Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 10th, 2004, 11:30 AM
the mul's Avatar
the mul the mul is offline
Very Frequent Poster
 
Join Date: Jul 2003
Location: scotland
Posts: 1,709
Default Internet Explorer - 2 new critical vulnerabilities

This new bulletin advises to "Disable Active Scripting support for all but trusted web sites"

SA11793: Internet Explorer Local Resource Access and Cross-Zone Scripting Vulnerabilities

http://secunia.com/advisories/11793/


QUOTE
Secunia Advisory: SA11793
Release Date: 2004-06-08

Critical: Extremely critical

Impact: Security Bypass and System access

Two vulnerabilities have been reported in Internet Explorer, which in combination with other known issues can be exploited by malicious people to compromise a user's system.

1) A variant of the "Location:" local resource access vulnerability can be exploited via a specially crafted URL in the "Location:" HTTP header to open local files.

2) A cross-zone scripting error can be exploited to execute files in the "Local Machine" security zone.

Secunia has confirmed the vulnerabilities in a fully patched system with Internet Explorer 6.0. It has been reported that the preliminary SP2 prevents exploitation by denying access.

Successful exploitation requires that a user can be tricked into following a link or view a malicious HTML document. The vulnerabilities are actively being exploited in the wild to install adware on users' systems

Solution: Disable Active Scripting support for all but trusted web sites.


The Mul
__________________
OUTPOST BETA TESTER

WINDOWS 7 PRO 64 BIT, SP1, DUO CORE 2 OVERCLOCKED 3.4 GHZ 4 Gb PC6400 RAM 800MHZ
AVIRA ANTIVIRUS PREMIUM 2013 - Outpost PRO 8.0(4164.652.1856) - MBAM PRO V 1.70 - WINPATROL PLUS V 26.0 - HITMAN PRO 3.7.0
  #2  
Old June 10th, 2004, 11:57 AM
nadirah nadirah is offline
Massive Poster
 
Join Date: Oct 2003
Posts: 3,647
Default Re: Internet Explorer - 2 new critical vulnerabilities

Absolutely horrible, critical vulnerabilities again. When will all these critical vulnerabilities stop?
  #3  
Old June 10th, 2004, 04:07 PM
sig's Avatar
sig sig is offline
Frequent Poster
 
Join Date: Feb 2002
Posts: 716
Default Re: Internet Explorer - 2 new critical vulnerabilities

I was just reading this article linked to at BBR, it appears to be the same exploit. MS says it is working with law enforcement since it considers it an unlawful exploit and wants prosecution of the perps. Article here: http://news.com.com/IE+flaws+used+to...l?tag=nefd.top
  #4  
Old June 10th, 2004, 04:17 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,210
Default Re: Internet Explorer - 2 new critical vulnerabilities

Quote:
Originally Posted by sig
I was just reading this article linked to at BBR, it appears to be the same exploit. MS says it is working with law enforcement since it considers it an unlawful exploit and wants prosecution of the perps. Article here: http://news.com.com/IE+flaws+used+to...l?tag=nefd.top


In my mind, I think Microsoft wanted people to have fun on the Web with all the scripting, etc, built in to IE. Too bad the dark side wants to take advantage.

The hijack forum is full of unsuspecting people.

I'm sticking with Firefox.
  #5  
Old June 10th, 2004, 04:28 PM
sig's Avatar
sig sig is offline
Frequent Poster
 
Join Date: Feb 2002
Posts: 716
Default Re: Internet Explorer - 2 new critical vulnerabilities

I just happen to be running Opera lately myself. I lke the new version. I also like Firefox and IE. Although I'm not one of the MS bashers, I recently mentioned to someone else here that even when up to date with MS patches there are still unpatched known vulnerabilities in IE. And of course there are potential unknown vulnerablities such as this apparently was until now when an exploit is ITW.
  #6  
Old June 10th, 2004, 04:34 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,210
Default Re: Internet Explorer - 2 new critical vulnerabilities

Quote:
Originally Posted by sig
I just happen to be running Opera lately myself. I lke the new version. I also like Firefox and IE. Although I'm not one of the MS bashers, I recently mentioned to someone else here that even when up to date with MS patches there are still unpatched known vulnerabilities in IE. And of course there are potential unknown vulnerablities such as this apparently was until now when an exploit is ITW.


I can't bash Microsoft. They have provided me with many hours of fun and learning. (excluding DOS, of course )
  #7  
Old June 10th, 2004, 07:15 PM
JacK's Avatar
JacK JacK is offline
Frequent Poster
 
Join Date: Jun 2002
Location: Belgium -Liège
Posts: 737
Lightbulb Re: Internet Explorer - 2 new critical vulnerabilities

Hello,

The first one AdobeB.stream is know for months.

A simple work around is to set a kill bit on CLSID {00000566-0000-0010-8000-00AA006D2EA4} , easily done with SpywareBlaster or directly with REGEDIT :
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{00000566-0000-0010-8000-00AA006D2EA4}]
"Compatibility Flags"=dword:00000400 (hex)

No need either to disable Active Scripting in security zone Internet : just set the same parameters for the Intranet local zone as for the sensible sites zone.

Regards,

Jack

Back after a long time
  #8  
Old June 16th, 2004, 06:14 PM
the mul's Avatar
the mul the mul is offline
Very Frequent Poster
 
Join Date: Jul 2003
Location: scotland
Posts: 1,709
Default Re: Internet Explorer - 2 new critical vulnerabilities

IE flaws used to spread pop-up toolbar

http://news.com.com/IE+flaws+used+to...3-5229707.html

An adware purveyor has apparently used two previously unknown security flaws in Microsoft's Internet Explorer browser to install a toolbar on victims' computers that triggers pop-up ads, researchers said this week. On Tuesday, security information group Secunia released an advisory about the problem, rating the two flaws "extremely critical."

SA11793: IE Local Resource Access and Cross-Zone Scripting Vulnerabilities
http://secunia.com/advisories/11793/

Microsoft's Toulouse said Internet Explorer users could harden the software against such attacks by following instructions on the company's site. Other browsers available on Windows, such as Opera and Mozilla, do not contain the flaws.

Here are some additional Protective Recommendations from Microsoft:

http://www.microsoft.com/security/in.../settings.mspx

Another new IE trojan capitalizing on IE vulnerabilities

http://secunia.com/virus_information/10089/ject/

Download.Ject is a Trojan that attempts to download and install a file on a compromised system by exploiting a vulnerability in Internet Explorer. The Trojan is triggered by visiting a web site that contains the exploit code.


The Mul
__________________
OUTPOST BETA TESTER

WINDOWS 7 PRO 64 BIT, SP1, DUO CORE 2 OVERCLOCKED 3.4 GHZ 4 Gb PC6400 RAM 800MHZ
AVIRA ANTIVIRUS PREMIUM 2013 - Outpost PRO 8.0(4164.652.1856) - MBAM PRO V 1.70 - WINPATROL PLUS V 26.0 - HITMAN PRO 3.7.0
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:47 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums