Massimo Morelli's Weblog
A personal weblog on technology, science, books etc..






Subscribe to "Massimo Morelli's Weblog" in Radio UserLand.

Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.


Top 7 hits for semantic blog on..
Google
1.Semantic Web Blog , featuring RDF
2.webservices.xml.com: The Semantic Blog [Apr. 15, 2003]
3.XML.com: The Semantic Blog
4.webservices.xml.com: The Semantic Blog [Apr. 15, 2003]
5.webservices.xml.com: The Semantic Blog [Apr. 15, 2003]
6.webservices.xml.com: The Semantic Blog [Apr. 15, 2003]
7.webservices.xml.com: The Semantic Blog [Apr. 15, 2003]

Help link 27/04/2003; 15.44.25.


martedì 17 settembre 2002
 

In his last newsletter, Bruce Schneier explains (well) the last vulnerability found in word

Microsoft Word 97 Vulnerability

Here's the vulnerability. Alice sends Bob a Word document. Bob edits it and sends it back. Unbeknownst to Bob, the document he sends back can contain any file on his computer. All Alice has to know is the file's pathname.

To make the vulnerability work, Alice embeds a particular code in the Word document she sends Alice. When Bob opens the document, Word scarfs up the file off his hard drive and embeds it into the Word document. Bob can't see this happening, and he has no way of knowing it has happened. If he looks at the document in Notepad, though, he can see the snooped file. Then, when Bob saves the document, the file becomes part of the saved document. He sends it back to Alice, and she has successfully stolen the file.

This attack works with any file on Bob's computer, and any file on another server that Bob currently has access to. It's not a macro, so turning off macros doesn't help. It's not a piece of malware that an antivirus program will catch. It's just a feature of Word 97 being used in a novel way. And Alice can embed hundreds of these codes into the Word document she sends Bob, so if she doesn't know the exact filename she can make lots of guesses.

This is an enormous security hole, and one that the user is simply unable to close. All Bob can do is 1) refuse to return Word 97 documents he edits, or 2) manually examine them all in Notepad or WordPad.

Another Microsoft vulnerability...so what? There are hundreds of these a year. Why bother writing about it?

To me, the interesting aspect of this is that Microsoft is no longer supporting Word 97. This means the company has an interesting choice: they can patch the vulnerability, or they can demand that users upgrade to the latest version of Word. Doing the latter is sleazy, but it's in Microsoft's best interest for people to upgrade. They might think of this simply as added incentive.

We're seeing more and more of this: vulnerabilities in products that are no longer supported. When the SNMP vulnerabilities were published earlier this year, many products with the vulnerability were no longer supported. Some were made by companies no longer in business.

I first read about this vulnerability in an e-mail newsletter called "Woody's Office Watch." Alex Gantman reported the Word 97 vulnerability on Bugtraq, and Woody Leonhard claims that he has discovered similar vulnerabilities in Word 2000 and Word 2002. He's keeping them quiet for a while, giving Microsoft a chance to fix them.

<http://online.securityfocus.com/archive/1/289268>
<
http://www.woodyswatch.com/office/archtemplate.asp?v7-n42>
<http://makeashorterlink.com/?Z2C1218C1>


12:25:53 AM      comment []

It is always useful to annotate what Jon Udell find fascinating.

Application- and service-oriented architecture in Zope 3. Over at Industrie Toulouse, Jeffrey P Shell meditates on an issue I've long been fascinated by: the interaction between an application-oriented architecture (e.g., Zope's HTML aspect) and a service-oriented architecture (e.g., Zope's XML-RPC aspect): ... [Jon's Radio]


12:09:33 AM      comment []

Airborne copulators break diaper tables on Virgin jets. Virgin is going to retrofit the diaper tables in its jet lavatories because people use them to have sex on and then break them. Link Discuss [Boing Boing Blog]


12:04:46 AM      comment []


   Enter a City or US Zip:  


Click here to visit the Radio UserLand website. © Copyright 2003 Massimo Morelli.
Last update: 27/04/2003; 16.11.55.site index

Settembre 2002
Dom Lun Mar Mer Gio Ven Sab
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30          
Ago   Ott




currently subscribed to:
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. 4 banalitaten (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. >skip intro (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Aaron Swartz: The Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Appunti di viaggio (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Blogzilla - a blog about Mozilla (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Boing Boing Blog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Brodo Primordiale (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Business 2.0 - Technology (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Captain NEMO's Radio Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. CNET News.com (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Computerworld News (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Computerworld Security News (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Computerworld Shark Tank (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Curiouser and curiouser! (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Dictionary.com Word of the Day (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. dive into mark (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. dotcoma News (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Economist: Books (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Economist: Science (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Fed's Bolsoblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Google Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Jeremy Zawodny's blog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Jeroen Bekkers' Groove Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Jinn of Quality and Risk (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Joel on Software (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. John Burkhardt (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. John Robb's Radio Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Jon's Radio (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. kuro5hin.org (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. La finestra sul cortile [di Ermes] (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Lambda the Ultimate (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. manteblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. MerzLog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Mono Project News (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Network Games (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. neurologia.it (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. New Scientist (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. New York Times: Technology (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. notestips.com | articles and tips (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. ongoing (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Paolo Valdemarin: Paolo's Italian weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Paolo Valdemarin: Paolo's Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Philip Greenspun Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Quinto Stato (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Roland Piquepaille's Technology Trends (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. s l a m (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Sam Gentile's Blog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Sam Ruby (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Science Blog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. ScottGu's Blog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Scripting News (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Simone Bettini: simone.blogs.it (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Simplicissimus (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Slashdot (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. The FuzzyBlog! (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. the reverse cowgirl's blog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. theGNUeconomy (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Tom (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Tomalak's Realm (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Tony Bowden: Understanding Nothing (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Windley's Enterprise Computing Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Wired News (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. xmlhack (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Zope.org (rss)
Here's how this works.