<![CDATA[Article Comments for Ken Pfeil]]>http://www.windowsitpro.com/authors/author/author/5777659/rsscomment/5777659en-USSun, 27 May 2012 07:39:40 GMTSun, 27 May 2012 07:39:40 GMTProtection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorWed, 03 Aug 2005 22:43:08 GMT
for the previous posts, this is for unprotecting a word doc that has a password (to edit text), not for opening a password required doc (there are utilities available for that). you don’t need a hex editor, save as a html file open it up in a html editor like front page search for the tag replace the password with 8 zeros: 00000000 then open the html in word (it’s now unprotected)save as a doc]]>
Anonymous User Wed, 03 Aug 2005 22:43:08 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorWed, 01 Jun 2005 12:15:05 GMT
The tag in HTML is only there if you use Word 2003. The type of protection discussed here is found under Tools, Protect Document. It is not the document password. Also, you can get around this type of "protection" by inserting a protected file into a new blank document. The protection is automatically removed!]]>
Anonymous User Wed, 01 Jun 2005 12:15:05 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorThu, 07 Apr 2005 20:54:19 GMT
these comments are the worst i’ve ever read.]]>
Anonymous User Thu, 07 Apr 2005 20:54:19 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorThu, 31 Mar 2005 00:29:50 GMT
can somebody tell me how to crack the password to view the .doc or .xls files. If yes then please mail me at amitdudeja@intertollindia.com URGENTLY.]]>
Anonymous User Thu, 31 Mar 2005 00:29:50 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorThu, 31 Mar 2005 00:27:23 GMT
All these steps are useless unless you have the password to view the contents even. If someone can crack the password to view the file then there is no problem modifying it by copying the same text in new .doc file. amitdudeja@intertollindia.com ]]>
Anonymous User Thu, 31 Mar 2005 00:27:23 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorWed, 23 Feb 2005 15:53:48 GMT
nope its not working i could’nt find the password line ]]>
Anonymous User Wed, 23 Feb 2005 15:53:48 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorSun, 06 Feb 2005 18:37:17 GMT
This is for a READ ONLY password. I have been able to find this line but it doesnt appear to work in Word 97 so not much use to me. ]]>
Anonymous User Sun, 06 Feb 2005 18:37:17 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorTue, 01 Feb 2005 13:31:54 GMT
Ref my previous comment.. I created a PROTECTED do***ent, opened it and saved it as HTML, opened it in Notepad.... found NO TAG LINE as described in line 4 of procedure.-i did the same, smth is changed,Help! ]]>
Anonymous User Tue, 01 Feb 2005 13:31:54 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Multiple Vulnerabilities in Microsoft Windowshttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-microsoft-windows44855#commentsAnchorMon, 27 Dec 2004 13:09:31 GMT
Fix announced on 14th, article on 18th, distributed on 23rd. Don’t you think this is too time-sensitive to hold for 9 days?]]>
Anonymous User Mon, 27 Dec 2004 13:09:31 GMThttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-microsoft-windows44855#commentsAnchor
Arbitrary Code Execution in Microsoft WINShttp://www.windowsitpro.com/article/networking/arbitrary-code-execution-in-microsoft-wins#commentsAnchorThu, 02 Dec 2004 07:22:23 GMT
http://support.microsoft.com/search/default.aspx?catalog=LCID%3D1033&query=890710&x=0&y=0 -kewakl]]>
Anonymous User Thu, 02 Dec 2004 07:22:23 GMThttp://www.windowsitpro.com/article/networking/arbitrary-code-execution-in-microsoft-wins#commentsAnchor
Arbitrary Code Execution in Microsoft WINShttp://www.windowsitpro.com/article/networking/arbitrary-code-execution-in-microsoft-wins#commentsAnchorThu, 02 Dec 2004 07:19:36 GMT
Oops- should have been http://support.microsoft.com/default.aspx?scid=kb;en-us;890710 prev link points to the search page. -kewakl]]>
Anonymous User Thu, 02 Dec 2004 07:19:36 GMThttp://www.windowsitpro.com/article/networking/arbitrary-code-execution-in-microsoft-wins#commentsAnchor
Arbitrary Code Execution in Microsoft WINShttp://www.windowsitpro.com/article/networking/arbitrary-code-execution-in-microsoft-wins#commentsAnchorThu, 02 Dec 2004 06:20:14 GMT
The URL given doesn’t work, and MSKB searches on the title given also don’t turn anything up. (and it would be nice if it was actually a link)]]>
Anonymous User Thu, 02 Dec 2004 06:20:14 GMThttp://www.windowsitpro.com/article/networking/arbitrary-code-execution-in-microsoft-wins#commentsAnchor
Multiple Vulnerabilities in Microsoft Internet Explorer 6http://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchorThu, 25 Nov 2004 08:12:12 GMT
Is this like the Readers wives section>]]>
Anonymous User Thu, 25 Nov 2004 08:12:12 GMThttp://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchor
Multiple Vulnerabilities in Microsoft Internet Explorer 6http://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchorThu, 25 Nov 2004 00:57:11 GMT
Hm, 2 questions regarding the issues..: Before: no Sp2 After: there’s Sp2 I just wonder if does it matter if there’s sp2 or not. I mean before you neither got the message about file downloads (btw, it’s a really annoying feature). Other question/update is: there was an error in Netscape (many y ago) and in opera (probably 1/2 y ago) where you were able to force the download location. I don’t know if you want to write about it but it isn’t a security issue - for me(!) - if you are just to change the extension. Expl’: create a html document with .exe extension, save it by save as (is that a problem? not really - as i said: at me).]]>
Anonymous User Thu, 25 Nov 2004 00:57:11 GMThttp://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchor
Multiple Vulnerabilities in Microsoft Internet Explorer 6http://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchorWed, 24 Nov 2004 09:43:56 GMT
Mister ’screw IE’, Your razor sharp intellectual comments have completely changed my opinion on this matter. You are truly a poet.]]>
Anonymous User Wed, 24 Nov 2004 09:43:56 GMThttp://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchor
Multiple Vulnerabilities in Microsoft Internet Explorer 6http://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchorWed, 24 Nov 2004 09:39:25 GMT
"Screw IE"?? "Firefox rules??" Please restrict your posts to the under-12 "script-kiddy" area.... ]]>
