Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Acer puts Active X hole on laptops
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Credit Card Company's Help German Police. »
« D'Oh! Encrypted files, transfered, then reformated.  
AuthorAll Replies


Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC

reply to vircotto
Re: Acer puts Active X hole on laptops

said by vircotto See Profile :

NG,

Okay, you've confused me. (Really, not that hard to do!)

I'm pretty sure that LunchAPP.APlunch is the ActiveX control in question. I've found a site where on 11/19/06 Tan Chew Keong presented information:
»vuln.sg/acerlunchapp-en.html

He only tested on two Acer notebooks as that was all he had access to. He does provide some test code that launches calc.exe.

Also, I found this:
»nvd.nist.gov/nvd.cfm?cvename=CVE-2006-6121
Yup and I see all of the links out there about a lunchapp thingie all points to his info..or others who just linked to or copied his warning...BUT since I myself do not have one of those laptops..and since [LaunchApp] Alaunch is surely part of Acer stuff..I am trying to figure out myself if he just has a 'typo' in his write up..and he really mean Launch...or he did find a lunch and it is not even part of Acer stuff and might be a bad boy..so hope that someone who has an Acer laptop can really confirm it is lunch for the activeX..since to me that would be very strange.
--
Gladiator Security Forum »www.gladiator-antivirus.com/ Missing Kids »www.missingkids.com/


vircotto

join:2002-06-04
Illinois

reply to vircotto
NG,

Okay, you've confused me. (Really, not that hard to do!)

I'm pretty sure that LunchAPP.APlunch is the ActiveX control in question. I've found a site where on 11/19/06 Tan Chew Keong presented information:
»vuln.sg/acerlunchapp-en.html

He only tested on two Acer notebooks as that was all he had access to. He does provide some test code that launches calc.exe.

Also, I found this:
»nvd.nist.gov/nvd.cfm?cvename=CVE-2006-6121
Forums » Up and Running » Security » SecurityCredit Card Company's Help German Police. »
« D'Oh! Encrypted files, transfered, then reformated.  


Saturday, 05-Dec 04:24:50 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [145] Avast Antivirus Has Gone Mad
· [126] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [89] The Bandwidth Hog Does Not Exist
· [83] FCC Ponders Moving From PSTN To IP Voice
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [74] Sprint Defuses GPS Privacy Media Bomb
· [70] Baltimore To Ban Lazy Cable Installs
Most people now reading
· False positive in Avast! or is it real? [Security]
· Windows 7 boot manager editing questions [Microsoft Help]
· DNS options, what are YOU using? [TekSavvy]
· Evading throttling with uTP / uTorrent 1.9a [TekSavvy]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Maximizing Rogue DPS for 3.1 [World of Warcraft]
· [Snow Leopard] NFS Mounts - no more Directory Utility [All Things Macintosh]
· What to use while demonoid is down? [Filesharing Software]
· Farewell [Bell Canada]
· Google takes aim at browser redirection [Security]