ActiveX security faces storm before calm


HD Moore is at it again.

Using a custom-built data fuzzing tool, the security researcher pinpointed more than 100 vulnerabilities in the ActiveX controls included with the default installation of Microsoft's Windows XP operating system. Data fuzzing tools combine knowledge of the input parameters accepted by a software package with a tenacious and systematic mangling of the data to discover how applications react to various permutations, whether valid or invalid.

Moore claims that, while he found more than 100 vulnerabilities in standard ActiveX components, almost another 100 exist in the ActiveX components installed by popular applications, such as Microsoft Office. ActiveX security faces storm before calm

Linked by shanmuga Tuesday, 1st August 2006 3:05AM