Author Topic: New vulnerability in IE  (Read 19808 times)

0 Members and 1 Guest are viewing this topic.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: New vulnerability in IE
« Reply #15 on: March 23, 2006, 06:42:57 PM »
Have you or antone else tried it (windizupdate) Bob ?
Works perfectly for me  8)
The best things in life are free.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: New vulnerability in IE
« Reply #16 on: March 23, 2006, 07:53:19 PM »
Hi Bob,

I think there must be a reason for you too, Bob, to use GreenBrowser in stead of the default embedded one.
It is like David says here, compromise the browser & you have compromised the OS, at least with IE. Good that MS did not hand out the information to alternate browsers to do the same.
To have a browser when it is such an important posible vehicle for malware vectors build in that deep as an integral part of the OS, is not a thing you do when you have security as a first priority.
Why does not MS come up with a new platform that is really lite, and only carries the OS, there would be a lot of vulnerabilities less to guess at.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

CharleyO

  • Guest
Re: New vulnerability in IE
« Reply #17 on: March 23, 2006, 08:10:12 PM »
***

Yes, I must agree that the internet browser (whatever it is called ... IE, FF, Flock, etc) should not be built into the operating system. I also think that the browser should not be so closely "related" to Windows Explorer. Why, after all this time and multiple problems, MS continues with this is beyond me.    ???    ::)


***

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89062
  • No support PMs thanks
Re: New vulnerability in IE
« Reply #18 on: March 23, 2006, 08:34:40 PM »
Have you or antone else tried it (windizupdate) Bob ?
Works perfectly for me  8)
I just tried to install the same driver update and it failed again but I got a little more information this time, a missing file, "unable to load UPD62INT.DLL -- file not found?" So I will uninstall the plug-in and try again later.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline YLAP

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2118
Re: New vulnerability in IE
« Reply #19 on: March 23, 2006, 09:36:19 PM »
Latest info from http://isc.sans.org (INFOCon globe in Firefox just went yellow)

Quote
IE exploit on the loose, going to yellow (NEW)
Published: 2006-03-23,
Last Updated: 2006-03-23 20:18:59 UTC by Jim Clausing (Version: 1)

Folks, as Lorna predicted yesterday, it didn't take long for the exploits to appear for that IE vulnerability.  One has been making the rounds that pops the calculator up (no, I'm not going to point you to the PoC code, it is easy enough to find if you read any of the standard mailing lists), but it is a relatively trivial mod to turn that into something more destructive (in fact, one of our readers has provided us with a version that he created that is more destructive).  For that reason, we're raising Infocon to yellow for the next 24 hours.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: New vulnerability in IE
« Reply #20 on: March 24, 2006, 01:15:26 PM »
Hi Ylap,

Thanks for that link to our Lithuanian friend.
They say in the article that locking down the computer may protect against this vulnerability. I like this confirmed. Read: http://www.eweek.com/article2/0,1759,1891447,00.asp
Read more here:
http://www.securityfocus.com/archive/1/427904/30/0/threaded
Stay malware free Ylap,

polonus
« Last Edit: March 24, 2006, 03:22:34 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Dwarden

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1793
  • Ideas, that's ocean without borders!
    • Bohemia Interactive
Re: New vulnerability in IE
« Reply #21 on: March 24, 2006, 05:37:38 PM »
simple blocking .hta in Avast! webshield should work fine ...

that's similar to .wmf trick :)
https://twitter.com/FoltynD , Tech. Community, Online Services & Distribution manager of Bohemia Interactive

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: New vulnerability in IE
« Reply #22 on: March 24, 2006, 09:37:53 PM »
Hi Dwarden,

Good analytical thought, and when the patch is there you can uncheck it again. But isn't it striking that the same holes come up again and again, like in a concert they are variations on the same theme. With IE it is a bit like "Peter and the Wolf".

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
« Last Edit: March 24, 2006, 10:14:39 PM by FreewheelinFrank »
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline YLAP

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2118
Re: New vulnerability in IE
« Reply #24 on: March 24, 2006, 11:07:18 PM »
Latest info from http://isc.sans.org (INFOCon globe in Firefox just went yellow)

Quote
IE exploit on the loose, going to yellow (NEW)
Published: 2006-03-23,
Last Updated: 2006-03-23 20:18:59 UTC by Jim Clausing (Version: 1)

Folks, as Lorna predicted yesterday, it didn't take long for the exploits to appear for that IE vulnerability.  One has been making the rounds that pops the calculator up (no, I'm not going to point you to the PoC code, it is easy enough to find if you read any of the standard mailing lists), but it is a relatively trivial mod to turn that into something more destructive (in fact, one of our readers has provided us with a version that he created that is more destructive).  For that reason, we're raising Infocon to yellow for the next 24 hours.

Update: At the urging of Handler Extraordinaire Kyle Haugsness, I tested the sploit on a box with software-based DEP and DropMyRights... here are the results:

Software-based DEP protecting core Windows programs: sploit worked
Software-based DEP protecting all programs: sploit worked
DropMyRights, config'ed to allow IE to run (weakest form of DropMyRights protection): sploit worked
Active Scripting Disabled: sploit failed

So, go with the last one, if you are concerned.  By the way, you should be concerned.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: New vulnerability in IE
« Reply #25 on: March 24, 2006, 11:58:46 PM »
Hi forum folks,

Here is the evidence that ActiveX-scripting is at the base of this problem. I would say again. http://securitytracker.com/alerts/2006/Mar/1015812.html

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Mastertech

  • Guest
Re: New vulnerability in IE
« Reply #26 on: March 25, 2006, 01:25:57 AM »
The simplest solution is to install IE 7 Beta 2 refresh Build 5335.5. It is not vulnerable to this exploit - Download.

You have to uninstall the old BETA 2 first if you have that installed.


neal62

  • Guest
Re: New vulnerability in IE
« Reply #27 on: March 25, 2006, 08:34:30 AM »
IMHO the simplest step in this case is to NOT use the Beta of I.E. 7 period. Just wait until they come out with a finished product. Maybe by then they will get things right for us their bread and butter.  :)

Offline TedNelly

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1538
  • Trust No-One!
Re: New vulnerability in IE
« Reply #28 on: March 25, 2006, 11:17:12 AM »
IMHO the simplest step in this case is to NOT use the Beta of I.E. 7 period. Just wait until they come out with a finished product. Maybe by then they will get things right for us their bread and butter.  :)

That'll be the day Neal hell they haven't had much practice at it have they mate??
Windows 10 Pro | Intel I7 CPU | 16 Gig 2133 RAM | Avast beta 17.5.2295 | Firefox 54 b9(64-bit) | Cyberfox 52.1 | T-Bird 52.1.1 | SpyWareBlaster 5.5 | MalwareBytes 3.0.0.865 | WinPatrol 35.5.2 | GlassWire 1.2.100 | Cybereason Ransomfree 2.2.7 |  Pulla-dePlug Final!

Mastertech

  • Guest
Re: New vulnerability in IE
« Reply #29 on: March 25, 2006, 02:16:00 PM »
That makes absolutely no sense. ??? The latest IE 7 Beta is the only version of IE that is NOT affected by this vulnerability? Not to mention IE 7's interface is 100 times better than IE 6, you can easily uninstall it if you don't want it.