Computing.Net > Forums > Security and Virus > More on SP2 vulnerability

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

More on SP2 vulnerability

Reply to Message Icon

Original Message
Name: IronMan
Date: August 23, 2004 at 10:47:57 Pacific
Subject: More on SP2 vulnerability
OS: XP
CPU/Ram: P4 512MB
Comment:


This is additional information to a previous post, and was published in today's Register newsletter.
_______________________________________

XP SP2 über patch already needs fixing

By John Leyden

The first new vulnerability affecting Internet Explorer on Windows XP with SP2 has been discovered

The vulnerability allows malicious websites to place an executable file in a user's start-up folder when a user drags or clicks on a program masqueraded as an image. http-equiv of malware.com, a so-called White Hat hacker, has posted a sample exploit which demonstrates security weaknesses in the drag and drop function of IE that give rise to the exploit.

Even though this demo depends on the user performing a drag and drop event, it might be rewritten so a user need only perform a single click on an image instead, according to security firm Secunia.

The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP1/SP2. Users of IE 5.5 and 5.01 are also affected.

Secunia says the "highly critical" vuln could be exploited by attackers to obtain full system access to vulnerable systems. Microsoft has yet to issue a patch, but workarounds are available. Secunia advises users to disable Active Scripting or use an alternative browser to protect themselves from attack. ®


Report Offensive Message For Removal


Response Number 1
Name: Kevin The Tech Dude
Date: August 23, 2004 at 11:29:40 Pacific
Reply:

Just turn off Active Scripting and problem is solved. Not a biggie to worry about.

KTTD

Though I walk through the valley of Microsoft, I shall fear no OS for skills are with me


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home



Results for: More on SP2 vulnerability

virus alert!!!!!
    Summary: New Strain of Mass-Email Virus Poses Increased Risk September 19, 2003 Security vendors on Friday continued to issue alerts about a new mass-mailing virus, which has been identified as a variant of t...
www.computing.net/answers/security/virus-alert/6536.html

More on Google
    Summary: In the latest edition of the Spyware Weekly newsletter, the publisher had an overview of Google's microphone antics and a PDF link for a more detailed explanation of how it could work. He wrote: "The...
www.computing.net/answers/security/more-on-google/19416.html

Verifierbug not able to delete
    Summary: Rick, This is a Java exploit identified by virus scanners as a trojan because they do not have another catagory to slot them into. This thread @ Wilders joined by some of the top trojan program design...
www.computing.net/answers/security/verifierbug-not-able-to-delete/6525.html








Which MP3 player do you have?

iPod/iPhone
Zune
Something Else
None


View Results

Poll Finishes Today.
Discuss in The Lounge
Poll History






Data Recovery Software