Anonymous User Wed, 24 Nov 2004 09:39:25 GMThttp://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchor
Multiple Vulnerabilities in Microsoft Internet Explorer 6http://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchorWed, 24 Nov 2004 08:44:56 GMT
Screw IE. Firefox rules. IE is only useful for non-critical Windows updates, apart from that, it’s obsolete!]]>
Anonymous User Wed, 24 Nov 2004 08:44:56 GMThttp://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchor
Multiple Vulnerabilities in Microsoft Internet Explorer 6http://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchorWed, 24 Nov 2004 08:37:13 GMT
I think the inteligent thing to say here is to limit your use of IE, especially when navigating to sites you normally don’t visit, until Microsoft can fix this problem. I’m positive there are things wrong with Firefox, but one thing is certain; it doesn’t have this problem.]]>
toadkickerWed, 24 Nov 2004 08:37:13 GMThttp://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchor
Multiple Vulnerabilities in Microsoft Internet Explorer 6http://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchorWed, 24 Nov 2004 05:12:57 GMT
Firefox just came out as v1. Of course there’s still no patches needed. versions pre v1 have been patched, and there’s been security alerts regarding FF as well. Please do your homework before posting the next time.]]>
Anonymous User Wed, 24 Nov 2004 05:12:57 GMThttp://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchor
Multiple Vulnerabilities in Microsoft Internet Explorer 6http://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchorTue, 23 Nov 2004 20:45:27 GMT
While it’s no secret that IE is suffering from new vulnerabilities every other day, one of the key reasons is due to the market share of over 90% that it commands. The real test of firefox or any other browser will be the day once it reaches atleast 20% market share. That’s the time when researchers have fun in exploiting the vulnerabilities..]]>
Anonymous User Tue, 23 Nov 2004 20:45:27 GMThttp://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchor
Multiple Vulnerabilities in Microsoft Internet Explorer 6http://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchorTue, 23 Nov 2004 20:35:49 GMT
Anybody can claim that any browser is having a security problem. There are no evidences that such security holes exist in IE 6.0, please stop marking the FireFox.]]>
Anonymous User Tue, 23 Nov 2004 20:35:49 GMThttp://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchor
Multiple Vulnerabilities in Microsoft Internet Explorer 6http://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchorTue, 23 Nov 2004 10:28:01 GMT
Yeah... FireFox is great as long as you don’t need ActiveX controls.]]>
Anonymous User Tue, 23 Nov 2004 10:28:01 GMThttp://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchor
Multiple Vulnerabilities in Microsoft Internet Explorer 6http://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchorTue, 23 Nov 2004 10:12:18 GMT
Firefox has been patched. You fool.]]>
Anonymous User Tue, 23 Nov 2004 10:12:18 GMThttp://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchor
Multiple Vulnerabilities in Microsoft Internet Explorer 6http://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchorTue, 23 Nov 2004 10:00:06 GMT
Jeez - can people please stop bleating on about Firefox. It’s the first thing you see against every IE flaw. It’s amazing how they managed to write such a perfect browser, first time round. Perhaps they should be working on the WorldPeace.exe or NoMoreHunger.exe]]>
Anonymous User Tue, 23 Nov 2004 10:00:06 GMThttp://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchor
Multiple Vulnerabilities in Cactusoft’s CactuShop 5.xhttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-cactusoft-s-cactushop-5-x#commentsAnchorTue, 23 Nov 2004 07:35:08 GMT
The issues were fixed: http://www.s-quadra.com/advisories/Adv-20040331.txt]]>
Anonymous User Tue, 23 Nov 2004 07:35:08 GMThttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-cactusoft-s-cactushop-5-x#commentsAnchor
Multiple Vulnerabilities in Microsoft Internet Explorer 6http://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchorMon, 22 Nov 2004 04:55:35 GMT
That’s a fantastic observation. firefox rocks. Good for you.]]>
Anonymous User Mon, 22 Nov 2004 04:55:35 GMThttp://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer-6#commentsAnchor
Multiple Vulnerabilities in RealPlayer and RealOne playerhttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-realplayer-and-realone-player#commentsAnchorSun, 21 Nov 2004 05:26:42 GMT
http://www.armux.com]]>
Anonymous User Sun, 21 Nov 2004 05:26:42 GMThttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-realplayer-and-realone-player#commentsAnchor
Denial of Service in Oracle 8i and 9i for Windowshttp://www.windowsitpro.com/article/oracle/denial-of-service-in-oracle-8i-and-9i-for-windows#commentsAnchorSun, 07 Nov 2004 06:16:53 GMT
asdf]]>
Anonymous User Sun, 07 Nov 2004 06:16:53 GMThttp://www.windowsitpro.com/article/oracle/denial-of-service-in-oracle-8i-and-9i-for-windows#commentsAnchor
Arbitrary Code Execution in PuTTY for Windowshttp://www.windowsitpro.com/article/security/arbitrary-code-execution-in-putty-for-windows#commentsAnchorWed, 03 Nov 2004 01:18:39 GMT
Great article. Better than mine!]]>
PAUL THURR0TTWed, 03 Nov 2004 01:18:39 GMThttp://www.windowsitpro.com/article/security/arbitrary-code-execution-in-putty-for-windows#commentsAnchor
Arbitrary Remote Code Execution Vulnerability in WildTangent Web Driver 4.0http://www.windowsitpro.com/article/security/arbitrary-remote-code-execution-vulnerability-in-wildtangent-web-driver-4-0#commentsAnchorThu, 14 Oct 2004 08:07:22 GMT
no comment, thank you very useful]]>
Anonymous User Thu, 14 Oct 2004 08:07:22 GMThttp://www.windowsitpro.com/article/security/arbitrary-remote-code-execution-vulnerability-in-wildtangent-web-driver-4-0#commentsAnchor
Local Privilege Escalation Vulnerability in ServU FTP serverhttp://www.windowsitpro.com/article/ftp/local-privilege-escalation-vulnerability-in-servu-ftp-server#commentsAnchorThu, 19 Aug 2004 14:01:25 GMT
I have the Serv-U 5.1 Personal Edition installed on a Windows 2000 box, and it does not allow remote administration. SITE MAINTENANCE Serv-U responds with: 553 Server Edition does not support remote administration. Perhaps this attack is only good for Serv-U installed on Windows XP? - Chris]]>
