Re: [SC-L] State Department break-in last summer

2007-04-19 Thread Nick FitzGerald
Ed Reed wrote: > http://news.yahoo.com/s/ap/20070419/ap_on_hi_te/hackers_state_department > > This article describes a Trojan horse attack introduced via MS Office > (Word) documents that provided remote access by adversaries to > compromised systems. It doesn't say if t

Re: [SC-L] JavaScript Hijacking

2007-04-19 Thread Brian Chess
Frederik De Keukelaere <[EMAIL PROTECTED]> writes: > Would you mind sharing the different data formats you came across for > exchanging data in mashups/Web 2.0? Considering the challenges you > recently discovered, it might be good to have such an overview to look at > it from a security point of

[SC-L] State Department break-in last summer

2007-04-19 Thread Ed Reed
http://news.yahoo.com/s/ap/20070419/ap_on_hi_te/hackers_state_department This article describes a Trojan horse attack introduced via MS Office (Word) documents that provided remote access by adversaries to compromised systems. It doesn't say if the exploit - "design flaw" - wa