bk99.de entertain the web since 1997

Blog 2002

11 posts

Projects, Linux, networks, systems, finds and internet standards from 2002.

Microsoft plugs security holes in Office Web Components

In August 2002 Microsoft reported three critical holes in Office Web Components 2000 and 2002, which were part of Office, Money, Project and several server products. Via the Host() function, a prepared web page could start Office programs and execute arbitrary commands, and two further holes exposed the clipboard and local files. The patch was already included in Service Pack 2 for Office XP.

Read the full post

Linux kernel 2.4.19 released

In August 2002 Marcelo Tosatti released Linux kernel 2.4.19, with better support for 64-bit processors such as Intel’s IA64, USB 2.0 and PCI hotplug. Above all, the version fixed bugs and improved drivers; Alan Cox published the variant 2.4.19-ac1 at the same time. Meanwhile the older 2.2 series and Linus Torvalds’ 2.5 development branch continued.

Read the full post

Novell’s NetWare full of security holes

At Black Hat 2002, Rain Forest Puppy presented numerous holes in NetWare 5.1 and 6.0 in the talk “Novell – The Forgotten OS”. Default installations could be crashed, NDS directory data read out and Perl scripts executed with system privileges. The recommendation was to remove the NetBasic, Perl and JSP handlers from the web servers until Novell delivered patches.

Read the full post

IBM: Linux and open source have changed society

At LinuxWorld 2002 in New York, IBM manager William M. Zeitler declared that Linux and open source would end the era in which vendors controlled customers through proprietary platforms. Zeitler saw grid computing as the next big open technology. The internet would change from a communication platform into a platform for computing power on demand.

Read the full post

IBM announces new servers specifically for Linux

In January 2002 IBM announced two servers designed specifically for Linux, including a mainframe developed in Böblingen that runs only Linux. For the first time it was not to require knowledge of classic mainframe operating systems such as z/OS. With z/VM virtualisation it was to replace between 20 and several hundred Unix or Intel servers.

Read the full post

Internet Explorer has a security hole in JavaScript

In January 2002 the Bulgarian security researcher Georgi Guninski published a hole in Internet Explorer through which JavaScript could read local files and start programs. The cause was an incorrect interpretation of the GetObject() function; the patched IE 6.0 and IE 5.5 SP2 under Windows 2000 were affected. According to Guninski, Microsoft had been informed three weeks earlier and had not responded.

Read the full post

Linux on the Xbox: opening a closed platform

The Xbox Linux team analyses the hardware and chain of trust of the first Xbox and shows how custom hardware and cryptographic mistakes made Linux on the console possible. Closed devices remain open to investigation when physical possession gives access to their interfaces. A security architecture is only as strong as its weakest implemented detail.

Read the full post