CHRISThu, 19 Aug 2004 14:01:25 GMThttp://www.windowsitpro.com/article/ftp/local-privilege-escalation-vulnerability-in-servu-ftp-server#commentsAnchor
Multiple Vulnerabilities in winShadow for Windowshttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-winshadow-for-windows#commentsAnchorTue, 22 Jun 2004 22:22:02 GMT
These issues were resolved on the 17th of October 2003.]]>
OmniCom Support Tue, 22 Jun 2004 22:22:02 GMThttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-winshadow-for-windows#commentsAnchor
Arbitrary Remote Code Execution Vulnerability in WildTangent Web Driver 4.0http://www.windowsitpro.com/article/security/arbitrary-remote-code-execution-vulnerability-in-wildtangent-web-driver-4-0#commentsAnchorFri, 11 Jun 2004 09:38:03 GMT
We thank you so very much for letting us know about this problem. But you always seem to not go the distance and tell us the whole story; by not telling us that this is SPYWARE you are doing an extreme disservice to your customers. I believe more people would want to completely remove this software and update it. http://www.spyany.com/program/article_spw_rm_WildTangent.html]]>
aaronFri, 11 Jun 2004 09:38:03 GMThttp://www.windowsitpro.com/article/security/arbitrary-remote-code-execution-vulnerability-in-wildtangent-web-driver-4-0#commentsAnchor
Denial of Service in MDaemon Email for Windows NT/2000http://www.windowsitpro.com/article/security/denial-of-service-in-mdaemon-email-for-windows-nt-2000#commentsAnchorWed, 02 Jun 2004 00:45:12 GMT
I am really Empresed by this product.]]>
sibghat Wed, 02 Jun 2004 00:45:12 GMThttp://www.windowsitpro.com/article/security/denial-of-service-in-mdaemon-email-for-windows-nt-2000#commentsAnchor
ImageMap URL Spoof Vulnerability in Microsoft Internet Explorerhttp://www.windowsitpro.com/article/internet/imagemap-url-spoof-vulnerability-in-microsoft-internet-explorer#commentsAnchorFri, 28 May 2004 09:37:30 GMT
this same spoof can be configured to do the yellow lock in the bottom right hand corner of the page.to spoof secure site.saw it in a repply post in slashdot many months ago. this is not a new problem. just newly reported!]]>
DaveFri, 28 May 2004 09:37:30 GMThttp://www.windowsitpro.com/article/internet/imagemap-url-spoof-vulnerability-in-microsoft-internet-explorer#commentsAnchor
ImageMap URL Spoof Vulnerability in Microsoft Internet Explorerhttp://www.windowsitpro.com/article/internet/imagemap-url-spoof-vulnerability-in-microsoft-internet-explorer#commentsAnchorFri, 28 May 2004 09:15:52 GMT
This doesnt appear to be anything new? The same effect can be achieved using javascript to manipulate the status bar as follows: Demo Page

Test Page

http://www.microsoft.com

]]>
Nick Burrlock Fri, 28 May 2004 09:15:52 GMThttp://www.windowsitpro.com/article/internet/imagemap-url-spoof-vulnerability-in-microsoft-internet-explorer#commentsAnchor
ImageMap URL Spoof Vulnerability in Microsoft Internet Explorerhttp://www.windowsitpro.com/article/internet/imagemap-url-spoof-vulnerability-in-microsoft-internet-explorer#commentsAnchorFri, 28 May 2004 09:11:04 GMT
Its good that I use Mozilla or Opera web browsers I tested them and they dont suffer from this vulnerality. Now, how says that Open Source is not safer than the people at Redmont.....]]>
Juan Hernandez Fri, 28 May 2004 09:11:04 GMThttp://www.windowsitpro.com/article/internet/imagemap-url-spoof-vulnerability-in-microsoft-internet-explorer#commentsAnchor
ImageMap URL Spoof Vulnerability in Microsoft Internet Explorerhttp://www.windowsitpro.com/article/internet/imagemap-url-spoof-vulnerability-in-microsoft-internet-explorer#commentsAnchorFri, 28 May 2004 09:04:58 GMT
I do not thing it’s a vulnerability, it’s more like spoofing technique. Looks like inside of . One can do similar things with OnMouseOver/Out script -> If you have access to the web server copy/paste code below, also if you click on URL and hold mouse button down (in both cases), IE would display actual URL <<<<<<<<<<<<<<<<< www.ms.com >>>>>>>>>>>>>>>>>>>>>>>> Thank you. Alex]]>
alexFri, 28 May 2004 09:04:58 GMThttp://www.windowsitpro.com/article/internet/imagemap-url-spoof-vulnerability-in-microsoft-internet-explorer#commentsAnchor
ImageMap URL Spoof Vulnerability in Microsoft Internet Explorerhttp://www.windowsitpro.com/article/internet/imagemap-url-spoof-vulnerability-in-microsoft-internet-explorer#commentsAnchorFri, 28 May 2004 09:04:47 GMT
This can also be done less benignly by using an image link in the same way and JavaScript to change the status bar text to show the false link.]]>
Ian Haynes Fri, 28 May 2004 09:04:47 GMThttp://www.windowsitpro.com/article/internet/imagemap-url-spoof-vulnerability-in-microsoft-internet-explorer#commentsAnchor
ImageMap URL Spoof Vulnerability in Microsoft Internet Explorerhttp://www.windowsitpro.com/article/internet/imagemap-url-spoof-vulnerability-in-microsoft-internet-explorer#commentsAnchorFri, 28 May 2004 09:01:30 GMT
Kind of a kludgey workaround, but try this on the proof of concept page: If you set focus to the link itself (not the image) by either hitting the tab key or right-clicking it, rather than left-clicking on the link, the real URL appears in the status bar. But who’s going to know to do this in advance?]]>
Elrod Fri, 28 May 2004 09:01:30 GMThttp://www.windowsitpro.com/article/internet/imagemap-url-spoof-vulnerability-in-microsoft-internet-explorer#commentsAnchor
ImageMap URL Spoof Vulnerability in Microsoft Internet Explorerhttp://www.windowsitpro.com/article/internet/imagemap-url-spoof-vulnerability-in-microsoft-internet-explorer#commentsAnchorFri, 28 May 2004 08:48:17 GMT
Why would anyone call this a vulnerability? You can do the same thing with a window.status call in JavaScript. He’s showing a URL-like image and linking this to another site. Big deal(!)]]>
Joe A. Fri, 28 May 2004 08:48:17 GMThttp://www.windowsitpro.com/article/internet/imagemap-url-spoof-vulnerability-in-microsoft-internet-explorer#commentsAnchor
Denial of Service in Microsoft Internet Explorer 6.0 SP1http://www.windowsitpro.com/article/internet/denial-of-service-in-microsoft-internet-explorer-6-0-sp1#commentsAnchorThu, 27 May 2004 08:07:37 GMT
Am suffering from the effects of this or something very similar HTML corruptionbut not able to correct it....please can anybody suggest a cure.]]>
Richard S Thu, 27 May 2004 08:07:37 GMThttp://www.windowsitpro.com/article/internet/denial-of-service-in-microsoft-internet-explorer-6-0-sp1#commentsAnchor
