lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: Fri, 2 Jul 2004 08:39:55 -0700
From: "Thor Larholm" <thor-ZXHyySWV5Wg@...lic.gmane.org>
To: "General DShield Discussion List" <list-js9DF5ScdFUR2m3UPm69cti2O/JbrIOy@...lic.gmane.org>
Cc: bugtraq-o7tR/nIX9Vi1EmJ4MpGYnQC/G2K4zDHf@...lic.gmane.org
Subject: Microsoft disables ADODB.Stream


If you are curious about what this configuration change might be, it is a
registry entry that sets the killbit on the ADODB.Stream ActiveX object. There
is a Knowledge Base article detailing how to manually implement this change and
there is a Critical Update available for download that accomplishes the same.

How to disable the ADODB.Stream object from Internet Explorer
http://support.microsoft.com/?kbid=870669

Critical Update for Microsoft Data Access Components - Disable ADODB.Stream
object from Internet Explorer (KB870669)
http://www.microsoft.com/downloads/details.aspx?FamilyID=4D056748-C538-46F6-B7C8-2FBFD0D237E3&DisplayLang=en

What You Should Know About Download.Ject
http://www.microsoft.com/security/incident/download_ject.mspx



Regards

Thor Larholm
Senior Security Researcher
PivX Solutions
23 Corporate Plaza #280
Newport Beach, CA 92660
http://www.pivx.com
thor-ZXHyySWV5Wg@...lic.gmane.org
Stock symbol: (PIVX.OB)
Phone: +1 (949) 231-8496
PGP: 0x5A276569
6BB1 B77F CB62 0D3D 5A82 C65D E1A4 157C 5A27 6569

PivX defines a new genre in Desktop Security: Proactive Threat Mitigation.
<http://www.pivx.com/qwikfix>

----- Original Message ----- 
From: "Paul Marsh" <pmarsh-Uw6xM9kCeDcdnm+yROfE0A@...lic.gmane.org>
To: "General DShield Discussion List" <list-js9DF5ScdFUR2m3UPm69cti2O/JbrIOy@...lic.gmane.org>
Sent: Friday, July 02, 2004 6:29 AM
Subject: [Dshield] Microsoft Statement Download.Ject Security Issue


>
> Microsoft Statement Regarding Configuration Change to Windows in
> Response to Download.Ject Security Issue
> http://www.microsoft.com/presspass/press/2004/jul04/07-02configchange.as
> p
> _______________________________________________
> list mailing list
> list-js9DF5ScdFUR2m3UPm69cti2O/JbrIOy@...lic.gmane.org
> To change your subscription options (or unsubscribe), see:
http://www.dshield.org/mailman/listinfo/list
>
>

_______________________________________________
list mailing list
list-js9DF5ScdFUR2m3UPm69cti2O/JbrIOy@...lic.gmane.org
To change your subscription options (or unsubscribe), see: http://www.dshield.org/mailman/listinfo/list


Powered by blists - more mailing lists