|
Crawling Across Chaos and Time Without End
|
|
Dec
14
2008
The Problem with Microsoft and Oledb32.dllAnother day, another Microsoft security alert.. This morning, another raft of advisories arrived in my mail from Secunia, this is one; This rivetting title is like deja-vu. Time and again we’ve seen this. This is the fault of a company, Microsoft, that puts form before function, functionality before security. Yet again, the core problem stems from years back when Microsoft had the bright idea to get everything linked together, like the internet is now, but different. The key is the method of linking. When you connect to a web page, like this one, you connect, when you decide you want to. Microsoft, unfortunately, have everything set up as they originally envisaged it, that is, everything is permanently connected to everything else! And that’s the problem! If you have Visual Studio, say 2008, as I have, when web applications are constructed, one of the key things you’ll notice is the data-binding going on. The wizards and the help system are all permanently geared to doing this!
This latest problem hangs around OLEDB32.dll In M$ shorthand, this stands for “Object Linking and Embedding Data Base 32-bit Dynamic Linked Library” There we have it, Linking & Embedding. This is wonderful technology for putting spreadsheets in Word documents within the corporate offfice environment. However, when passing secure information over unsecured internet lines, it’s not! Of couse, you can delete oledb32.dll, but then you cannot access any data….doh! Despite the continuous obvious failings of this methodology, just listen to the sanctimonious obfuscatory speech in their “Security Advisory” here: Microsoft Security Advisory (961051): Vulnerability in Internet Explorer Could Allow Remote Code Execution
Basically, this means all their current operating systems and browsers! Not “only”….
Well that’s what’s wrong. So what are Microsoft going to do, I can hear you asking? It’s their software design, after all?
So Microsoft is looking, and if it gets worse they’ll let us know!!! Let’s have the final word on this from the Secunia Advisory;
We all bought into the “Welcome to Microsoft” world. We are all fully patched. Caveat Emptor. Amazon Related:
Related Posts by TagsImprove the web with Nofollow Reciprocity.
|
© 2007-2010 Strangely Perfect All Rights Reserved
Strangely Perfect is Digg proof thanks to caching by WP Super Cache
[...] digg_title = ‘Oledb32.dll and IE7 – it’s getting Massively Worse!’; In a follow-up to my earlier post, this problem is now going mainstream news. [...]
Like or Dislike:
0
0