Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: [NTSEC] ActiveX, MSIE and Quicken
From: Adam Shostack <adam @ homeport . org>
Date: Sat, 1 Feb 1997 21:09:11 -0500 (EST)
To: Russ . Cooper @ RC . on . ca (Russ)
Cc: firewalls @ GreatCircle . COM, lists @ reflections . mindspring . com
In-reply-to: <41FDA823FC5AD011A0970000E8D5C667029335 @ mail . rc . on . ca> from Russ at "Jan 31, 97 07:04:44 am"

Russ wrote:
| 1. If the default IE implementation existed on the exploited machine,
| they were informed of the company name who signed the certificate, and
| were asked to confirm acceptance of the object. In which case, they
| chose to trust an untrustworthy company, why is that the fault of
| Activex?
| 
| 2. If they previously had told IE to accept all signed certificates,
| then they chose to leave their machine wide open, again, why is that
| ActiveX's fault?

	Lets say that the user is in class one, and makes a mistake.
	They've could have just accepted a malicious applet that
changes their IE config into class two.  Or perhaps it adds a trusted
CA.  (Or perhaps the attack is two pronged; the malicious code that
changes the config file is a word virus.)  There are subtle attacks.
ActiveX is bad technology because it does not offer mechanisms for an
organizations security officer to control what is happening in any
way other than turning it off.

Adam


-- 
Pet peeve of the day: Security companies whose protocols dare not
speak their name. Guilty company of the day is Security Dynamics.




Follow-Ups:
Indexed By Date Previous: Re: Sidewinder vs. Cyberguard
From: Jim Canfield <jcanfiel @ davocom . com>
Next: Re: [NTSEC] ActiveX, MSIE and Quicken
From: Todd Graham Lewis <lists @ reflections . mindspring . com>
Indexed By Thread Previous: Re: What is a virus? (long & off-topic)
From: harley @ icrf . icnet . uk
Next: Re: [NTSEC] ActiveX, MSIE and Quicken
From: Todd Graham Lewis <lists @ reflections . mindspring . com>

Google
 
Search Internet Search www.greatcircle.com