Latest Ie Exploit - does anyone still use this browser?

Pages: 1, 2
free web hosting
Open Discussion > CONTRIBUTE > Computers > Computer Security Issues & Exploits

Latest Ie Exploit - does anyone still use this browser?

sandbox
For Internet Explorer users, please note that there is a new exploit in the wild that is capable of compromising a fully patched and updated WinXP machine:

http://www.eweek.com/article2/0,1759,18917...3119TX1K0000594

Microsoft has not released a fix yet. From the article:

QUOTE
IE users should immediately disable Active Scripting via the Tools > Internet Options > Security tab > Custom Level feature.

Firefox and other alternative web browsers are not affected. You would have to be tricked into going to a malicious website to have any chance of being affected by this one, so most folks are probably safe anyway, but I thought I would let everybody know.

For the curious, here's a proof of concept site that launches MScalculator when you visit their web page. Scary!

http://www.computerterrorism.com/research/ie/poc.htm

 

 

 


Reply

jlhaslip
So does that mean to disable "javascript" if you are using IE? Or is Active Scripting different than js?

Reply

wariorpk
It really bothers me how Internet Explorer has so many flaws. I mean they should take time to test it before releasing it to the general public. Its insane how it has been out for a few years and people are still finding exploits.

Reply

sandbox
Disabling active scripting will disable javascript. I'm not sure exactly what the difference is between the two. You can see the 'Active scripting' option in the 'custom level' area of the security tab in internet options:

user posted image


It's the top one in this image. Just set it to 'Disable'

Notice from BuffaloHELP:
Edited as reported.

Reply

moogie
This is really good information. Thank you.

I went to the ComputerTerrorism site and tried the test and yes it is scarey how well IE co-operates with the test. Not only that, it hung itself and stopped responding when I tried closing the test pop-up window. First I got the message that that program was not responding and then IE crashed.

I went into my security settings and disabled activeX scripting and ran the test again and.....nothing happened. Good!

However, ComputerTerrorists do go on to say that as long as you stay off potentially malicious websites, you won't have a problem. Yeah....right.

I forgot to add that my Calculator did not pop up. I was expecting it to.

Did I misunderstand?

Reply

sandbox
Yeah, it's supposed to pop up calculator. It comes up after the pop up does it's thing, so if ie crashed in the middle of it that's probably why you didn't see it.

Reply

DreamCore
Nice thanks for that information. And the test like with an "javascript virus" is funny smile.gif

lol tought that Internet Explorer was almost 100% safe, anyway its not any big problem its just an little exploit and microsoft will soon deliver an patch to fic that problem.

Reply

Saint_Michael
well heres a question if you disable the javascript through your browser are you not going to have problems loading sites and um using certain features like post (fast reply) and what not.

of course you would have to be stupid to be tricked into going to a phony website through your email.

but its simple delete/block junk email and your find and don't go to websites you don't know about without researching it first.

Reply

seanooi
Well, here's another obvious reason why current IE users should switch to FireFox laugh.gif

I used to use IE a few months ago, but it just keeps getting more annoying everytime i use it. In the end, i decided to reformat my computer, forget about IE and use FireFox. And up till now, FireFox has served me well. biggrin.gif

Reply

truefusion
I disabled active scripting, but that made my Mcafee virus scanner stop working. So, i advise not to disable, but to "prompt". Good thing i have more than one virus scanner, eh?

Reply



Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

(Maximum characters: 10,000)
You have characters left.

Pages: 1, 2
Recent Queries:-
  1. searchathand.com keeps loading - 813.10 hr back. (1)
Similar Topics

