Bigbruin.com
Home :: Reviews & Articles ::
Forum :: Info :: :: Facebook :: Youtube :: RSS Feed
Search  :: Register :: Log in
New IE Vulnerability
Post new topic   Reply to topic    Bigbruin.com Forum Index -> Software
View previous topic :: View next topic  
Author Message
BeerCheeze
*hick*


Joined: 14 Jun 2003
Posts: 9285
Location: At the Bar

PostPosted: Mon, 21 Nov 2005 19:57:52    Post Subject: New IE Vulnerability Reply with quote View Single Post

A vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0/5.5 and Microsoft Windows XP SP2, and Internet Explorer 6.0 and Microsoft Windows 2000 SP4.

The vulnerability,which can be exploited by malicious people to compromise a user's system, is caused due to certain objects not being initialized correctly when the "window()" function is used in conjunction with the "<body onload>" event. This can be exploited to execute arbitrary code on a vulnerable browser via some specially crafted JavaScript code called directly when a site has been loaded.


*Note* I have personally tested this venerability and found it to be 100% real. It is very easy to exploit remotely.


Recommendations:

1) Use an alternative browser. While other browsers (such as Firefox) will crash when presented with this exploit it will not allow arbitrary code to be executed on your computer.

2) Disable Javascript - WARNING This may cause many websites to stop functioning.
1. Open Internet Explorer.
2. Select Internet Options from the Tools menu.
3. In Internet Options dialog box select the Security tab.
4. Click Custom level button at bottom. The Security settings dialog box will pop up.
5. Under Scripting category disable* Active Scripting, Allow paste options via script and Scripting of Java applets (will be at almost bottom of list)
6. Click OK twice to close out.
7. Close Internet Explorer.
*Note - You can choose Prompt if you want, but this may cause you to be prompted on a lot of site a lot of times.


Unfortunately these are the only two safe things you can do on a Windows system. Contuine to watch MS windows update site as well.
Back to top
View user's profile Send private message
Little Bruin
Boo Boo

Joined: 07 Apr 2003
Posts: 667
Location: Pic-A-Nic Basket
Display posts from previous:   
Post new topic   Reply to topic    Bigbruin.com Forum Index -> Software All times are GMT - 4 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum
Contact Us :: On Facebook :: On Youtube :: Newsletter :: RSS Feed :: FAQ :: Links :: Sponsors :: Privacy Policy
Copyright © 2000 - 2023 Bigbruin.com - All rights reserved