Author Topic: Reason 38943 to switch to Firefox: Zero-Day Xploit  (Read 2983 times)

0 Members and 1 Guest are viewing this topic.

Snowthrower

  • Guest
Reason 38943 to switch to Firefox: Zero-Day Xploit
« on: November 21, 2005, 07:12:11 pm »
Quote
Exploit code for a critical flaw in fully patched versions of Microsoft Corp.'s Internet Explorer browser has been released on the Internet, putting millions of Web surfers at risk of computer hijack attacks.

The zero-day exploit, posted by a U.K.-based group called "Computer Terrorism," could allow a remote hacker to take complete control of a Windows system if the victim simply browses to a malicious Web site.

Ziff Davis Internet News have verified that the exploit works on fully patched Windows XP systems with default IE installations.

PointerClick here to read more about Microsoft's IE patch breaking Web sites.

The MSRC (Microsoft Security Response Center) is expected to release a security advisory to address the public reports.

A Microsoft spokeswoman acknowledged that customers running Windows 2000 SP4 and Windows XP SP2 were at risk. The Windows Server 2003 and Windows Server 2003 SP1 in their default configurations, with the Enhanced Security Configuration turned on, are not affected.

"We have also been made aware of proof of concept code that could seek to exploit the reported vulnerability but are not aware of any customer impact at this time but Microsoft will continue to investigating these public reports," the spokeswoman added.

The proof-of-concept exploit, which is available from the FrSirt site, currently launched the Windows Calculator (calc.exe) but can be easily modified by malicious hackers.

eWEEK.com Special Report: Keeping Pace with Microsoft's Patches

Johannes Ullrich, chief technology officer at the SANS ISC (Internet Storm Center), warned that arbitrary executables may be launch without user interaction. An attacker must however lure the victim to visit a maliciously crafted Web site.

Ullrich said the ISC has already received reports that a new version of the exploit is capable of opening a remote shell. "The PoC exploit allows for easy copy/paste of various shell code snippets," he warned.

In a diary entry, Ullrich said the exploit targets a known bug in the JavaScript "Window()" function, when used in conjunction with a event. The 'onload' is an argument to the HTML tag that is used to execute Javascript as the IE page loads.

PointerClick here to read more about Microsoft correcting the IE patch download glitch.

The group that published the exploit said Microsoft has been aware of the Javascript Window() vulnerability for several months but was mistakenly treating it as a low-priority denial-of-service flaw.

Benjamin Tobias Franz, a German security researcher, originally published an advisory in May this year to warn of the denial-of-service bug.

However, according to the latest findings, the issue is much more serious and could allow remote, arbitrary code execution, yielding full system access with the privileges of the underlying user, according to a notice from Computer Terrorism (U.K.) Ltd.

The group said IE users should immediately disable "Active Scripting via the Tools > Internet Options > Security tab > Custom Level feature.

The SANS ISC's Ullrich said IE users should consider switching to Firefox of Opera.

Offline VulturEMaN

  • Global Moderator
  • SpongeBob
  • *****
  • Posts: 3,853
  • Gender: Male
  • Dengaku Man xD
    • View Profile
Reason 38943 to switch to Firefox: Zero-Day Xploit
« Reply #1 on: November 21, 2005, 08:19:20 pm »
btw, ur link was smelly, so here's a nice one :D

http://www.eweek.com/article2/0,1895,1891749,00.asp

Offline AppleNick

  • SpongeBob
  • *****
  • Posts: 4,432
  • Gender: Male
  • ドブネズミみたいに
    • View Profile
Reason 38943 to switch to Firefox: Zero-Day Xploit
« Reply #2 on: December 12, 2005, 10:57:16 am »
We've got the point. IE is not secure, it will never be secure.

Offline ssj4gogita4

  • Honorable
  • SpongeBob
  • ******
  • Posts: 17,890
  • Gender: Male
    • View Profile
Reason 38943 to switch to Firefox: Zero-Day Xploit
« Reply #3 on: December 12, 2005, 11:00:15 am »
Ah, secure for some people.

Offline VulturEMaN

  • Global Moderator
  • SpongeBob
  • *****
  • Posts: 3,853
  • Gender: Male
  • Dengaku Man xD
    • View Profile
Reason 38943 to switch to Firefox: Zero-Day Xploit
« Reply #4 on: December 12, 2005, 05:52:41 pm »
same :P

mine's mega frosty goodness...nothing has gotten by it in a while..

Offline IceFox

  • SpongeBob
  • *****
  • Posts: 5,712
  • Jacked up on Red Bull
    • View Profile
    • http://Nothing.
Reason 38943 to switch to Firefox: Zero-Day Xploit
« Reply #5 on: December 12, 2005, 06:03:03 pm »
I have used IE6 logng before I switched to FFand then to Opera. NO spyware. No viruses. Natta. Even when I was on IE4, with an inredibly outdatedAnti-Virus on Win98, it still brought in nothing. After a while my sister downloaded some spyware....

Offline ssj4gogita4

  • Honorable
  • SpongeBob
  • ******
  • Posts: 17,890
  • Gender: Male
    • View Profile
Reason 38943 to switch to Firefox: Zero-Day Xploit
« Reply #6 on: December 12, 2005, 06:10:21 pm »
Quote
I have used IE6 logng before I switched to FFand then to Opera. NO spyware. No viruses. Natta. Even when I was on IE4, with an inredibly outdatedAnti-Virus on Win98, it still brought in nothing. After a while my sister downloaded some spyware....
[snapback]259810[/snapback]
So? Just kick your sister off the computer and tell her to use some other browser. Tell her to stop looking up porn.

Snowthrower

  • Guest
Reason 38943 to switch to Firefox: Zero-Day Xploit
« Reply #7 on: December 12, 2005, 07:10:24 pm »
Whoa, topic resurrection :biggrin:

I think that "Spyware Quest" speaks for itself. I ended up reformatting my computer because of it.

Maybe its time to get multiple people involved this time, since I plan on doing it again sometime after Christmas.

williambob286

  • Guest
Reason 38943 to switch to Firefox: Zero-Day Xploit
« Reply #8 on: December 13, 2005, 03:49:25 am »
Yes! IE really is useless!

Offline IceFox

  • SpongeBob
  • *****
  • Posts: 5,712
  • Jacked up on Red Bull
    • View Profile
    • http://Nothing.
Reason 38943 to switch to Firefox: Zero-Day Xploit
« Reply #9 on: December 13, 2005, 10:04:43 am »
Quote
Quote
I have used IE6 logng before I switched to FFand then to Opera. NO spyware. No viruses. Natta. Even when I was on IE4, with an inredibly outdatedAnti-Virus on Win98, it still brought in nothing. After a while my sister downloaded some spyware....
[snapback]259810[/snapback]
So? Just kick your sister off the computer and tell her to use some other browser. Tell her to stop looking up porn.
[snapback]259811[/snapback]
Haha. She switched to FF after she got the spyware, so she could blame it on me.


Anyways, we each have a computer w/ interent now