Keywords : latest exploit browser

  1. Another New Exploit And One A Few Weeks Ago, We Are All At Risk From These - A DNS exploit and a clipboard expload believe it or not! (0)
  2. DNS Hijack SearchAtHand.com Browser Result Removal - this is a browser hijack and method of removing (6)
    Recently, I don't know when, I realized that my browser was opening some weird pages. It would
    either open to what it seemed to be a valid webpage but it always looked the same. But the contents
    will be text only but always with adult related links... so I was curious but never paid any
    attention since these pages were coming up only when I mistyped an URL address. But the pages
    popped up were always the same and it got me curious. So I started to click on refersh and see how
    far it will lead. At the end, it led to a site called "SearchAtHand.com" After few minutes ...
  3. Cpanel Exploit - security hole in cPanel to hack the servers of a hosting company (8)
    A pair days ago I read this new on Slashdot: cPanel Exploit Used to Circulate IE Exploit
    QUOTE "In a dangerous combination of unpatched exploits, hackers have used a previously
    undiscovered security hole in cPanel to hack the servers of a hosting company and use hundreds of
    hijacked sites to infect Internet Explorer users with malware using the unpatched VML exploit.
    cPanel, whose hosting automation software is used by many large hosting companies, has issued a fix.
    It's a local exploit, meaning the attacker must control a cPanel account on the target hosti...
  4. Is There An Exploit In Vista Home Premium To Make Firefox Permanant Default Browser? - (4)
    I just got a new laptop, and of course it's loaded with vista. Everything works awesomly!
    (my last PC was from 2001, BIG DIFF.) But the damned thing compulsivly and automatically sets
    Internet Explorer to my default browser and won't let me change certain things which browsers
    will typically handle. 've manually changed it so Firefox handles all the stuff except HTTPS
    and what not (CANNOT CHANGE W/O HACK!), but IE just bumps in every time I want to click a link
    from a non-browser based file /sad.gif" style="vertical-align:middle" emoid=":(" border="...
  5. Quicktime Zero Day Exploit News And Updates - (1)
    On monday it was reported that Quicktime 7.2 and 7.3 versions come with a new exploit in which
    malware could on to a person's computer through streaming videos. They only mention that XP and
    Vista are the only affect systems and no word came about on the Mac operating system. They mention
    that a buffer overflow bug was made in which it "contains a stack buffer overflow vulnerability in
    the way Quicktime handles the RTSP Content-Type header." For those who don't know what RTSP is,
    RTSP is the Real-Time Streaming Protocol which apple uses for its QuickTime softw...
  6. Zero-day Firefox Exploit - (5)
    Link to Article: http://news.com.com/Hackers+claim+zero-day..._3-6121608.html Thought this was
    interesting. Really caught me offgaurd, didn't expect such a huge flaw on a GPL based program.
    Whats even more scary is they said they have about 30 other flaws found......
  7. Attention All Ipb Users/admin - Important exploit discovered! (6)
    Invision Power Board v2.1.6 © 2006 IPS, Inc. This is what it is written on the bottom of the
    board. Not so long ago, i was surfing somewhere, (i wont say where) and i discovered a "sql
    injection"exploit, a perl script. QUOTE(step28 in the hack) 28. Reload and click on the
    username to the admin. You are now logged in as an ADMIN!!! Admins, pm to receive
    the link where i found this. with this hack, you can log in with any user without his pass.
    It's really easy to do, you just need PERL, Opera webbrowser and 3 minutes fo your life... ...
  8. Windows Xp Pro Exploit: Permission Setup Allows Access To Task Manager During Login - even if permissions deny this abiltity. (1)
    A friend of mine was temporarily banned from the computers at my school a while ago after he
    accidentially found a way into Task Manager, which is disabled on our network. He has had his
    permissions restored now, but has no idea why he got banned in the first place. However, recently he
    explained what he did to me, and I tested it. I soon found out that, by accident, we had both
    discovered that there is a Security Exploit in networking Windows XP Professional. The exploit is
    to do with network permissions. Windows XP recieves the permission data from the network as soon...
  9. Browser Spy - BrowserSpy can tell you all kinds of detailed information about you an (1)
    /smile.gif" style="vertical-align:middle" emoid=":)" border="0" alt="smile.gif" /> Browser Spy
    -------------------------- Wow, this makes me feel rather exposed..... a browser spy that can find
    countless little bits of information, I'm sure something evil could be devised out of this.
    And it's also not even one of those things that work only in IE (except for some of the
    features). Take a look Browser Spy /cool.gif" style="vertical-align:middle" emoid="B)"
    border="0" alt="cool.gif" /> have a nice day! ...
