Welcome Guest ( Log In | Register)



2 Pages V   1 2 >  
Reply to this topicStart new topic
> Latest Ie Exploit, does anyone still use this browser?
sandbox
post Nov 22 2005, 09:04 PM
Post #1


Advanced Member
*******

Group: Members
Posts: 107
Joined: 9-September 05
From: Houston, TX USA
Member No.: 11,651



For Internet Explorer users, please note that there is a new exploit in the wild that is capable of compromising a fully patched and updated WinXP machine:

http://www.eweek.com/article2/0,1759,18917...3119TX1K0000594

Microsoft has not released a fix yet. From the article:

QUOTE
IE users should immediately disable Active Scripting via the Tools > Internet Options > Security tab > Custom Level feature.

Firefox and other alternative web browsers are not affected. You would have to be tricked into going to a malicious website to have any chance of being affected by this one, so most folks are probably safe anyway, but I thought I would let everybody know.

For the curious, here's a proof of concept site that launches MScalculator when you visit their web page. Scary!

http://www.computerterrorism.com/research/ie/poc.htm
Go to the top of the page
 
+Quote Post
jlhaslip
post Nov 22 2005, 09:38 PM
Post #2


A computer once beat me at chess, but it was no match for me at kick boxing.
Group Icon

Group: [MODERATOR]
Posts: 4,071
Joined: 24-July 05
From: Linix, DOS and Windows…the good, the bad and the ugly
Member No.: 9,787
Spam Patrol



So does that mean to disable "javascript" if you are using IE? Or is Active Scripting different than js?
Go to the top of the page
 
+Quote Post
wariorpk
post Nov 22 2005, 09:51 PM
Post #3


Privileged Member
*********

Group: Members
Posts: 661
Joined: 18-April 05
Member No.: 5,852



It really bothers me how Internet Explorer has so many flaws. I mean they should take time to test it before releasing it to the general public. Its insane how it has been out for a few years and people are still finding exploits.
Go to the top of the page
 
+Quote Post
sandbox
post Nov 22 2005, 10:01 PM
Post #4


Advanced Member
*******

Group: Members
Posts: 107
Joined: 9-September 05
From: Houston, TX USA
Member No.: 11,651



Disabling active scripting will disable javascript. I'm not sure exactly what the difference is between the two. You can see the 'Active scripting' option in the 'custom level' area of the security tab in internet options:

user posted image


It's the top one in this image. Just set it to 'Disable'

Notice from BuffaloHELP:
Edited as reported.


This post has been edited by BuffaloHELP: Nov 22 2005, 10:38 PM
Go to the top of the page
 
+Quote Post
moogie
post Nov 23 2005, 02:00 AM
Post #5


Advanced Member
*******

Group: Members
Posts: 103
Joined: 23-September 05
From: Ontario Canada
Member No.: 12,186



This is really good information. Thank you.

I went to the ComputerTerrorism site and tried the test and yes it is scarey how well IE co-operates with the test. Not only that, it hung itself and stopped responding when I tried closing the test pop-up window. First I got the message that that program was not responding and then IE crashed.

I went into my security settings and disabled activeX scripting and ran the test again and.....nothing happened. Good!

However, ComputerTerrorists do go on to say that as long as you stay off potentially malicious websites, you won't have a problem. Yeah....right.

I forgot to add that my Calculator did not pop up. I was expecting it to.

Did I misunderstand?
Go to the top of the page
 
+Quote Post
sandbox
post Nov 23 2005, 02:49 AM
Post #6


Advanced Member
*******

Group: Members
Posts: 107
Joined: 9-September 05
From: Houston, TX USA
Member No.: 11,651



Yeah, it's supposed to pop up calculator. It comes up after the pop up does it's thing, so if ie crashed in the middle of it that's probably why you didn't see it.
Go to the top of the page
 
+Quote Post
DreamCore
post Nov 23 2005, 09:31 PM
Post #7


Premium Member
********

Group: Members
Posts: 199
Joined: 29-September 05
Member No.: 12,363



Nice thanks for that information. And the test like with an "javascript virus" is funny smile.gif

lol tought that Internet Explorer was almost 100% safe, anyway its not any big problem its just an little exploit and microsoft will soon deliver an patch to fic that problem.
Go to the top of the page
 
+Quote Post
Saint_Michael
post Nov 23 2005, 09:55 PM
Post #8


$p4m 0n j00 $h4m3 m3 0nc3 $p4m 0n m3 $h4m3 m3 7\/\/1c3
*********************

Group: [HOSTED]
Posts: 6,560
Joined: 21-September 04
From: 9r33|\| 399$ 4|\|D 5P4/\/\
Member No.: 1,218
T17 GFX Crew



well heres a question if you disable the javascript through your browser are you not going to have problems loading sites and um using certain features like post (fast reply) and what not.

of course you would have to be stupid to be tricked into going to a phony website through your email.

but its simple delete/block junk email and your find and don't go to websites you don't know about without researching it first.
Go to the top of the page
 
+Quote Post
seanooi
post Nov 25 2005, 06:11 AM
Post #9


Advanced Member
*******

Group: Members
Posts: 131
Joined: 22-November 05
Member No.: 14,730



Well, here's another obvious reason why current IE users should switch to FireFox laugh.gif

I used to use IE a few months ago, but it just keeps getting more annoying everytime i use it. In the end, i decided to reformat my computer, forget about IE and use FireFox. And up till now, FireFox has served me well. biggrin.gif