Skip to Content

AOL Tech

exploit posts

Computers

Virus Exploits 'Excel' Security Hole to Infect Macs, PCs


Just about a week after a sweeping security hole was announced that affects most versions of Adobe Reader and Adobe Acrobat, software widely used by computers around the world, now we have news of a disconcerting security gap in another piece of popular software: Microsoft's Excel. The company is indicating that versions of the software dating back to Office 2000 are vulnerable to exploit, and a fix is not yet available.

Have you ever been the victim of a computer virus?



Versions of Excel included in Office 2000, 2002, 2003, 2004, 2007, and 2008 on the PC and Mac are vulnerable to an attack able to be hidden in .XLS files. The attack has been called Trojan.Mdropper.AC and has been found on a few infected computers, primarily in Japan. For infection to happen, users would have to manually open the corrupt Excel file, either as an attachment on an e-mail or downloaded from the Internet. Once the corrupt file is run, the attackers who distributed the files could take control of the user's machine, stealing passwords or using it for whatever purpose they like. Anti-virus software maker Symantec at least is now scanning for these files, and Microsoft is working on a fix, but it remains to be seen when it will be released. [From: CNET News]

Read more →

Computers

MacBook Air Hacked In Under Two Minutes

MacBook Air Hacked in Under Two Minutes

If there's one thing Apple users love to taunt Windows users about, it's security. Mac owners giddily flaunt their lack of virus scanners and lack of worries in front of their PC comrades, whose machines look comparatively bloated with virus scanners, firewalls, and daily patch updates to fix the exploit du jour. Bad news for those Mac users, then, as a recent hacking competition showed that the new MacBook Air is able to be completely compromised in under two minutes.

The hacker in question, Charlie Miller, achieved this feat as part of a hacking competition called PWN 2 OWN. Miller hosted a malicious Web page privately, accessed it from the MacBook Air, and then, within two minutes, was able to take full control of the machine remotely and make it do his bidding.The culprit here is apparently an undiscovered flaw in the Mac Web browser Safari, which has shown to be somewhat lacking in the security department on both the iPhone and on Windows.

Charlie won $10,000 for his troubles, and he got to keep the laptop, but as part of the deal, he was also required to keep secret about the details of exploit, so hopefully there's little chance of it getting into the wild and taking over Macs around the world.

Still, we'd recommend steering clear of Safari -- and perhaps not being so smug.

From Engadget

Related Links:

Computers

Security Flaw Affects Sony MicroVault Drives

Security Flaw Affects Sony MicroVault DrivesIf you use one of those Sony MicroVault USB drives with a built-in fingerprint reader, the extra security measures you're taking to protect your files may be doing more harm than good -- this according to Sony itself.

A security flaw, which affects three models of the company's MicroVault USB sticks, has been discovered that works by allowing hackers to bury malicious code and files in the hidden directory created by the fingerprint-reading software, which then makes them invisible to many virus scanning and security programs.

Though a third-party company developed the software that runs on the sticks, Sony has had problems with bad security software in the past – most notably in 2005 when it hid anti-piracy software on its music CDs that opened up the computers of more than a million users to attacks from hackers.

What can you do? Obviously, don't buy this product. Despite a recall, some of the tainted MicroVaults can still be found on the sites of many online retailers. If you already own one, hold off on using it until mid-September when Sony says it will release a downloadable fix, which we expect will show up on the official MicroVault support site.

From BBC

Related Links:

Switched Video

Follow Switched on Twitter

Deals of the Day

Latest Reviews from CNET.com

CNET provides the latest tech news, unbiased reviews, videos, podcasts, software, and downloads, making tech products easy to find, understand and use.

Top Product Reviews

  • Home Audio Reviews

    9.0 out of 10

    Definitive Technology BPX
    Works great with Dolby Pro Logic and Dolby Digital. Full Review

    9.0 out of 10

    Denon AVR-4306 (black)
    Incredibly well-featured 7.1-channel receiver; excellent sound quality; three HDMI inputs; converts analog video to HDMI output; upconverts analog video to 720p/1080i HD resolution; iPod and USB MP3 player connectivity; Internet radio and MP3/WMA streaming audio via built-in Ethernet port; XM Satellite Radio compatible; touch-screen remote; multizone, multisource operation; browser-based control via home network; accurate autocalibration routine. Full Review

    8.8 out of 10

    KEF KHT3005 (black)
    The KEF KHT-3005 is one compact, beautifully designed speaker package with solid aluminum satellites that feature unique driver technology to produce incredible clarity. Meanwhile, the equally astounding dual 10-inch, 250-watt powered subwoofer delivers ultradeep bass. Full Review

  • Cell Phone Reviews

    8.7 out of 10

    SignalBoost Mobile Professional Amplifier Kit
    The Mobile Professional Amplifier delivers a powerful signal boost to your cell phone. Also, it offers a compact design and easy setup. Full Review

    8.6 out of 10

    Wi-Ex zBoost YX510-PCS-CEL cell phone signal extender
    The Wi-Ex zBoost YX510-PCS-CEL significantly boosts your cell phone reception and is easy to operate. Also, it uses a wireless connection to your phone. Full Review

    8.3 out of 10

    LG VX6000 (Verizon Wireless)
    Compact and stylish; impressive battery life; solid audio quality; sharp color screen; built-in camera; USB ready; affordable. Full Review

  • Digital Camera Reviews

    9.3 out of 10

    Canon EOS 1D Mark III
    Extremely fast, 10-megapixel continuous shooting; very low noise; highly customizable; well-designed body with weather sealing; 3-inch LCD; abundant optional accessories. Full Review

    9.3 out of 10

    Nikon D3 (body only)
    Full-frame sensor; well designed, pro-level weather-sealed body; very low noise, even at extremely high ISOs; fast. Full Review

    9.0 out of 10

    Canon EOS-1Ds Mark III
    Very low noise, high quality images; 21.1 megapixels; live view shooting; pro-level build-quality and performance. Full Review

  • Desktop Reviews

    8.9 out of 10

    Velocity Micro Edge Z30 (Intel Core i7)
    Best value among midrange gaming PCs; Velocity Micro's consistently high build quality; compact case makes few sacrifices; second graphics card slot previously uncommon at this price. Full Review

    8.5 out of 10

    Apple iMac (24-inch, 2.8GHz)
    A minor specification update results in some significant performance gains; graphics upgrade an option on this 24-inch model; sleek, polished design didn't receive an update, but we won't start clamoring for a new design until the current one is at least 12 months old. Full Review

Featured Galleries

Nissan Land Glider
Vintage Keyboards
Retro Computer Logos
Vintage Computer Festival
Motorola CLIQ
iPod touch
iTunes 9
Video iPod Nano
The Beatles: Rock Band

 

Switched Desktop

Get the New Switched Desktop

Latest tech news, Switched mail, and more.

AOL Tech Network

Resources

Autoblog

Daily Finance

Download Squad

Engadget

Joystiq

Urlesque

Fanhouse Main

WalletPop

Gadling