Denial of Service in Microsoft Internet Explorer 6.0 SP1http://www.windowsitpro.com/article/internet/denial-of-service-in-microsoft-internet-explorer-6-0-sp1#commentsAnchorWed, 26 May 2004 06:08:20 GMT
Where’s the DoS? All this VULNERABILITY proves is that bad HTML can crash IE which is no major surprise. You’re promoting the equivalent of Chicken Little’s "the sky is falling" to read "the universe is imploding!". Why assume that any crash like this can cause a DoS? Stop mixing your careers in journalism with those college semesters of advertising.]]>
J Palmer Wed, 26 May 2004 06:08:20 GMThttp://www.windowsitpro.com/article/internet/denial-of-service-in-microsoft-internet-explorer-6-0-sp1#commentsAnchor
Denial of Service in Microsoft Internet Explorer 6.0 SP1http://www.windowsitpro.com/article/internet/denial-of-service-in-microsoft-internet-explorer-6-0-sp1#commentsAnchorTue, 25 May 2004 20:22:23 GMT
So we have a script language interpreter/environment in which it’s possible to write code that crashes the environment? We have a name for that, but it’s not "vulnerability"... it’s called "life", get a grip. Meta tags aren’t valid in the body, only in the head. The browser imputes the html and body elements in an empty document but it’s under no onus to impute a head element. So it choked on bad code? If someone codes a page this way, it’s Microsoft’s fault that the client’s browser crashes? At absolute worst this represents a missed opportunity for judicious null-checking. This does not belong in a security bulliten. Could it be that someone has way too much time on his hands? -Mark]]>
Mark McGinty Tue, 25 May 2004 20:22:23 GMThttp://www.windowsitpro.com/article/internet/denial-of-service-in-microsoft-internet-explorer-6-0-sp1#commentsAnchor
Multiple Vulnerabilities in Cactusoft’s CactuShop 5.xhttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-cactusoft-s-cactushop-5-x#commentsAnchorTue, 11 May 2004 10:51:26 GMT
these issues were fixed within a few days of S-Quadra announcing them 16 Mar 2004: S-Quadra alerted CactuSoft about new PoC Code. 26 Mar 2004: S-Quadra alerted CactuSoft about new PoC Code. 04 Apr 2004: CactuSoft fixed SQL Injection vulnerability. 06 Apr 2004: CactuSoft fixed XSS vulnerability.]]>
PaulTue, 11 May 2004 10:51:26 GMThttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-cactusoft-s-cactushop-5-x#commentsAnchor
Multiple Vulnerabilities in Microsoft Windows RPC/DCOMhttp://www.windowsitpro.com/article/distributed-comdcom/multiple-vulnerabilities-in-microsoft-windows-rpc-dcom#commentsAnchorWed, 05 May 2004 23:55:24 GMT
Hi guys , listen please could you be abit quicker, Irun a sus server which had this patch on the 9th of April as with the last two "Alerts" you sent. Although I do appreciate you articles and the fact that your correspondence via email doesnt cost me anything, it is starting to cost me time that i really do not have by making me go back to verify that i have in fact applied a patch to correct the "latest" vulnerability.]]>
Marcelo Pronto Wed, 05 May 2004 23:55:24 GMThttp://www.windowsitpro.com/article/distributed-comdcom/multiple-vulnerabilities-in-microsoft-windows-rpc-dcom#commentsAnchor
Multiple Vulnerabilities in RealPlayer and RealOne playerhttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-realplayer-and-realone-player#commentsAnchorWed, 05 May 2004 15:33:25 GMT
I have heard this already on realone.com site. I have e-mailed their technicians but I can’t download updates from realnetworks.com. I’ve adjusted all the settings and the network transports and the udp ports. So I’m supposed to think it’s my spyware blaster? All of the above to say I’ve surfed in looking to help with network transport issues with RealOne player]]>
Lorne Bergson Wed, 05 May 2004 15:33:25 GMThttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-realplayer-and-realone-player#commentsAnchor
Multiple Vulnerabilities in Microsoft Windowshttp://www.windowsitpro.com/article/windows-2000/multiple-vulnerabilities-in-microsoft-windows#commentsAnchorTue, 27 Apr 2004 20:03:15 GMT
I thought the article was informative and practicle.]]>
e.b.penner Tue, 27 Apr 2004 20:03:15 GMThttp://www.windowsitpro.com/article/windows-2000/multiple-vulnerabilities-in-microsoft-windows#commentsAnchor
Exchange 2000 and IIS 5.0 Denial of Servicehttp://www.windowsitpro.com/article/exchange-2000-server/exchange-2000-and-iis-5-0-denial-of-service#commentsAnchorFri, 16 Apr 2004 04:01:59 GMT
very fine]]>
sandeepFri, 16 Apr 2004 04:01:59 GMThttp://www.windowsitpro.com/article/exchange-2000-server/exchange-2000-and-iis-5-0-denial-of-service#commentsAnchor
Buffer-overrun Vulnerability in WS_FTP Prohttp://www.windowsitpro.com/article/ftp/buffer-overrun-vulnerability-in-ws_ftp-pro#commentsAnchorFri, 02 Apr 2004 02:12:38 GMT
http://www.ipswitch.com/products/ws_ftp/whatsnew.html is where to go for the latest version single user cost: USD$44.95 What they call version 8.0? Upgrade to v8.0 with Service Agreement (provides all product upgrades & unlimited phone and email technical support for 12 months) USD$24.95 Upgrade (one-time upgrade to v8.0) USD$19.95 But, we don’t use this, the Trellix Corporation’s Web Photo Manager works fine and is easy to use!]]>
Mike Schiele Fri, 02 Apr 2004 02:12:38 GMThttp://www.windowsitpro.com/article/ftp/buffer-overrun-vulnerability-in-ws_ftp-pro#commentsAnchor
Buffer-overrun Vulnerability in WS_FTP Prohttp://www.windowsitpro.com/article/ftp/buffer-overrun-vulnerability-in-ws_ftp-pro#commentsAnchorWed, 24 Mar 2004 16:08:30 GMT
How about the makers of WSFTP Pro consider FIXING the problem in previous versions with a free patch? Hmmmm? Don’t make me upgrade just to fix a weakness in the product! C’mon people. Give me a break.]]>
Michael Dowless Wed, 24 Mar 2004 16:08:30 GMThttp://www.windowsitpro.com/article/ftp/buffer-overrun-vulnerability-in-ws_ftp-pro#commentsAnchor
Buffer-overrun Vulnerability in WS_FTP Prohttp://www.windowsitpro.com/article/ftp/buffer-overrun-vulnerability-in-ws_ftp-pro#commentsAnchorWed, 24 Mar 2004 10:38:08 GMT
Is there any fix?]]>
Maire Wed, 24 Mar 2004 10:38:08 GMThttp://www.windowsitpro.com/article/ftp/buffer-overrun-vulnerability-in-ws_ftp-pro#commentsAnchor
Buffer Overrun In Microsoft Windows HTML Converterhttp://www.windowsitpro.com/article/windows-2000/buffer-overrun-in-microsoft-windows-html-converter#commentsAnchorMon, 08 Mar 2004 18:01:26 GMT
