Blogs
- Contributing Editor Stuart J. Johnston advises you on how to fix the latest problems affecting your operating system, your browser, your other software, and your hardware.
Subscribe to this blog
Bugs and Fixes
Microsoft recently announced that someone tricked VeriSign, the company that issues digital certificates, into granting two certificates to a person claiming to be a Microsoft employee. That's a bit like allowing someone to steal a police officer's badge--it puts the thief in a position of trust that he or she can abuse.
When you download a program off the Web, its digital certificate guarantees that it comes from the company it says it comes from. Using the stolen certificates, though, a cracker could send you a Trojan horse, a virus, or another nasty piece of code that presents itself as an officially approved Microsoft program.
Microsoft has released a security update to address the problem, and offers a link to the 128KB fix (along with a FAQ section discussing the security breach and related issues).
For Norton AntiVirus users, Symantec says that any virus definitions dated March 23, 2001, or later will detect the two stolen certificates. Similarly, McAfee users are protected with virus definition files dated March 24, 2001, or later.
Hole in Outlook, Outlook Express
Outlook 98, Outlook 2000, and Outlook Express 5.x have a security hole in their VCard capabilities. A VCard stores your business card information in an electronic format. In addition, it permits you to send your contact information to other users as an attachment that they can load into their Outlook and Outlook Express contacts databases--no typing required.
Though it's handy, the VCard technology has a bug that enables a malicious hacker to create a VCard that could crash the user's e-mail program or, worst case, let the attacker take over the user's computer. In this last instance, the bad guy could do anything the user had privileges to do, including reformat the hard drive.
The specific element responsible for this flaw ships as part of Outlook Express and is shared by Outlook. Since IE installs Outlook Express by default, identifying the correct patch for your PC depends on the version of IE you use, not on the version of Outlook you have, according to Microsoft. (To find out which version of IE runs on your system, from within IE select Help, About Internet Explorer.) The attack takes advantage of a buffer overflow error to flood the program with data. Envision a stoppered sink with the water left on. By sending the VCard feature too much info, the hacker can overwhelm Outlook or Outlook Express.
The patch turns off the flow by truncating the length of the character stream that the rigged VCard is trying to pour into the program.
- Page 1 of 3
- Next »
Print 50% more pages than with refilled inks. Trust Original HP Inks. Hit Print Reliably.
Solve Tech Issues Fast
The Best of PC World
Featured APC Accessories For Your System
10% Off Entire Cart at Online Store
-
APC Back-UPS ES
Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
- APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.
Focus on Personal Productivitysponsored by Microsoft
- Personal Finance 2.0 These free and fee-based Web services not only aggregate data from your online bank accounts, they give you tools for managing your money.
- High-Tech Travel Tips Plenty of stories provide advice for elite mobile professionals. But what about you, the unproductive traveler?
People who read this also read:
Best Prices on Antivirus Software
Norton AntiVirus 2009 (Full Product)Price: $14.85
VirusScan Plus 2009 - 3-User (Full Product)Price: $13.95
Anti-Virus 2009 (Full Product)Price: $17.95
VirusScan Plus 2009 (Full Product)Price: $12.27
McAfee VirusScan Plus 2008 (Full Product)Price: $6.85
Mcafee McAfee 2009 VirusScan Plus- 1 User Download Version (VSF09E001RKA)Price: $12.27
All PC World Blogs
- Free OCR Service Turns Image Files Into Text Who needs a scanner or special software when you can take a photo of a document and let this free service convert it to text?
- LexJongg MahJongg Game Treads Lightly on Your System's Resources Play Mahjonng using unusual graphic symbols, not ancient Chinese tiles, in this feature-light freeware game.
- EA Says Command & Conquer 4 Windows Exclusive Electronic Arts may have pulled Windows support for franchises like Madden and Tiger Woods, but the next Command & Conquer is strictly PC-bound.
- Google, Microsoft Invade Enemy Territory: Who Wins? It's a battle of tech titan vs. search giant, with each behemoth gunning for the other guy’s turf. Let's examine who might win, and why..
- Cisco Small Business Center Find out how to keep employees mobile, connected and productive with secure wireless networking.
- Dell Servers for Small Business Click here to see how a Dell server can help you back up your company's data and save you valuable time.





