ANTICHAT.XYZ    VIDEO.ANTICHAT.XYZ    НОВЫЕ СООБЩЕНИЯ    ФОРУМ  
Баннер 1   Баннер 2
Antichat снова доступен.
Форум Antichat (Античат) возвращается и снова открыт для пользователей. Здесь обсуждаются безопасность, программирование, технологии и многое другое. Сообщество снова собирается вместе.
Новый адрес: forum.antichat.xyz
Вернуться   Форум АНТИЧАТ > Оффтоп > Forum for discussion of ANTICHAT
   
Ответ
 
Опции темы Поиск в этой теме Опции просмотра

Acer ships laptops with security hole
  #1  
Старый 11.01.2007, 13:16
Аватар для Sn@k3
Sn@k3
Познавший АНТИЧАТ
Регистрация: 13.04.2006
Сообщений: 1,738
Провел на форуме:
5151669

Репутация: 1198


Отправить сообщение для Sn@k3 с помощью ICQ
По умолчанию Acer ships laptops with security hole

Computer maker Acer has shipped its notebook computers with an ActiveX control that lets any Web site install software on the machine, security researchers warned this week.

The ActiveX control--named LunchApp.ocx--appears to be a way for the company to easily update customer laptops, but also allows others to do the same thing, antivirus firm F-Secure stated in a blog post on Tuesday. The security problem, first discovered in November by security researcher Tan Chew Keong, was confirmed by antivirus F-Secure.

"The library, named LunchApp.ocx, is probably supposed to help with browsing the vendor's website, enable easy updates and such," wrote F-Secure's research team. "It turns out it also makes all those machines vulnerable to a specially crafted HTML file that could instantly download malicious file(s) onto the user's machine and then execute them."

The Acer vulnerability is not the first time that a company has shipped flawed software that threatened customers' security. In December, music giant Sony BMG settled lawsuits filed by Texas and California that sought consumer remedies after the company distributed audio CDs with copy protection software that undermined the security of computers on which the program was installed. ActiveX controls--a framework for creating software components to add interactivity to Web sites as well as add functionality to the operating system--have frequently been at the heart of security problems for Microsoft.

Acer did not immediately respond to a request for comment. It's unknown if the company has taken steps to fix the problem.

securityfocus.com
 
Ответить с цитированием
Ответ



Похожие темы
Тема Автор Раздел Ответов Последнее сообщение
Security Links _-[A.M.D]HiM@S-_ Уязвимости 1 28.11.2006 23:12
Mozilla focuses on security with Firefox 2.0 Dracula4ever Forum for discussion of ANTICHAT 1 26.10.2006 15:23



Здесь присутствуют: 1 (пользователей: 0 , гостей: 1)
 


Быстрый переход




ANTICHAT.XYZ