Wednesday, January 26, 2005

3Com 11g Vulnerability

Simple Web requests reveal admin user name, password, WEP key, and SSID: 3Com has fixed the glaring hole as of Jan. 19 based on an iDefense report that was provided to them in advance and released yesterday. 3Com users of the affected equipment are obviously advised to immediately update. It's unclear whether the URLs noted in the report are easily available over the Internet: a quick Google check using "inurl:" (looking for text in an URL) didn't spot any 3Com routers. It's likely that remote administration has to be enabled. [link via Frederick Wamsley, the expert behind Beryllium Sphere]...

Saturday, January 15, 2005

XInclude Is a W3C Recommendation

2004-12-20: The World Wide Web Consortium today released XML Inclusions (XInclude) Version 1.0 as a W3C Recommendation. Strengthening the XML family, XInclude provides a generic method for merging XML documents into a single composite document. It contributes to efficient content management at the enterprise level. XInclude uses existing XML constructs—elements, attributes and URI references. Read the press release and testimonials and visit the XML home page. (News archive)