Computing.Net > Forums > Security and Virus > More IE exploits

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

More IE exploits

Reply to Message Icon

Original Message
Name: IronMan
Date: June 11, 2004 at 10:19:50 Pacific
Subject: More IE exploits
OS: XP
CPU/Ram: P4 512MB
Comment:


Published in yesterday's Register newsletter.
_______________________________________

Unpatched IE vuln exploited by adware

By John Leyden

Detailed information on a brace of unpatched vulnerabilities in Internet Explorer has been posted onto a dull disclosure mailing list. The flaws involve a cross-zone scripting vuln and a bug in IE's Local Resource Access and pose an "extremely critical" risk to Windows users, according to security firm Secunia. The vulnerabilities affect both Internet Explorer 6 and Outlook.

Secunia has confirmed the vulnerabilities in a fully patched system with Internet Explorer 6.0. Improved security features in the XP SP2 reportedly block exploitation but users would be ill advised to rely on beta code for protection. SP2 doesn't help users of earlier versions of Windows who are also at risk.

The vulnerabilities are actively being exploited in the wild to install adware on users' systems, security researchers warn. Other exploits - include computer viruses - based on the same techniques of tricking users into visiting a maliciously constructed website housing malign script could follow.

Etienne Greeff, director at MIS Corporate Defence Solutions, said: "This is a very sophisticated exploit using encryption and stealth technologies to deliver its payload, using previously unknown vulnerabilities to work."

Windows users should disable Active Scripting support for all but trusted websites until Microsoft releases patches to address the vulnerabilities. The vulnerabilities were publicised by a Dutch 'white hat hacker' called Jelmer, who came across an example of an exploit of the flaws already in circulation last weekend. ®

Motor cooled down, heat went down, that's when I heard that reinstall sound


Report Offensive Message For Removal


Response Number 1
Name: CrazyOne
Date: June 11, 2004 at 14:34:21 Pacific
Reply:

IronMan,

Thanks for that, and some, do that already. Even for trusted sites ;-)

"Windows users should disable Active Scripting support for all but trusted websites until Microsoft releases patches to address the vulnerabilities."

CrazyOne


Report Offensive Follow Up For Removal

Response Number 2
Name: LUKE
Date: June 11, 2004 at 15:08:18 Pacific
Reply:

IE viruses,IE spyware,IE trojans,IE is a piece of junk.they money Billy boy makes he should start makin something a little better then IE.IN a matter of fact he should make a safer Os.People pay all this money for what?Stress,"OH!! Microsoft is a safe os".What a joke.There is 14,15 year olds that can easliy get past anything Microjunk has to offer.How can anyone stand behind microcrap that his main goal in life is to rule the world?His main goal is not your safety,if you believe this hogwash then your foolin yourself.How can anyone pay that Windows is the safest Os around.Pull up some history and archives, and you will see who is safe.People pay 200.00 for what?My car alarm is safer then windows and it cost me 150.00bux.And to top that it doest cost me a few hundred dollars a month on antidepressant pills.I have had linux for many many years without 1 virus,and spyware.and i dont have 50 security software installed on my pc to keep me safe from all that crap.People are paying big bucks for looks,and not for security.


Report Offensive Follow Up For Removal

Response Number 3
Name: Derek
Date: June 16, 2004 at 16:54:16 Pacific
Reply:

Jake

I eagerly await the software you produce which will do better than IE and Windows.

Derek.W


Report Offensive Follow Up For Removal

Response Number 4
Name: pkurczaba
Date: June 27, 2004 at 13:43:21 Pacific
Reply:

We have set up a dedicated forum regarding this topic. If you are interested, it can be found at: http://forums.kurczaba.com/forum_topics.asp?FID=11

Paul Kurczaba
Kurczaba Associates


Report Offensive Follow Up For Removal

Response Number 5
Name: Derek
Date: June 27, 2004 at 17:00:41 Pacific
Reply:

Thanks Paul Kurczaba. I've posted a new link to this.

Derek.W


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home



Results for: More IE exploits

virus alert!!!!!
    Summary: New Strain of Mass-Email Virus Poses Increased Risk September 19, 2003 Security vendors on Friday continued to issue alerts about a new mass-mailing virus, which has been identified as a variant of t...
www.computing.net/answers/security/virus-alert/6536.html

More IE vulnerabilities
    Summary: The following article appeared in this morning's Register newsletter. __________________________ Scripting flaws pose severe risk for IE users A set of five unpatched scripting vulnerabilities in Inte...
www.computing.net/answers/security/more-ie-vulnerabilities/7615.html

trojan trying to execute script? =(
    Summary: Might be relevent, been seeing a fair amount of verifier bug stuff lately. Of note, the site approvedlinks .com is a known pain associated with the CoolWebsearch highjacker. Message 3 in thread From:...
www.computing.net/answers/security/trojan-trying-to-execute-script-/6516.html








Which MP3 player do you have?

iPod/iPhone
Zune
Something Else
None


View Results

Poll Finishes Today.
Discuss in The Lounge
Poll History






Data Recovery Software