Νέα IE Vulnerabilities!!! - Μπράβο M$ τα κατάφερες πάλι

Συζητήσεις για θέματα που σχετίζονται με software.
Post Reply
User avatar
HdkiLLeR
Venus Project Founder
Venus Project Founder
Posts: 4356
Joined: Tue Jan 27, 2004 4:41 pm
Academic status: Alumnus/a
Gender:
Location: New York, NY
Contact:

Νέα IE Vulnerabilities!!! - Μπράβο M$ τα κατάφερες πάλι

Post by HdkiLLeR » Wed Jun 09, 2004 4:41 am

Καλά τώρα τελαυταία την έχω καταβρεί με την την Μ$...πάλι 0day exploit βγάλανε για τον ΙΕ...τι θα γίνει επιτέλους λίγο εγωισμό δεν έχουν οι κακομήρουλες programmers της; Έλεος έτσι 15άχρονα γράφουνε τα spl0its...τεσπα μετά την εισαγωγούλα έχουμε και τα εξής:
Internet Explorer Local Resource Access and Cross-Zone Scripting Vulnerabilities


Secunia Advisory: SA11793
Release Date: 2004-06-08


Critical:
Extremely critical
Impact: Security Bypass
System access

Where: From remote :-D :-D :-D



Software: Microsoft Internet Explorer 6


Description:
Two vulnerabilities have been reported in Internet Explorer, which in combination with other known issues can be exploited by malicious people to compromise a user's system.

1) A variant of the "Location:" local resource access vulnerability can be exploited via a specially crafted URL in the "Location:" HTTP header to open local files.

Example:
"Location: URL:ms-its:C:\WINDOWS\Help\iexplore.chm::/iegetsrt.htm"

2) A cross-zone scripting error can be exploited to execute files in the "Local Machine" security zone.

Secunia has confirmed the vulnerabilities in a fully patched system with Internet Explorer 6.0. It has been reported that the preliminary SP2 prevents exploitation by denying access.

Successful exploitation requires that a user can be tricked into following a link or view a malicious HTML document.

NOTE: The vulnerabilities are actively being exploited in the wild to install adware on users' systems.

Solution:
Disable Active Scripting support for all but trusted web sites.

Provided and/or discovered by:
Originally discovered in the wild.
Detailed analysis of exploit by Jelmer.

Changelog:
2004-06-08: Updated information in advisory.

Και το Full - Disclosure εδώ:
http://archives.neohapsis.com/archives/ ... /0104.html
-----BEGIN GEEK CODE BLOCK-----
Version: 3.12
GCS d-->--- s+:+ a- C++(+++) BILS++++$ P--- L++++>+++++ E--- W+++ N+ o+ K w--
O M+ V-- PS++>+++ PE- Y++ PGP++ t+ 5+ X+ R* tv b++ DI- D+ G+++ e+++>++++ h r++ y++
------END GEEK CODE BLOCK------

"UNIX is basically a simple operating system, but you have to be a genius to understand the simplicity." -- Dennis Ritchie
Post Reply

Return to “Software”