  10. Firefox Exploit - (0)
    QUOTE Earlier this week, I blogged about a site doing a bunch of different exploits, depending
    on what you are running. One of the things the site will do is detect if you have Firefox, and
    attempt to exploit it, using the InstallVersion.compareTo() vulnerability. Read More with
    images Already found to be copying and pasting. Take this time to review our forum rules. Warning.
    ...
  11. Firefox's Answer To Ie's Phishing Filter? - users of the sacred browser can breathe once more! (5)
    SiteAdvisor - Firefox's Answer To IE's Phishing Filter? A site-warning plugin
    for ie and firefox Name: Site Advisor Url: http://siteadvisor.com Download:
    http://www.siteadvisor.com/download/ff.html Rating: 9.75/10 Improvements: Not all sites are on
    their database but many of the popular ones are so index all webistes. SiteAdvisor is a simple and
    easy to install extension created for firefox which checks to see if the site you are on is "bad"
    from its database of urls. Once the results have reached your browser a notificatio...
  12. Nyxem E - Be Safe From This Virus/worm - Latest Mass Mailing Worm (14)
    QUOTE Windows users are being urged to scan their computers before 3rd February 2006 to avoid
    falling victim to a destructive Worm. On that date the Nyxem E Worm is set to delete Word,
    Powerpoint, Excel and Acrobat files on infected machines! Don't get caught out... See
    complete article at http://www.updatexp.com/nyxem-e.html Better get your anti-virus updated by
    3rd Febuary before seeing your files go missing. It's kindda scary worm if not handled properly.
    The date is near so get updated fast. Edited topic title. ...
  13. Serious Wmf Windows Exploit - No-one is safe right now (16)
    This has blown up big time in the last 3 days: http://www.f-secure.com/weblog/ ...
  14. Web Browser - Which Browser do you use? (2)
    Which web browser do you use? Personally, I use Firefox 1.5. Firefox is from a trusted provider,
    Mozilla. For more information on Mozilla, and if you want to download Firefox for your own computer,
    visit either Mozilla.com or Mozilla.org. If you do not want to remember Mozilla, you can visit their
    newly-obtained domain, firefox.com. You? Stephen...
  15. [exploit] Cpanel Versions Below And Equal To 9x - (7)
    Exploit for cPanel versions below and equal to 9x that takes advantage of a remote command execution
    vulnerability. /* cPanel */ //headers #include //In/Out #include //sockets functions
    #include //memory functions #include //strlen,strcat,strcpy #pragma comment(lib,"ws2_32.lib")
    //for compile with dev-c++ link to "libws2_32.lib" #define Port 2082 //port for connect to cPanel
    #define SIZE 1024 //buffer size to receive the data /*connect host:port*/ SOCKET Conecta(char
    *Host, short puerto) { /*struct for make the socket*/ WSADATA wsaData; SOCKET Winsock;//l...
  16. Online Scams Exploit Katrina Disaster - (10)
    In the wake of hurricane Katrina, several online scams have begun to circulate the Internet,
    according to several security firms. Sophos warned users on Thursday not to open a malware-Infected
    e-mail posing as news on the disaster. Possible subject lines of the e-mail could be QUOTE
    "Re: g8 Tropical storm flooded New Orleans", "Re: g7 80 percent of our city underwater", and "Re:
    q1 Katrina killed as many as 80 people". The group said there could be additional variants.
    BetaNews on Thursday morning had received a variant of the above e-mails, however it app...
  17. [exploit] Microsoft Windows 2000 Plug And Play - (1)
    Microsoft Windows 2000 Plug and Play Universal Remote Exploit #2 (MS05-039) /*
    HOD-ms05039-pnp-expl.c: 2005-08-10: PUBLIC v.0.2 * * Copyright © 2005 houseofdabus. * * (MS05-039)
    Microsoft Windows Plug-and-Play Service Remote Overflow * Universal Exploit + no crash shellcode * *
    .:: ::. * * --------------------------------------------------------------------- * Description: * A
    remote code execution and local elevation of privilege * vulnerability exists in Plug and Play that
    could allow an * attacker who successfully exploited this vulnerability to take * complete con...
  18. [exploit] Phpbb <=2.0.12 Vulnerability. - How to be Admin on phpBB in Simple steps (2)
    Another vulnerability in PHPbb based forums that can be used to easily gain any user level access to
    the forum. Even the admin account is not not secure with the default setup. Click Here for more
    details about -"How to be Admin on phpBB in Simple steps!" And here is the Homepage of
    PHPbb and click here to download the latest version....
  19. [exploit] Phpbb 2.0.15 "viewtopic.php" - Remote PHP Code Execution Exploit (3)
    phpBB 2.0.15 "viewtopic.php" Remote PHP Code Execution Exploit #!/usr/bin/pyth0n print
    "\nphpBB 2.0.15 arbitrary command execution eXploit" print " 2005 by rattle@awarenetwork.org"
    print " well, just because there is none." import sys from urllib2 import Request, urlopen from
    urlparse import urlparse, urlunparse from urllib import quote as quote_plus INITTAG = ' '
