A paper has just been released on the Windows Vista's gadget API. The=20
abstract is as follows:
Windows has had the ability to embed HTML into it=E2=80=99s user interface =
for many=20
years. Right back to and including Windows NT 4.0, it has been possible to=
=20
embed HTML into the task bar, but the OS has always maintained a sandbox,=20
from which the HTML has been unable to escape. All this changes with Window=
s=20
Vista. This paper seeks to inform system administrators, users and the
wider community on both potential attack vectors using gadgets and the=20
mitigations provided by Windows Vista.
The full paper can be found at http://www.portcullis-security.com/165.php.
Cheers,
Tim
=2D-=20
Tim Brown
<mailto:tmb@65535.com>