Slashdot Mirror


Unpatched IE Flaw Extremely Critical

Durinthal writes "The biggest blip on the security radar over the Thanksgiving holiday was the realization by the security community that an Internet Explorer problem first identified six months ago was a lot worse than it appeared, as what appeared to be only a DoS vulnerability also allows for execution of arbitrary code. The realization caused Secunia to issue a rare 'Extremely Critical' advisory."

13 of 277 comments (clear)

  1. Proof of Concept by Motherfucking+Shit · · Score: 5, Informative

    Here is a link to the Proof of Concept page, which will launch an instance of calc.exe if you're vulnerable. AVG Free caught the exploit in the cached page, but calc.exe ran anyway, even after I deleted the file.

    --
    "BSD: Free as in speech. Linux: Free as in beer. Windows 10: Free as in herpes." --Man On Pink Corner in #52607549.
    1. Re:Proof of Concept by Pxtl · · Score: 3, Informative

      Hm. I get a "Script Prompt" window over a tiny IE window, with the name of your site in a textbox. A few seconds later (or when I touch it) it snaps and then I get the windows "close-details" app crash window.

      So it disturbs the browser, but it doesn't hack it for me.

    2. Re:Proof of Concept by TheSpoom · · Score: 4, Informative

      Slightly offtopic, but if you're wondering, NAV calls anything it considers suspicious enough to stop but doesn't have a name for yet "Bloodhound" because that's the component that detects buffer overflows and the like. Just something rather interesting I found when I was doing tech support.

      --
      It's better to vote for what you want and not get it than to vote for what you don't want and get it.
      - E. Debs
    3. Re:Proof of Concept by PlusFiveTroll · · Score: 3, Informative

      Firefox didnt crash, if you waited long enough (like I did) it opens up a popup dialog full of ??????'s, you can then close the window. But it did take a full 3 minutes on a Athlon64 300+ with a gig of ram. calc.exe does not run.

  2. Temp Fix by Manip · · Score: 4, Informative

    Turn on "Data Execution Protection" for all programs and services. Instead of allowing full execution it will limit it to a DOS (crack IE).

    Control Panel -> System -> Advanced [Tab] -> Performance Settings -> Data Execution Protection [Tab] -> Turn on DEP for all programs and services except those I select -> Ok -> OK.

    1. Re:Temp Fix by _Shorty-dammit · · Score: 3, Informative

      I believe DEP is on by default for IE anyways, so I'm not sure this is even necessary. I just tried the proof-of-concept test on my machine, and all it did was bring up some script prompt, didn't launch calc.exe as it should have. This is with the IE7 beta, btw.

  3. It affects Firefox, too. by Mitchell+Mebane · · Score: 5, Informative
    --

    The roots of education are bitter, but the fruit is sweet.
    --Aristotle
  4. Re:Scummy eweek popup alert by BattleRat · · Score: 5, Informative

    The extention you are looking for is called NoScript. It works awesome.

  5. Re:Scummy eweek popup alert by HoosierPeschke · · Score: 3, Informative

    Try this NoScript. It's a whitelist so you can allow only certain sites to use javascript.

    --
    Mr. Universe: "They can't stop the signal, Mal. They can never stop the signal."
  6. McAfee Fails It by Orrin+Bloquy · · Score: 5, Informative

    On my W2K box, McAfee warns me of a threat, then as soon as I close the window, the code executes anyway.

    --
    "Made up/misattributed quote that makes me look smart. I am on /. and I must look smart."
  7. Simmer down by TubeSteak · · Score: 3, Informative

    The URL is http://www.ocremix.org/
    And here's the submitter's user page http://slashdot.org/~Durinthal

    I think you mistook the submitter for **Beatles-Beatles
    This Beatles guy is really getting out of hand.
    He manages to taint stories he isn't even submitting. ...or maybe /.'ers need to stop being so effing hyper sensitive about certain things.

    --
    [Fuck Beta]
    o0t!
  8. Re:Extremely Dupical by Anonymous Coward · · Score: 3, Informative

    OK, now I know Slashdot's biased, but posting this twice and not posting this at all?

    All your OS are belong to Sun!

  9. Re:Firefox v1.5 by m0i · · Score: 3, Informative

    This makes Slashdot exactly on the day Firefox v1.5 is supposed to be released. Apparently, Mozilla want to create a huge marketing campaign, better and larger than the one for v1.0. This is a perfect time to capitalize on this horrible security hole to promote Firefox.

    Hrm, did you notice that Firefox 1.5 is crashing as well on this exploit? It's not a security risk but a big annoyance nonetheless.

    --
    have you been defaced today?