    ENDTAG = ' ' def makecmd(cmd): return reduce(lambda x,y: x+'.chr(%d)'%ord(y),cmd
    ,'chr(%d)'%ord(cmd )) _ex = "%sviewtopic.php?t=%s&highlight=%%27." _ex += ...
  20. [exploit] Microsoft Server Message Block - (SMB) Remote Exploit (MS05-011) (0)
    Microsoft Server Message Block (SMB) Remote Exploit (MS05-011) /* * Windows SMB Client
    Transaction Response Handling * * MS05-011 * CAN-2005-0045 * * This works against Win2k * *
    cybertronic gmx net * http://www.livejournal.com/users/cybertronic/ * * usage: * gcc -o mssmb_poc
    mssmb_poc.c * ./mssmb_poc * * connect via \\ip * and hit the netbios folder! * *
    ***STOP: 0x00000050 (0xF115B000,0x00000001,0xFAF24690, * 0x00000000) * PAGE_FAULT_IN_NONPAGED_AREA *
    * The Client reboots immediately * * Technical Details: * ----------------- * * The driver MRXSMB.S...
  21. [exploit] Microsoft Internet Explorer Com Objects - File Download Exploit (MS05-038) (0)
    Microsoft Internet Explorer COM Objects File Download Exploit (MS05-038)
    /*+++++++++++++++++++++++++++++++++++++++++++++++ Ms05 038 exploit POC Write By ZwelL 2005 8 11
    http://www.donews.net/zwell zwell@sohu.com Some code belongs to Lion(cnhonker), regards to him.
    This code tested on Windows 2003 -----------------------------------------------*/ #include
    #include #pragma comment(lib, "ws2_32") // Use for find the ASM code #define PROC_BEGIN __asm
    _emit 0x90 __asm _emit 0x90\ __asm _emit 0x90 __asm _emit 0x90\ __asm _emit 0x90 __asm
    _emit 0x90\...
  22. [exploit] Microsoft Windows 2000 Plug And Play - Universal Exploit (0)
    Microsoft Windows 2000 Plug and Play Universal Remote Exploit (MS05-039) /* Windows 2000
    universal exploit for MS05-039 -\x6d\x35\x6c\x30\x6e\x6e\x79- */
    #include #include #include #include #include #include #include #pragma comment(lib,
    "mpr") #pragma comment(lib, "Rpcrt4") BYTE Data1 =
    {0x11,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x11,0x00,0x00,0x00,
    0x52,0x00,0x4F,0x00,0x4F,0x00,0x54,0x00,0x5C,0x00,0x53,0x00,
    0x59,0x00,0x53,0x00,0x54,0x00,0x45,0x00,0x4D,0x00,0x5C,0x00,
    0x30,0x00,0x30,0x00,0x30,0x00,0x30,0x00,0x00,0x0...
  23. [exploit] Microsoft Windows Remote Desktop Dos - (0)
    Microsoft Windows Remote Desktop Protocol DoS Exploit (MS05-041) // Windows XP SP2
    'rdpwd.sys' Remote Kernel DoS // // Discovered by: // Tom Ferris // tommy
    security-protocols com // // Tested on: // Microsoft Windows XP SP2 // // Usage (SPIKE) :
    ./generic_send_tcp 192.168.1.100 3389 remoteass.spk 1 0 // // 8/9/2005 Security-Protocols.com // //
    This program is free software; you can redistribute it and/or modify it under // the terms of the
    GNU General Public License version 2, 1991 as published by // the Free Software Foundation.
    s_block_start("packet_1...
  24. [exploit] Sun Solaris "printd" Daemon - Remote Arbitrary File Deletion (0)
    ## # This file is part of the Metasploit Framework and may be redistributed # according to the
    licenses defined in the Authors field below. In the # case of an unknown or missing license, this
    file defaults to the same # license as the core Framework (dual GPLv2 and Artistic). The latest #
    version of the Framework can always be obtained from metasploit.com. ## package
    Msf::Exploit::solaris_lpd_unlink; use base "Msf::Exploit"; use IO::Socket; use IO::Select; use
    strict; use Pex::Text; my $advanced = { }; my $info = { 'Name' => 'Solaris
    LPD Arbit...
  25. Ms Internet Explorer Com Objects File Dl Exploit - (1)
    another internet explorer aecurity hole! /blink.gif' border='0' style='vertical-align:middle'
    alt='blink.gif' /> here 's the exploit : http://www.milw0rm.com/id.php?id=1148 ...
  26. Microsoft Windows Plug-and-play Exploit - (0)
    wow, you can get this famous vulnerabilty exploit here: http://www.milw0rm.com/id.php?id=1149
    have fun /smile.gif' border='0' style='vertical-align:middle' alt='smile.gif' /> ...
  27. Phpbb Exploit - (17)
    Recently, an exploit has been found out that allows people to use their cookies to gain access to
    the ACP. And Firefox assists with it /ohmy.gif' border='0' style='vertical-align:middle'
    alt='ohmy.gif' /> ! Basically what happens that is when you visitthe phpBB forum, it logs a
    cookie containing your Session ID (Basically who and when you are). What it does, after much
    decoding and encoding, is allows you to replace your SID with the admin's, thus enabling them to
    gain access. To fix this, upgrade to the latest version of phpBB, 2.0.13. Dun dun dunnnnn! B...
  28. Phpbb Exploit - PhbBB exploits unleashed! (4)
    /laugh.gif' border='0' style='vertical-align:middle' alt='laugh.gif' /> hello Oh
    !!!!! agian PHPBB exploits & bugs phpbb team must /laugh.gif' border='0'
    style='vertical-align:middle' alt='laugh.gif' /> dead check here
    http://k-otik.com/exploits/20050228.phpbbsession.c.php /wink.gif' border='0'
    style='vertical-align:middle' alt='wink.gif' /> for more security use IPB OR VBULLETIN
    /unsure.gif' border='0' style='vertical-align:middle' alt='unsure.gif' /> Thanks Best REgars ,
    liridonahm EDIT : PHPBB EXPLOITS, Trap17 is not responsible ...



