http://isc.sans.org/diary.html?storyid=6778
and
http://blog.security4all.be/2009/07/active-exploitation-of-office-web.html
this one has been known for 1+ year by microsoft as can be seen http://www.liquidmatrix.org/blog/2009/07/12/microsoft-knew-about-ie-bug-for-a-year/
:sigh:
I'm going to buy an abacus.
just to make you happier looks like ev ssl has got owned as well http://www.darkreading.com/security/app-security/showArticle.jhtml;jsessionid=2U15XCAWKUKKEQSNDLOSKHSCJUNN2JVN?articleID=218500176
crazy week. Normally is though with the hacker cons approaching though.
Thanks, So, I wonder how much longer it will be reasonably safe to use the 'net? I can foresee banking, for example, moving back to private networks to minimise the risks.
the sooner the credit card with the secureid on the front comes out the better.
How long do you think it would survive uncracked?
i think a long time tbh. Secureid/rsa is solid as long as it has been implemented properly and the standards have been adhered to.
Let's hope you're right, So, the present system seems like a leaky sieve. :(