I bought a new computer, thinking I wouls still be compatable with windows 2000,I could bring my work home and work.But, I can’t because this window 98 does not have office in it. I think after paying as much as I did for this computer, it would at least have a compatable converter or a conversion that I couls use.]]>
hazel crews Mon, 08 Mar 2004 18:01:26 GMThttp://www.windowsitpro.com/article/windows-2000/buffer-overrun-in-microsoft-windows-html-converter#commentsAnchor
Multiple Vulnerabilities in RealPlayer and RealOne playerhttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-realplayer-and-realone-player#commentsAnchorTue, 24 Feb 2004 20:37:14 GMT
Good description of the potential threat.]]>
Terry Ellis Tue, 24 Feb 2004 20:37:14 GMThttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-realplayer-and-realone-player#commentsAnchor
Multiple Vulnerabilities in RealPlayer and RealOne playerhttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-realplayer-and-realone-player#commentsAnchorMon, 23 Feb 2004 22:09:29 GMT
I use it regularly prefer it over windows media player]]>
N. D'ERI Mon, 23 Feb 2004 22:09:29 GMThttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-realplayer-and-realone-player#commentsAnchor
Arbitrary Remote Execution of Code in Microsoft Windowshttp://www.windowsitpro.com/article/windows-2000/arbitrary-remote-execution-of-code-in-microsoft-windows#commentsAnchorThu, 12 Feb 2004 04:22:48 GMT
It´s good article.]]>
Jorge Atoji Thu, 12 Feb 2004 04:22:48 GMThttp://www.windowsitpro.com/article/windows-2000/arbitrary-remote-execution-of-code-in-microsoft-windows#commentsAnchor
Multiple Vulnerabilities in Microsoft Internet Explorerhttp://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer41698#commentsAnchorTue, 10 Feb 2004 09:55:49 GMT
Your reference to the Microsoft bulletin MS04-003 is incorrect and should be MS04-004. The referenced bulletin is a security bulletin that has to do with MDAC.]]>
Robert Gay Tue, 10 Feb 2004 09:55:49 GMThttp://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer41698#commentsAnchor
Multiple Vulnerabilities in Microsoft Internet Explorerhttp://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer41698#commentsAnchorTue, 10 Feb 2004 01:17:07 GMT
it is MS04-004, not MS04-003]]>
hans hamakers Tue, 10 Feb 2004 01:17:07 GMThttp://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer41698#commentsAnchor
Remote Code Execution Vulnerability in Microsoft ISA Server 2000http://www.windowsitpro.com/article/security/remote-code-execution-vulnerability-in-microsoft-isa-server-2000#commentsAnchorWed, 21 Jan 2004 00:10:15 GMT
The article is timely and sensitive. It will go along way in solving security issues both on the engine that power the security and the vehicle that the engine powers to bring about a secure environment.]]>
Akintade Olusegun Wed, 21 Jan 2004 00:10:15 GMThttp://www.windowsitpro.com/article/security/remote-code-execution-vulnerability-in-microsoft-isa-server-2000#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorFri, 09 Jan 2004 08:53:43 GMT
Ref my previous comment.. I created a PROTECTED document, opened it and saved it as HTML, opened it in Notepad.... found NO TAG LINE as described in line 4 of procedure.]]>
KJ Fri, 09 Jan 2004 08:53:43 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorFri, 09 Jan 2004 08:32:18 GMT
How do you OPEN A PROTECTED DOCUMENT IN WORD without already knowing the password you are going to defeat? Or, how do you get past the modal dialog box to open a protecrted document without the password?]]>
KJ Fri, 09 Jan 2004 08:32:18 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorThu, 08 Jan 2004 13:46:08 GMT
Your steps start with open a secured document. But how this malicious user open the document on the first place.]]>
Maida Thu, 08 Jan 2004 13:46:08 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorThu, 08 Jan 2004 07:42:09 GMT
I’ve seen a couple articles about this now, and none have stated the obvious fact that Word password protection was never intended as a full-blown security measure. If you want a truly protected document, use a digital signature or encryption. Why do you think that such industry-standard protection schemes exist? On top of that, if you are worried about legal chain-of-custody in a compromised document, it is easily proven that the document cracked in this manner is not original. Word stores all revision information about the document in the document’s "metadata"; data that is not visible within the application itself. When saving the document to HTML and then back into .DOC format, all of this information is destroyed because the .HTM file is a new file rather than a modified version of the original, which has its own metadata attributes. A simple comparison of the metadata between the original and the cracked version will quickly show that the latter is a fake. This really is not a vulnerability. It is simply a wake-up call for those people using a feature for what it was never intended for, rather than be bothered to protect their documents properly using one of many industry accepted practices.]]>
Robert Richard Thu, 08 Jan 2004 07:42:09 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorThu, 08 Jan 2004 07:12:10 GMT
If you can gather the password why bother going through the trouble with the hex editor to remove it. Just use it...]]>
brianThu, 08 Jan 2004 07:12:10 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorThu, 08 Jan 2004 06:50:48 GMT
I tried this using Word 2002 with SP-2 installed and I received a message stating that the Save As Web Page (*.htm; *.html) will unsecure the document - did I wish to continue? Are you sure these instructions are correct?]]>
Jim Krakowski Thu, 08 Jan 2004 06:50:48 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorThu, 08 Jan 2004 06:13:57 GMT
May be my understanding of English isn’ t enough? But, I don’t notice something stranger! You can open a protected document IF you know it of course, isn’ it? Or may be someone open it for you and let you work on it. With the trick explained by Thorsten Delbrouck you can know the password. That the only problem, I see. If I misunderstand IT; please, explain me.]]>
Michel BRUYÈRE Thu, 08 Jan 2004 06:13:57 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorWed, 07 Jan 2004 21:57:48 GMT