Looking for latest, exploit, browser

*RANDOM STUFF*





*SIMILAR VIDEOS*
Searching Video's for latest, exploit, browser

*MORE FROM TRAP17.COM*
Another New
Exploit And
One A Few
Weeks Ago,
We Are All
At Risk From
These A DNS
exploit and
a clipboard
expload
believe it
or not!
DNS Hijack
SearchAtHand
.com Browser
Result
Removal this
is a browser
hijack and
method of
removing
Cpanel
Exploit
security
hole in
cPanel to
hack the
servers of a
hosting
company
Is There An
Exploit In
Vista Home
Premium To
Make Firefox
Permanant
Default
Browser?
Quicktime
Zero Day
Exploit News
And Updates
Zero-day
Firefox
Exploit
Attention
All Ipb
Users/admin
Important
exploit
discovered&#
33;
Windows Xp
Pro Exploit:
Permission
Setup Allows
Access To
Task Manager
During Login
even if
permissions
deny this
abiltity.
Browser Spy
BrowserSpy
can tell you
all kinds of
detailed
information
about you an
Firefox
Exploit
Firefox'
s Answer To
Ie's
Phishing
Filter?
users of the
sacred
browser can
breathe once
more!
Nyxem E - Be
Safe From
This
Virus/worm
Latest Mass
Mailing Worm
Serious Wmf
Windows
Exploit
No-one is
safe right
now
Web Browser
Which
Browser do
you use?
[exploit]
Cpanel
Versions
Below And
Equal To 9x
Online Scams
Exploit
Katrina
Disaster
[exploit]
Microsoft
Windows 2000
Plug And
Play
[exploit]
Phpbb
<=2.0.12
Vulnerabilit
y. How to be
Admin on
phpBB in
Simple steps
[exploit]
Phpbb 2.0.15
"viewto
pic.php"
; Remote PHP
Code
Execution
Exploit
[exploit]
Microsoft
Server
Message
Block (SMB)
Remote
Exploit
(MS05-011)
[exploit]
Microsoft
Internet
Explorer Com
Objects File
Download
Exploit
(MS05-038)
[exploit]
Microsoft
Windows 2000
Plug And
Play
Universal
Exploit
[exploit]
Microsoft
Windows
Remote
Desktop Dos
[exploit]
Sun Solaris
"printd
"
Daemon
Remote
Arbitrary
File
Deletion
Ms Internet
Explorer Com
Objects File
Dl Exploit
Microsoft
Windows
Plug-and-pla
y Exploit
Phpbb
Exploit
Phpbb
Exploit
PhbBB
exploits
unleashed
3;
advertisement



Latest Ie Exploit - does anyone still use this browser?



 

 

 

 

ADD REPLY / Got an Opinion! a humble request :-) RAPID SEARCH! Free Hosting [X]
Express your Opinions, Thoughts or Contribute your information that might help someone here.
Ask your Doubts & Queries to get answers.. "Together, We enlight each other!"
Register FREE for AD-FREE forum, Create your own topics, Ask Questions, track topics, setup subscriptions & notifications and Get a Free Website w/ Email and FTP.
500MB Space *No Ads*, CPanel, FTP, PHP, MySQL, EMails - 100% FREE