagrams which have been drawn up during a meeting, to convert them to Visio format later.


9:08:36 AM    comment []

© Copyright 2008 Mark O'Neill.
 
August 2007
Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31  
Jul   Oct


Vordel




Subscribe to "Mark O'Neill's Radio Weblog" in Radio UserLand.

Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.