Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 9th, 2002, 08:41 PM
snowman
 
Posts: n/a
Default css block results


* * * * the following message if being didplayed on a on/off basis when I connect an my homepage dl's




* * * Why does this page look like this? *This page has been designed to work best with current browsers. *If you're seeing this message, you either have an older browser, or you have disabled CSS (Cascading Style Sheets) support in your browser. *You can continue using this browser, but you won't experience MSN at it's best. *Your experience may suffer, and the reliability and security of your information cannot be guaranteed



* * * * *my browser is current enough...but yes I have entered a block for css........I seem to recall that cascading style sheets can be exploited in some form or another...........I don't have the info on this at this time so can post more on that.

* * * *the block actually resulted after I noticed that I had two connection to <msn> whenever connecting.....
..the the first block I made result in a white page displaying a redirect being blocked......an the page went no where.....an I just moved on....

* * * *then I noticed something else....when viewing files in internet explorer........an ASHX file...ok, so whats a ASHX file?? * *so I blocked the <msn> site it came from...an now the above display if resulting....an I have only one connection to <msn> on connecting.....but I stress that this is not consistent.......the blocks are there but the results are now always the same.

* * * so, is this a <msn> call-home..........?


* * * for anyone interested the block was set on:

*(<wwx.msn.com/styles/css-site3>) * * *

* * * *the redirect that also has been blocked is:

* * (((((<link rel="stylesheet" type=yext/css>))))

* * * * the < at the beginning actually belongs there


* * * * I've no idea whats I am blocking here...but it seem to upset M$ so I like it........
  #2  
Old April 9th, 2002, 08:46 PM
snowman
 
Posts: n/a
Default Re: css block results



* * * *CAUTION:

* * * * one of the posted links above is live/active....I thought when posting that it would not be "live" but it is.

* * * * I clicled on the like...nothing appear...but my CPU says something went on.....careful here folks.....sorry for this mishap
  #3  
Old April 9th, 2002, 10:03 PM
FanJ
 
Posts: n/a
Default Re: css block results

Hi snowman,

the only thing I get there is this:

Quote:
Sorry, the page you're trying to reach is temporarily unavailable or the page may no longer exist. *
Please try one of the following:
Click your browser's Refresh button to try reconnecting.
Check the spelling of the URL to make sure the address is correct (capitalization and punctuation are important) and then click your browser's Refresh button.
Click your browser's Back button to return to the previous page.
*

Error type 404 - Object Not Found

But I'm using NIS-ad-blocking-feature, IE-SPYAD, HOSTS, IEClean.
Anyway, thanks for it, I just now blocked c.msn.com in HOSTS (long time ago I already did block c.microsoft.com ).
  #4  
Old April 9th, 2002, 11:35 PM
snowman
 
Posts: n/a
Default Re: css block results



* * * *FanJ

* * * *thank you for checking into to that link....I always worry about active links.


* * * *just blocking the <c.msn> did not complete work in my case......the entire url as posted above had to be blocked.....the first block I made was the same as the one you made......it still got through......the ASHX file still would show up again......

* * * hmmmmmm....when I click that link nothing shows....whatever page thats open at the time remains the same.
  #5  
Old April 10th, 2002, 08:19 PM
snowman
 
Posts: n/a
Default Re: css block results






* * * http://online.securityfocus.com/cgi-bin/vulns-item.pl?section=discussion&id=4411




* * * * the topic of this thread has now been discovered to be an exploit.........(hack)
  #6  
Old April 10th, 2002, 08:33 PM
snowman
 
Posts: n/a
Default Re: css block results




* * * * * nice to see that this exploit has been discovered.......


* * * * * so,,,,has M$ been/is using this means to to profile users.? * no accusation....food for thought.

* * * * * since placing the blocks I have not expereinced this problem again......


* * * *Paul and/or Mods


* * * * * * seing that this has been discovered....perhaps it would be a good idea to delete the active link to MS posted above.........your call guys.
  #7  
Old April 10th, 2002, 09:07 PM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re: css block results

snowman,

Quote:
Paul and/or Mods


* seing that this has been discovered....perhaps it would be a good idea to delete the active link to MS posted above.........your call guys.

Not deleted, but made into an inactive link (wwx). Thus, anyone who feels the need to visit the URL, can do so by altering the URL. Best of both worlds - I hope!

regards.

paul

__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #8  
Old April 10th, 2002, 09:30 PM
FanJ
 
Posts: n/a
Default Re: css block results

http://online.securityfocus.com/archive/1/265427

Quote:
Microsoft was first informed on 18 Feb 2002 (44 days ago), they have opened an investigation regarding this issue and will probably release a patch in the near future.

Until a patch becomes available the only workaround is to disable Active Scripting.
  #9  
Old April 10th, 2002, 10:48 PM
snowman
 
Posts: n/a
Default Re: css block results




* * * * *Paul

* * * * *thanking you kindly.........defintely I have managed "somehow" to block the exploit entirely at this particular time...will contiue monitoring..




* * * SPECIAL NOTE

* * * *disabling activeX *does not stop this exploit.
* * * *activeX has not been enabled on my computer for a
* * * *very long time......no zones have activeX enabled.

* * * *an yet obviously this exploit was able to load on
* * * *to my computer. * * if disabling activeX was the
* * * *solution...as stated by M$.....this exploit would
* * * *not have loaded onto my os.


* * * * this is posted as a pre-caution......other comments/
* * * * opinions welcomed.


* * * * * * * * * * * * *snowman


* * *
  #10  
Old April 10th, 2002, 10:55 PM
snowman
 
Posts: n/a
Default Re: css block results




* * * * am I mis-understanding something here......M$ is investigating this.......huh........css is needed/essential for the M$ homepage to load properly (as M$ would want/have it load)

* * * right now my homepage contains black letters/white background.........with css blocked.
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:25 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums