Most Popular Stories
Events
- IT360 Conference & Expo
April 7, 2010 — Toronto, Canada - Comptel PLUS
Mar 14-17, 2010 - AIIM Expo + Conference
April 20-22, 2010 — Philadelphia, PA - Healthcare IT Institute
May 2nd-4th — Atlanta, GA
Sponsored Links
HOT TOPICS >> Solid State Drives | IT Security | Open Source | ARM Processors | Google Chrome 4
INDUSTRY >> Healthcare | Government | Financial Services | Biotech | Compliance
Free Newsletter
Latest News
Popular Topics
Whitepapers
- How to Reduce Business Risks through Secure User Access for SAP?
- Protect Your Digital Assets with Full Disk Encryption
- The Value of Network Monitoring
- Practical Change Auditing for Virtual Environments
- Consumption-Based Fundamental Asset Allocation Redefines Investing -- Relevant Investing in a Post-Collapse Era
- The New Corporate Digital Leadership
Vista exploit: Annoying MySpace pages a threat?
It's only been a day since the first Vista patches were released and two days since the operating system was made available to the public. You know what that means: time for a vulnerability. ZDnet's George Ou reports that Vista's Speech Command feature leaves the OS open to malicious attack by--get this--sound files played back from a website that send commands to the OS. "I recorded a sound file that would engage speech command on Vista, then engaged the start button, and then I asked for the command prompt. When I played back the sound file with the speakers turned up loud, it actually engaged the speech command system and fired up the start menu," Ou wrote. "I had to try a few more times to get the audio recording quality high enough to get the exact commands I wanted but the shocking thing is that it worked! Anyone that's ever visited MySpace knows how many annoying webpages out there that will start blasting loud MP3 music as soon as they enter the page." The obvious workaround here is to disable Speech Command on user's machines. It remains to be seen, however, whether annoying MP3s of Panic! At the Disco can induce a kernel panic.
For more on the strange exploit:
- see Ou's blog entry at ZDnet
Related Article:
December Vista sales strong. Report
Related Stories
- Firefox 2/IE 7 animated cursor exploit on the way
- Patch Tuesday: Critical Vista, IE7 patches released
- Hackers exploiting unpatched Windows DNS bug
- Hackers respond to Patch Tuesday with exploits
- Windows XP SP3 in testing, coming in early 2008
- New Microsoft Word zero-day attack on the loose
- Zero-day bugs remain after Microsoft Patch Tuesday
- Microsoft addresses many bugs in this month's Patch Tuesday
- Symantec: Vista vulnerable to legacy exploits
- Windows flaw gets critical, patch coming tomorrow
Comments
Post new comment
Home
| Subscribe | Advertise | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe© 2009 FierceMarkets, Inc. All rights reserved. |
![]() |






