On Tuesday a security researcher disclosed to Bugtraq a public newsgroup details of remote execution attacks on some models of Hewlett-Packard laptops. According to the researcher who is using the name "porkythepig," flaws in HPInfoDLL dll one of the ActiveX controls used within the HP Info Center could accept remote attackers to aim the laptop and also execute registry changes on the compromised machine.
The scenario within the disclosure suggests that an attacker could provoke a victim to a specially created Web site. When viewing the Web site in Internet Explorer the ActiveX control within the HP Info Center could be compromised. If the victim uses a browser other than Internet Explorer the browser would still call Internet Explorer to handle the ActiveX component on the specially created Web site.
Once a machine is compromised an attacker could then install malware change registry information in preparation for a more sophisticated contend use the machine in a denial-of-service contend on itself or another target or take sensitive data from documents on the compromised forge.
A list of potentially vulnerable HP laptop models can be open in the full disclosure posted on. To see whether your particular HP laptop is vulnerable the researcher also provided a (use this link at your own assay).
Posted in The Social by Caroline McCarthy April 7. 2008 9:01 PM PDT
MySpacehasunveiledthefullversionofitsbilingualMySpaceLatinohomepage,whichhasbeeninabetatestphasesincelastyearandincludescontentinbothSpanishandEnglish. Inconjunctionwiththelaunch,MySpaceadditionallyannounceddealswithanumberofcontentpartnerstokick-startnewintebe…
Virtualcomputingenvironmentsstillneedrealsecurity,andIBMsaysithastheanswer:"Phantom."ThecompanyissettooutlineatRSA2008onTuesdayanewresearchinitiativedesignedtoprotectagainstnewsecurityvulnerabilitiesthatarisewhenacorporationmovesfromaphysicalcomputingenvironmenttoa…
Posted in News Blog by Michael Kanellos April 7. 2008 9:00 PM PDT
IBM'slatestsupercomputerishookeduptothewatercooler. BigBluehascomeoutwithanewversionofitshigh-endsupercomputer,thePower575,whichcanprovidefivetimestheperformanceofitspredecessoron40percentofthepower. AfullystockedPower575rackcontains448…
Thebiggestnameincomputingisjoiningthegrowingmini-notebookfray. OnTuesday,Hewlett-PackardisexpectedtoofficiallyannouncetheavailabilityoftheMini-NotePC. Thedevicewillbeginshippingnextweek. YoumightrecognizeitastheHPCompaq2133,whichwastheinternalHPnamebackwhenearly…
Posted in News communicate by Stephen Shankland April 7. 2008 7:30 PM PDT
GoogleplanstolaunchaservicecalledAppEngineMondayeveningthatthecompanyhopeswillattractprogrammersandeventuallycompaniesneedinganexpandablefoundationforonlineapplications. AppEngine,freetothefirst10,000peoplewhosignup,offersacombinationofseveralonlineGoogleservicesforthose…
by Ina Fried A look at how technology is changing our lives and at the populate behind all that life-changing stuff.
by Charles Cooper Charles make weighs in on Silicon Valley hijinks and he doesn't suffer fools gladly.
by Robert Vamosi Covering the latest in computer viruses and computer crime.
by Daniel Terdiman At the tech grow nexus of video games blast art and virtual worlds.
by Tom Krazit Tom Krazit takes on the tech phenomenon that is Apple and keeps a close watch on the chip industry.
by Dan Farber When business and technology cater that's when things get interesting.
by Declan McCullagh Exploring the intersection of politics and technology.
by Caroline McCarthy Exploring all facets of social media and tech culture.
by Stephen Shankland Coverage of digital photography science and open-source software.
Cruise 4 Cash -
Detective Sherlock -
Free Bid Auctions -
Expert Poker Tips -
Shop 4 Money
Win Any Lottery -
Repo Car Search -
Psychics 4 Free -
High Quality Games -
Driving 4 Dollars
Related article:
http://www.news.com/8301-10784_3-9833007-7.html?part=rss&subj=news&tag=2547-1040_3-0-5
comments | Add comment | Report as Spam
|