Zero Day IE Exploit?

Discussion in 'NOD32 version 2 Forum' started by Mannaggia, Mar 20, 2006.

Thread Status:
Not open for further replies.
  1. Elwood

    Elwood Registered Member

    Joined:
    Sep 12, 2005
    Posts:
    205
    Location:
    Mis'sippi
    Someone would have to pay me to use NAV, enough to buy another pc to put NOD32 on.

    I'm not saying it doesn't detect viruses, but there are plenty of (good) reasons for me not to use it.
     
  2. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Nice job De Hollander. Thanks
     
  3. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    Well, I think we are actually protected. ;)
    That page is just for testing but it doesn't contain a real exploit. Did something happened to your PC besides IE crashing?

    If the malware will be posted on another website by a hacker having some other "options" to hack you NOD will detect it. :) (Hmm..something tells me I was not clear enough :p)
     
  4. Brian N

    Brian N Registered Member

    Joined:
    Jul 7, 2005
    Posts:
    2,174
    Location:
    Denmark
    Nope nothing happended, and nothing happended with NOD either.. It was dead as a cold beef or something.
     
  5. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    that's cool...working in underground. :D
     
  6. Brian N

    Brian N Registered Member

    Joined:
    Jul 7, 2005
    Posts:
    2,174
    Location:
    Denmark
    Bah! you! bah! :D
     
  7. Brian N

    Brian N Registered Member

    Joined:
    Jul 7, 2005
    Posts:
    2,174
    Location:
    Denmark
    Still true
     
  8. Elwood

    Elwood Registered Member

    Joined:
    Sep 12, 2005
    Posts:
    205
    Location:
    Mis'sippi
    I hope you're not going to blame NOD32 whenever IE crashes from now on. ;)
     
  9. Brian N

    Brian N Registered Member

    Joined:
    Jul 7, 2005
    Posts:
    2,174
    Location:
    Denmark
    I don't use IE, so that's probably a no.
    But it would suck if I did ..
     
  10. Elwood

    Elwood Registered Member

    Joined:
    Sep 12, 2005
    Posts:
    205
    Location:
    Mis'sippi
    Back when I used it, seems like something was always happening to it.
     
  11. Brian N

    Brian N Registered Member

    Joined:
    Jul 7, 2005
    Posts:
    2,174
    Location:
    Denmark
    Well now I just think they are just super slow.
    Crashing my crap is not acceptable. Period.
     
  12. Elwood

    Elwood Registered Member

    Joined:
    Sep 12, 2005
    Posts:
    205
    Location:
    Mis'sippi
    Up until Firefox 1.5 was released, there was a javascript exploit that could crash Firefox every time if you let it continue to load the page long enough (you could not stop it through Firefox unless javascript was disabled before starting to load the page).

    AFAIK, there was no way to execute code via the aforementioned Gecko vulnerability.
     
  13. TradeMark

    TradeMark Registered Member

    Joined:
    Mar 19, 2006
    Posts:
    65
    so good to know that nod32 is protecting against this.
    I just test it with nod32 and it works just fine.
     
  14. De Hollander

    De Hollander Registered Member

    Joined:
    Sep 10, 2005
    Posts:
    718
    Location:
    Windmills and cows

    No prob...;)

    But, i still have a question o_O

    Was this a FP or a real virus....(TextRange[1].htm) :doubt:
     
  15. shanijee

    shanijee Registered Member

    Joined:
    Feb 1, 2006
    Posts:
    107
    Location:
    Faisalabad(Pakistan)
    now all will know the truth:eek:
     

    Attached Files:

    • ff.jpg
      ff.jpg
      File size:
      41.9 KB
      Views:
      290
  16. De Hollander

    De Hollander Registered Member

    Joined:
    Sep 10, 2005
    Posts:
    718
    Location:
    Windmills and cows
    ...are the users of Nod32 unprotected, yes or no :blink:

    Thank You.
     
  17. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    I don,t know but certainly an exploit. Anyone can explain?
     
  18. SSK

    SSK Registered Member

    Joined:
    Nov 28, 2004
    Posts:
    976
    Location:
    Amsterdam
    Could be that NOD is detecting real exploits, not the test versions?
     
  19. Detox

    Detox Retired Moderator

    Joined:
    Feb 9, 2002
    Posts:
    8,507
    Location:
    Texas, USA

    Wow, what software is that saying "deteced" anyway o_O
     
  20. mata7

    mata7 Registered Member

    Joined:
    Nov 8, 2005
    Posts:
    635
    Location:
    Mississauga, Canada
    what i don't understand is why no1 from eset show here and clarified this
     
  21. fosius

    fosius Registered Member

    Joined:
    Oct 14, 2004
    Posts:
    479
    Location:
    Partizanske, Slovakia
    Since your sample has probably very high priority, I would recommend you to send it to support@nod32.com or servis@eset.sk
     
  22. De Hollander

    De Hollander Registered Member

    Joined:
    Sep 10, 2005
    Posts:
    718
    Location:
    Windmills and cows
    I did, yesterday evening 19:12 local time. (Amsterdam) at samples@nod32.com Subject: Sample
    The file was encrypted (rar) with a password. "infected"
    But I will send it again right now, to support@nod32.com, with a link to this thread.
     
  23. beenthereb4

    beenthereb4 Registered Member

    Joined:
    Jun 29, 2004
    Posts:
    568
    The latest definitions actively block the crash and the exploit.

    *******End of story*****
     
  24. Elwood

    Elwood Registered Member

    Joined:
    Sep 12, 2005
    Posts:
    205
    Location:
    Mis'sippi
    Yes, we all know the truth now. :rolleyes:
     
  25. De Hollander

    De Hollander Registered Member

    Joined:
    Sep 10, 2005
    Posts:
    718
    Location:
    Windmills and cows

    Viewing the page, and IMON alerts..... JS/MBork.A trojan :cool:

    Scanning...TextRange[1].htm...and no alerts from Nod.
    IE6 SP2 , gives a alert and blocks the full viewing of the file.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.