In fact I have found that you need not go to this trouble. You can save the document in save as a rtf file. Then open the same in word & unprotect the document. It does not ask for a password, if it is done in this sequence.]]>
K. Ramaswamy Wed, 07 Jan 2004 21:57:48 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorWed, 07 Jan 2004 21:53:34 GMT
what do you mean by protected...?? is it password or what.. thanx]]>
manafWed, 07 Jan 2004 21:53:34 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorWed, 07 Jan 2004 17:52:18 GMT
Try just opening the document with Wordpad to bypass security. The "Thorsten Delbrouck" is way to complicated.]]>
Lisa Burke Wed, 07 Jan 2004 17:52:18 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorWed, 07 Jan 2004 15:42:58 GMT
Aww cmon - give poor ole MS a break. You’ve just discovered the MS password recovery feature (LOL!).]]>
Phil Hogan Wed, 07 Jan 2004 15:42:58 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorTue, 06 Jan 2004 19:50:53 GMT
I had problems with word not to long ago. I tried to go check on a document I thought I had saved but when I went to go look for It word told me It did not exist but I had just saved It not more then two weeks before this so I know It was there. I contacted Microsoft but they told me since I did not have a credit card their was nothing they could do so I ended up calling the manufacturer of my system and through them I was finally able to get It working again.]]>
JodiTue, 06 Jan 2004 19:50:53 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Protection Bypass Vulnerability in Microsoft Wordhttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchorTue, 06 Jan 2004 15:51:16 GMT
I’ve tested this process with an MS-provided document that has write protection enabled, yet the "" tag does exist in the HTML document that I saved. The document I’m speaking of is the SMS 2003 Reviews Guide available from http://www.microsoft.com/smserver.]]>
Larry A. Duncan Tue, 06 Jan 2004 15:51:16 GMThttp://www.windowsitpro.com/article/office/protection-bypass-vulnerability-in-microsoft-word#commentsAnchor
Mulitple Vulnerabilities in Cisco PIX Firewallhttp://www.windowsitpro.com/article/firewalls3/mulitple-vulnerabilities-in-cisco-pix-firewall#commentsAnchorWed, 17 Dec 2003 22:28:19 GMT
you don’t explain if the crash of snmpv3, must be done from the configured ip_addr in pix configuration or can be from any IP. regards]]>
raul lopez Wed, 17 Dec 2003 22:28:19 GMThttp://www.windowsitpro.com/article/firewalls3/mulitple-vulnerabilities-in-cisco-pix-firewall#commentsAnchor
Arbitrary Code Execution Vulnerability in Yahoo! Instant Messengerhttp://www.windowsitpro.com/article/instant-messaging-im/arbitrary-code-execution-vulnerability-in-yahoo-instant-messenger#commentsAnchorSat, 06 Dec 2003 04:28:32 GMT
There must also be a vulnerability in yahoo, I have a Yahoo account and quit using it because all I had been and still sometimes is SMUT, PORN, whatever you want to call it and when I go to block it is always someone from Yahoo,com. So as a result I had to block ANY @yahoo.com mail, thus losing some important mail as well. Richard kruse]]>
Richard Kruse Sat, 06 Dec 2003 04:28:32 GMThttp://www.windowsitpro.com/article/instant-messaging-im/arbitrary-code-execution-vulnerability-in-yahoo-instant-messenger#commentsAnchor
Arbitrary Code Execution Vulnerability in Yahoo! Instant Messengerhttp://www.windowsitpro.com/article/instant-messaging-im/arbitrary-code-execution-vulnerability-in-yahoo-instant-messenger#commentsAnchorFri, 05 Dec 2003 12:28:33 GMT
It would be interesting to know when the vendor was notified so that we can see how long the response takes. Regards, John Sharp]]>
John Sharp Fri, 05 Dec 2003 12:28:33 GMThttp://www.windowsitpro.com/article/instant-messaging-im/arbitrary-code-execution-vulnerability-in-yahoo-instant-messenger#commentsAnchor
Denial of Service in SpeakFreely for Windowshttp://www.windowsitpro.com/article/security/denial-of-service-in-speakfreely-for-windows#commentsAnchorTue, 11 Nov 2003 01:45:16 GMT
Any way that we might possibily get some more information about this vulnerability? The description is somewhat vague.]]>
Mike Aguilar Tue, 11 Nov 2003 01:45:16 GMThttp://www.windowsitpro.com/article/security/denial-of-service-in-speakfreely-for-windows#commentsAnchor
Data Compromise Vulnerability in PGPDisk for Windowshttp://www.windowsitpro.com/article/security/data-compromise-vulnerability-in-pgpdisk-for-windows#commentsAnchorThu, 30 Oct 2003 11:06:00 GMT
Isn’t the switch user fucntionality only available in standalone systems? Or is that controlled in an AD environment through group policy? And isn’t this a Microsoft problem, not a PGP problem?]]>
Fred Langston Thu, 30 Oct 2003 11:06:00 GMThttp://www.windowsitpro.com/article/security/data-compromise-vulnerability-in-pgpdisk-for-windows#commentsAnchor
Buffer Overrun in Microsoft Windows ListBox and ComboBox Controlshttp://www.windowsitpro.com/article/security/buffer-overrun-in-microsoft-windows-listbox-and-combobox-controls#commentsAnchorWed, 22 Oct 2003 17:18:28 GMT
According to Microsoft Windows ME is not affected by the Q824141 fault, contrary to what your article 40585 claims.]]>
Jeffrey Ross Wed, 22 Oct 2003 17:18:28 GMThttp://www.windowsitpro.com/article/security/buffer-overrun-in-microsoft-windows-listbox-and-combobox-controls#commentsAnchor
Buffer Overrun in Microsoft Windows ListBox and ComboBox Controlshttp://www.windowsitpro.com/article/security/buffer-overrun-in-microsoft-windows-listbox-and-combobox-controls#commentsAnchorWed, 22 Oct 2003 12:49:44 GMT
This patched caused some issues with roaming profiles has MS addresed it?]]>
Marlo Cleckley Sr Wed, 22 Oct 2003 12:49:44 GMThttp://www.windowsitpro.com/article/security/buffer-overrun-in-microsoft-windows-listbox-and-combobox-controls#commentsAnchor
Man-in-the-Middle Attack on Microsoft Terminal Serviceshttp://www.windowsitpro.com/article/security/man-in-the-middle-attack-on-microsoft-terminal-services#commentsAnchorFri, 17 Oct 2003 15:12:16 GMT
How realistic is an attack like this? What effort is involved in gaining a high enough level of access to make it worth while? Can it be automated to record all comms, thus allowing the attacker to pick and choose which credentials to use (obviously being Admin)?... And couldn’t sniffing like this be detected fairly easily?]]>
JKFri, 17 Oct 2003 15:12:16 GMThttp://www.windowsitpro.com/article/security/man-in-the-middle-attack-on-microsoft-terminal-services#commentsAnchor
Multiple Vulnerabilities in winShadow for Windowshttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-winshadow-for-windows#commentsAnchorTue, 07 Oct 2003 16:23:14 GMT
I was just wondering how you know this is legit?]]>
Tue, 07 Oct 2003 16:23:14 GMThttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-winshadow-for-windows#commentsAnchor
System Compromise Vulnerability in Microsoft MDAChttp://www.windowsitpro.com/article/data-access/system-compromise-vulnerability-in-microsoft-mdac#commentsAnchorFri, 22 Aug 2003 12:33:35 GMT
How does one deploy this update within an enterprise in an unattended mode?]]>
Shabbir Talib Fri, 22 Aug 2003 12:33:35 GMThttp://www.windowsitpro.com/article/data-access/system-compromise-vulnerability-in-microsoft-mdac#commentsAnchor
Buffer Overrun In RPC Interface Could Allow Code Executionhttp://www.windowsitpro.com/article/windows-2000/buffer-overrun-in-rpc-interface-could-allow-code-execution#commentsAnchorFri, 18 Jul 2003 11:41:37 GMT
Does anyone have any insights about the probability of this also being a problem on W9x, ME, - essentially all those home users who don’t have any idea that there is a thing called an open port on their computer? Why can’t the exploit work on those devices...I’m not real familiar with DCOM and where/when it’s used, but apparently that figures prominently in the exploit, do those OS’s not support DCOM]]>
Paul Petersen Fri, 18 Jul 2003 11:41:37 GMThttp://www.windowsitpro.com/article/windows-2000/buffer-overrun-in-rpc-interface-could-allow-code-execution#commentsAnchor
Buffer Overflow in Windows XP SP1's rundll32.exehttp://www.windowsitpro.com/article/windows-xp2/buffer-overflow-in-windows-xp-sp1-s-rundll32-exe#commentsAnchorWed, 09 Jul 2003 15:15:26 GMT
Can you provide more information about this issue? What rights did the user have when the this occurred and what rights did the user have afterwards? Thanks!]]>
Joe Iuen Wed, 09 Jul 2003 15:15:26 GMThttp://www.windowsitpro.com/article/windows-xp2/buffer-overflow-in-windows-xp-sp1-s-rundll32-exe#commentsAnchor
Unchecked Buffer in Windows 2000 WebDAVhttp://www.windowsitpro.com/article/windows-2000/unchecked-buffer-in-windows-2000-webdav#commentsAnchorWed, 19 Mar 2003 07:51:52 GMT
CREDIT TO MICROSOFT! PLEASE>>>>WE FOUND THAT!!! OUR ENGINEERS AT MY AGENCY FOUND THIS! DON"T GIVE MICROSOFT AND OUNCE OF CREDIT! WE HAD TO BEAT THEM INTO RELEASING THIS!!!]]>
Matthew Baum Wed, 19 Mar 2003 07:51:52 GMThttp://www.windowsitpro.com/article/windows-2000/unchecked-buffer-in-windows-2000-webdav#commentsAnchor
Unchecked Buffer in Windows 2000 WebDAVhttp://www.windowsitpro.com/article/windows-2000/unchecked-buffer-in-windows-2000-webdav#commentsAnchorTue, 18 Mar 2003 19:05:24 GMT
Micosoft did not discover this vulernability, a undisclosed company discovered it when they called Microsoft to say that something was wrong with their web servers, well at least this is what today’s New York Post reports....]]>
NY Post Reader Tue, 18 Mar 2003 19:05:24 GMThttp://www.windowsitpro.com/article/windows-2000/unchecked-buffer-in-windows-2000-webdav#commentsAnchor
Multiple Vulnerabilities in Microsoft IIShttp://www.windowsitpro.com/article/web-administration/multiple-vulnerabilities-in-microsoft-iis#commentsAnchorTue, 28 Jan 2003 00:02:19 GMT
I am having a problem when i am opening IIS 5.0 in windows 2000 server.When i am opening IIS service maanger it is showing that "a non-fatal configuration error occured.Not all available information may be dispalyed".Also i cann’t add new sites to the server due to this.i cann’t edit the current sites properties.can you help in this situation.]]>
Jojy George Tue, 28 Jan 2003 00:02:19 GMThttp://www.windowsitpro.com/article/web-administration/multiple-vulnerabilities-in-microsoft-iis#commentsAnchor
Buffer Overrun Vulnerability in CuteFTP for Windowshttp://www.windowsitpro.com/article/ftp/buffer-overrun-vulnerability-in-cuteftp-for-windows#commentsAnchorTue, 21 Jan 2003 17:10:08 GMT
What? Can this be explained in more detail.]]>
Richard Otter Tue, 21 Jan 2003 17:10:08 GMThttp://www.windowsitpro.com/article/ftp/buffer-overrun-vulnerability-in-cuteftp-for-windows#commentsAnchor
Privilege Escalation Vulnerability in Microsoft's WM_TIMER Message Handlinghttp://www.windowsitpro.com/article/windows-2000/privilege-escalation-vulnerability-in-microsoft-s-wm_timer-message-handling#commentsAnchorThu, 19 Dec 2002 13:48:19 GMT
Do not believe that. This vulnerability was discovered in september not by Microsoft. So many servers have been knocked out before december 16]]>
Bill Gates Thu, 19 Dec 2002 13:48:19 GMThttp://www.windowsitpro.com/article/windows-2000/privilege-escalation-vulnerability-in-microsoft-s-wm_timer-message-handling#commentsAnchor
Vulnerability In Microsoft's Server Message Block for Windows XP and Windows 2000http://www.windowsitpro.com/article/windows-2000/vulnerability-in-microsoft-s-server-message-block-for-windows-xp-and-windows-2000#commentsAnchorThu, 19 Dec 2002 06:05:31 GMT
It sounds very good. But the problem with deployment SP1 for XP in our firm is, that afterwards there are certain problems while working with Office files as in the Technet article Q331519 Network File Errors Occur After You Install Windows XP SP1 stated. Microsoft suggests us to disable SMS signing feature with we have’nt enabled at all. So it means there is no solution for it till now.]]>
Vu, Ngoc Chi Thu, 19 Dec 2002 06:05:31 GMThttp://www.windowsitpro.com/article/windows-2000/vulnerability-in-microsoft-s-server-message-block-for-windows-xp-and-windows-2000#commentsAnchor
Multiple Vulnerabilities in Sybase Adaptive Server 12.0 and 12.5http://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-sybase-adaptive-server-12-0-and-12-5#commentsAnchorWed, 04 Dec 2002 14:34:25 GMT
What risk do these pose? What rights would the hacker need in order to exploit either vulnerability?]]>
Mike Brewer Wed, 04 Dec 2002 14:34:25 GMThttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-sybase-adaptive-server-12-0-and-12-5#commentsAnchor
Multiple Vulnerabilities Exist in Kerio MailServer 5.0 for Windows XP/2000/NThttp://www.windowsitpro.com/article/webbased-services/multiple-vulnerabilities-exist-in-kerio-mailserver-5-0-for-windows-xp-2000-nt#commentsAnchorWed, 06 Nov 2002 10:12:31 GMT


This information is not up-to-date. These vulnerabilities regarding our Kerio MailServer have been fixed as of October 22, when we released the Kerio MailServer 5.1.7.
