seattletim opened this issue on Apr 01, 2006 ยท 40 posts
j_g posted Sun, 02 April 2006 at 11:43 AM
Attached Link: http://www.codeproject.com/com/com_in_c1.asp
As a programmer who is quite familiar with what can be done via ActiveX (I've just started a new tutorial at Code Project about COM/ActiveX you can read at the above URL), it always amuses me when endusers take a cavalier attitude toward hacking. If you surf to a web site that even remotely seems like it has been hacked, or was constructed by a hacker, and you've got your internet security setting on medium (or have the site in your Trusted list, and worse, have given that site your credit card number at any time), and you think you have something to laugh about, then you're truly clueless. You don't even know what's out there, let alone realize that it has you in its sights. If I were an evil guy, what I'd do right now is put up a web page with my own malicious ActiveX component, and put a message here saying that I have a Poser freebie for download. Then when you all visited that page, my component would download its payload, use the WinInet API to search through your browser cache and cookies, and your email, looking for anything related to Poser sites that I personally know require a password and/or take credit card numbers, and email me back the info. I strongly suspect that a hacker could easily compromise the systems of a majority of people posting to this thread. It doesn't sound like many people posting here (aside from Tereesa) even know the first thing about hacking, let alone know how easy it is to do when you've got a target audience that is so cavalier about security. Seems like ripe pickings here. Hmmmmm... Naw, I'm not that evil. But given how well-received RuntimeDNA's joke was, I almost wish I was evil because hacking the computers of some of you would probably be easy and lucrative.