PC Review


Reply
Thread Tools Rate Thread

Why gadgets have earned a bad reputation

 
 
Captain Crunchie, Retired
muckshifter's Avatar
Join Date: Mar 2002
Location: In a Hovel
Posts: 20,956
 
      19th Jul 2012
Gadgets are little snippets of HTML code that work with few rules and no security sandboxing. That's an open invitation to malicious hackers looking for unguarded entries into Windows.

Although the vulnerability in gadgets has existed for years, two security researchers are shedding some new light on the threat. At next week's annual hacker gathering in Las Vegas — Black Hat USA 2012 (more info) — Mickey Shkatov and Toby Kohlenberg will deliver their presentation, "We have you by the gadgets."

Much to their credit, Shkatov and Kohlenberg have been in talks with Microsoft, apparently divulging some of their findings. (The point of Black Hat is to reveal detailed information on how new security exploits work, thus pushing software developers into rapidly patching their code.) I can imagine the security folks at Microsoft saying, "These guys have us nailed." (Some of the MSRC folks might have said something considerably less printable.) The result is MS Security Advisory 2719662, which states, "Customers who are concerned about vulnerable or malicious gadgets should apply the automated Fix It solution as soon as possible"

Full Story

Microsoft invented a poison pill, disguised as a fixit in MS Support article 2719962. You’ll find two Fix it buttons halfway down the page: one to disable the Sidebar and gadgets, and another to enable them (which might be useful if Microsoft provides an actual patch for the vulnerability).

Direct link to the fix in the full story.



 
 
Reply With Quote
 
 
 
Reply

« MacBug | Jumpshot »
Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Gadgets icons disappear soon after opening the 'add gadgets' box. Monica CS Windows Vista General Discussion 0 25th May 2008 06:23 PM
Vista to face the same reputation as Millenium? DigitalBlade Windows Vista General Discussion 25 25th Apr 2007 04:22 AM
findcontrol("PlaceHolderPrice") why why why why why why why why why why why Mr. SweatyFinger Microsoft ASP .NET 2 2nd Dec 2006 04:46 PM
so what is the deal with maxtor's bad reputation ??? Lorenzo Sandini Storage Devices 48 21st Feb 2006 04:23 PM
Do Acer Monitors have a bad reputation? Interesting Ian DIY PC 12 12th Jul 2005 05:42 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 12:28 PM.