For more information you can contact Kerio Technologies’ Technical Support Department (support@kerio.com).
]]>
Trude Janssen Wed, 06 Nov 2002 10:12:31 GMThttp://www.windowsitpro.com/article/webbased-services/multiple-vulnerabilities-exist-in-kerio-mailserver-5-0-for-windows-xp-2000-nt#commentsAnchor
Multiple Vulnerabilities in Microsoft Windows Media Playerhttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-microsoft-windows-media-player#commentsAnchorThu, 04 Jul 2002 04:27:31 GMT


I note that you include no comment regarding the change of EULA in this "security" patch. It includes the following statement:
"Digital Rights Management (Security).  You agree that in order to protect the integrity of content and software protected by digital rights management ("Secure Content"), Microsoft may provide security related updates to the OS Components that will be automatically downloaded onto your computer.  These security related updates may disable your ability to copy and/or play Secure Content and use other software on your computer.  If we provide such a security update, we will use reasonable efforts to post notices on a web site explaining the update."
Microsoft appears to be trying to sneak DRM in the back door, by masking the updates as part of security patches... A security patch should fix a vulnerability in software I am running, not introduce a measure which prevents me from doing what I want with MY hardware.
Attempting to play, or playing, "secured content" on a PC is not a security breach of that system. Why should a patch to prevent such activity merit inclusion in a security patch?>br> OTOH, at least they are good enough to say that their so-called "security" patches may break other software.
Regards, Alan.
]]>
Alan Crowe Thu, 04 Jul 2002 04:27:31 GMThttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-microsoft-windows-media-player#commentsAnchor
Multiple Vulnerabilities in Microsoft Windows Media Playerhttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-microsoft-windows-media-player#commentsAnchorWed, 03 Jul 2002 14:40:36 GMT


If you download the patch, up pops a supplemental EULA which says you agree to let Microsoft update your software later on, and which holds MS harmless from breaking other software if they do that.
Does anyone know how that would work if the clients are behind a firewall?
]]>
GeoffWed, 03 Jul 2002 14:40:36 GMThttp://www.windowsitpro.com/article/security/multiple-vulnerabilities-in-microsoft-windows-media-player#commentsAnchor
Multiple Vulnerabilities in Microsoft Excel, Office XP, and Wordhttp://www.windowsitpro.com/article/office/multiple-vulnerabilities-in-microsoft-excel-office-xp-and-word#commentsAnchorFri, 21 Jun 2002 11:26:23 GMT


On 20 June 2002: In Microsoft’s latest email: "Insider Update for Preferred Customers", they headline the following Top Insider Story:
"Online Homeland Security for Your Family Want to ensure a safe Internet experience for you and your children? You can rest easy when you utilize the latest security features built into Internet Explorer 6, Outlook(r) Express, and Windows(r) Messenger."
How can Microsoft do this with a straight face? Just look at today’s announcements re: NIMDA in .NET and the vulnerabilities listed in this article. Does anyone believe Microsoft is capable of providing "Online Homeland Security for Your Family"?
]]>
Lance Otis Fri, 21 Jun 2002 11:26:23 GMThttp://www.windowsitpro.com/article/office/multiple-vulnerabilities-in-microsoft-excel-office-xp-and-word#commentsAnchor
Buffer Overflow in Ipswitch's IMail Serverhttp://www.windowsitpro.com/article/email/buffer-overflow-in-ipswitch-s-imail-server#commentsAnchorWed, 05 Jun 2002 19:21:51 GMT


How about fix for older version? We do not have budget to upgrade IMail yet and expose to the vulnerability now.
]]>
Yen Wed, 05 Jun 2002 19:21:51 GMThttp://www.windowsitpro.com/article/email/buffer-overflow-in-ipswitch-s-imail-server#commentsAnchor
Denial of Service in Exchange 2000 Serverhttp://www.windowsitpro.com/article/exchange-2000-server/denial-of-service-in-exchange-2000-server#commentsAnchorMon, 03 Jun 2002 00:06:54 GMT


We are glad that Microsoft has released a patch for the security hole found in Exchange Server 2000. However, this patch won’t install in the Small Business Server 2000 where Exchange Server 2000 is integrated to.
]]>
Ken Huang Mon, 03 Jun 2002 00:06:54 GMThttp://www.windowsitpro.com/article/exchange-2000-server/denial-of-service-in-exchange-2000-server#commentsAnchor
Authentication Flaw in Windows Debuggerhttp://www.windowsitpro.com/article/windows-2000/authentication-flaw-in-windows-debugger#commentsAnchorWed, 29 May 2002 02:39:26 GMT


It is DebPloit dicovered by me on March 9th.
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0367
]]>
Radim Wed, 29 May 2002 02:39:26 GMThttp://www.windowsitpro.com/article/windows-2000/authentication-flaw-in-windows-debugger#commentsAnchor
Multiple Vulnerabilities in Microsoft Internet Explorerhttp://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer25246#commentsAnchorMon, 20 May 2002 14:57:59 GMT


DOES ANYONE KNOW IF PREVIOUS VERSIONS OF IE ARE VULNERABLE? IE 2.0 IE 4.01?
]]>
LUIS pALACIOS Mon, 20 May 2002 14:57:59 GMThttp://www.windowsitpro.com/article/internet/multiple-vulnerabilities-in-microsoft-internet-explorer25246#commentsAnchor
Denial of Service in Microsoft Directory Services Port 445http://www.windowsitpro.com/article/active-directory/denial-of-service-in-microsoft-directory-services-port-445#commentsAnchorThu, 02 May 2002 12:42:58 GMT


In this online article you have a link to two work arounds from Microsoft. This link points to Knowledge Base Article Q320751. In looking up that article Microsoft’s Knowledge Base returns the following message "The Knowledge Base (KB) Article You Requested is Currently Not Available"
Hmmm... any ideas on: 1. Why Microsoft has pulled the article and 2. how do I protect my environment?
Cheers, John.
]]>
John Holden Thu, 02 May 2002 12:42:58 GMThttp://www.windowsitpro.com/article/active-directory/denial-of-service-in-microsoft-directory-services-port-445#commentsAnchor