[vox] And Yet Another Reason to Avoid Microsoft (YARAM)

R. Douglas Barbieri vox@lists.lugod.org
Sat, 06 Sep 2003 09:18:12 -0700


--=-5vUxvSVJjJzjVPBF4PGy
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

Big ugly URL:
http://www.computerweekly.com/articles/article.asp?liArticle
ID=3D124598&liArticleTypeID=3D1&liCategoryID=3D1&liChannelID=3D1&liF
lavourID=3D1&sSearch=3D&nPage=3D1

Nice compact URL:
http://tinyurl.com/mgot

Excerpt:

"Microsoft issues 'critical' Office security warning

Microsoft has warned of several flaws in its Office products, the most
serious of which could allow an attacker to take control of a user's
computer."

And here is the best part: "In addition, if Word is used as the e-mail
editor for Outlook, which is the default setting in Office XP/2002, an
attacker could strike via e-mail."

<rant on_soapbox=3D"doug">
That is so typical. The company ships stuff with vulnerable default
settings. They really should know better--office should ship with
VBscript support off by default--Word VB exploits are nothing new, M$
should know better. Besides, defaulting to Word as your editor email is
bad on top of all that. What's wrong with plain text?!
</rant>

--=20
R. Douglas Barbieri
doug@dooglio.net
http://www.dooglio.net

GPG Fingerprint : FE6A 6A57 2B95 7594 E534  BFEE 45F1 9E5E F30A 8A27
MIT.edu recv-key: F6368A3D
GPG Public key  : http://www.dooglio.net/dooglio.asc

--=-5vUxvSVJjJzjVPBF4PGy
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iQCVAwUAP1oIw0Xxnl7zCoonAQK9VwP/bDteGs2pUc3eVNqdWGLWtrYNI0B2kfZD
eA6m+UYbU35XaIyZQmEwCAXvvBvkEJ3kFn1jJoczeIiaMQLvioVEx1IhOrR7lL2j
o6u1kISTMMYXvAcldlepBnKbliJm1dTwshnd87Wdk4ZEfMHH+JZAmFhyz2ImGQVO
FRK0Ic5rqmY=
=pYNf
-----END PGP SIGNATURE-----

--=-5vUxvSVJjJzjVPBF4PGy--