Welcome to AppFail
You last visited: 2010-09-08
If you know of a site or app that has failed, tell us right away
via PBJ, via Twitter or via this contact form. If we use your submission we'll attribute and link back to you.
Keep your head above water by keeping on top of the latest failures. Follow us on Twitter or subscribe to our RSS feed
- appfail: RT @scaleengine: August Usage Statistics for ScaleEngine: Outgoing Bandwidth: 27.5TB, HTTP Requests Edge: 565M, CDN: 60M, Origin: 193M. ...
- appfail: It is @dhewlett birthday. Tweet #dGeek & #HappyBdayDavidHewlett to trend. #McKay 0wnz you and you know it.
- appfail: Password Security Misconceptions: http://bit.ly/cAk0F9
- appfail: The anatomy of a DoS attack http://bit.ly/bDLOYE
- appfail: @Miss604 The story about your website inspired me to write an article explaining the different types of DoS attack. http://appfail.com/178
Welcome to AppFail
Posted on 2009-07-06
ttackers compromised thousands of Web sites over the weekend to host code that exploits a previously unknown vulnerability in DirectShow, security experts said on Monday.The attacks, first reported by Danish security researchers at CSIS Security Group, use a flaw in the way that Microsoft's Windows operating system handles TV tuner requests through an ActiveX control.
"An attacker who successfully exploited this vulnerability could gain the same user rights as the local user," Microsoft stated in an advisory released on Monday. "When using Internet Explorer, code execution is remote and may not require any user intervention. We are aware of attacks attempting to exploit the vulnerability."
The code does not serve a useful purpose in Internet Explorer, so Microsoft recommended that users remove the ActiveX control from the browser.
A month ago, Microsoft warned of a different vulnerability in its DirectX multimedia library. A number of Chinese Web sites have posted the exploit for the code, according to the SANS Internet Storm Center.
Microsoft's advisory offers workarounds for the issue, including setting the killbit for the ActiveX control.
By: Michael Spencer
Cuiusvis hominis est errare; nullius nisi insipientis in errore perseverare - Any man can make a mistake; only a fool keeps making the same one.
Digg Proof Hosting
The key to surviving Digg and Slashdot is Infrastructure. You can't get it from a regular web host, it requires experience. The High Load Hosting Experts at ScaleEngine can make your site thrive, and avoid having your site featured on AppFail.
Cyber Security Alerts
- Mozilla Releases Firefox 3.6.9
- Apple Releases Safari 5.0.2 and 4.1.2
- Apple Releases iTunes 10
- Google Releases Chrome 6.0.472.53
- Insecure Loading of Dynamic Link Libraries in Windows Applications
- VMware Releases Updates for ESX Service Console Packages
- Cisco Releases Security Advisory for IOS XR Software Border Gateway Protocol
- RealNetworks Releases Update to Address Vulnerabilities in RealPlayer
Page Generated in 199ms