Post subject: 3 "Extremely Critical" Internet Explorer Exploits
Posted: Mon Jan 10, 2005 7:15 am
The Man, The Myth
Joined: Sun Oct 17, 2004 12:12 am Posts: 1080 Location: boulder
I decided to post this in N&D and not the Tech forum because I think this is important. In essence, any command can be run on your computer, including deleting your files or whatnot. You can be running a completely up-to-date WinXP machine with the latest SP2 patch, a firewall, anti-virus software, anti-spyware software, etc, and you're still completely vulnerable.
Here is the advisory: http://secunia.com/advisories/12889/. Secunia is a very well-known security site, and it's very atypical of them to say "Solution: Use another product".
For those curious, you can run a test of the exploit in action right here (click at your own risk). It will create a directory right on your c drive, although it could just as easily delete your directories.
If you haven't already done so, I'd strongly encourage using a more secure browser. Firefox and Opera are two popular, secure web browsers.
_________________ "my fading voice sings, of love..."
Joined: Sun Oct 17, 2004 12:39 pm Posts: 3306 Location: 4336 miles west of St. Albans
I've grown sick of IE and all it's bugs. I'd always get a error message and it would shut down my IE window I was surfing the net in. I finally downloaded Mozilla and it's amazing. I never have problems like the IE crap gave me nor do I ever get those pesty pop-ups.
_________________ But if home is where the heart is
then there's stories to be told.
No you don't need a doctor
no one else can heal your soul.
Joined: Fri Oct 29, 2004 2:01 pm Posts: 492 Location: Utrecht, Holland
CommonWord wrote:
I'm with Avant right now. Very cool. Thanks for the heads up.
macjunkie wrote:
i had suuuuch fucking issues with firefox. i'm using avant now. and it seems better.
IE really reeeeeally does suck. and considering its the most popular browser out there... bad news bears.
Sorry to burst your bubbles, but Avant Browser is but a shell around Internet Explorer. I am quite sure that Avant Browser is vulnerable to these exploits as well.
_________________ "I'd rather have a bottle in front of me, than a frontal lobotomy"
--- Tom Waits
Joined: Sat Oct 16, 2004 10:52 pm Posts: 1727 Location: Earth Gender: Male
Is CrazyBrowswer a shell for IE too? Cause that's my browswer of choice.
_________________ "The smart way to keep people passive and obedient is to strictly limit the spectrum of acceptable opinion, but allow very lively debate within that spectrum." -Noam Chomsky
Post subject: Re: 3 "Extremely Critical" Internet Explorer Explo
Posted: Mon Jan 10, 2005 11:16 pm
Force of Nature
Joined: Sun Oct 17, 2004 3:04 am Posts: 484 Location: Westerville, OH
stonecrest wrote:
I decided to post this in N&D and not the Tech forum because I think this is important. In essence, any command can be run on your computer, including deleting your files or whatnot. You can be running a completely up-to-date WinXP machine with the latest SP2 patch, a firewall, anti-virus software, anti-spyware software, etc, and you're still completely vulnerable.
Here is the advisory: http://secunia.com/advisories/12889/. Secunia is a very well-known security site, and it's very atypical of them to say "Solution: Use another product".
For those curious, you can run a test of the exploit in action right here (click at your own risk). It will create a directory right on your c drive, although it could just as easily delete your directories.
If you haven't already done so, I'd strongly encourage using a more secure browser. Firefox and Opera are two popular, secure web browsers.
Or you can just save yourself a headache and get a:
Just kidding.... although it's nice to not have to worry about Microsoft security issues and viruses for the most part, it still sucks to have limited software support. Hell, I don't run IE on my Mac either... Mozilla is the best browser I've ever used.
_________________ - Sir Not Appearing on this Board
Joined: Sun Oct 17, 2004 5:22 am Posts: 1603 Location: Buffalo
BornToRun86 wrote:
Yay for macs and Safari.
I thought I was the only one on this board using Safari. It's simple to use and well organized. The pop-up blocker works really well and it seems to be very safe.
Joined: Sun Oct 17, 2004 12:12 am Posts: 1080 Location: boulder
ElPhantasmo wrote:
Peeps wrote:
i just did the test and got a big fat nothing
And you are running IE version 6 with SP2, right? Now that I think of it, you probably also have to be running as an administrator, which 99% of windows users are since Microsoft automatically sets up everyone as such.
As for peeps, I said from the start that he was going to claim not to have a problem. His computer could have exploded and he would say things are still fine.
_________________ "my fading voice sings, of love..."
And you are running IE version 6 with SP2, right? Now that I think of it, you probably also have to be running as an administrator, which 99% of windows users are since Microsoft automatically sets up everyone as such.
As for peeps, I said from the start that he was going to claim not to have a problem. His computer could have exploded and he would say things are still fine.
yea, because i would get so much further in life about lying about your posts. you got me scott, thats what i live for. in fact, this isnt really even me, im just one of his friends doing this because his competer exploded, wait im lying, he doesnt have any friends. at work i dont even have SP2 on my PC. we use a dhcp server and are behind a firewall, but again, i must be lying just to make you look like an ass for posting this...oh wait, didnt have to post this for that to happen.....
And you are running IE version 6 with SP2, right? Now that I think of it, you probably also have to be running as an administrator, which 99% of windows users are since Microsoft automatically sets up everyone as such.
As for peeps, I said from the start that he was going to claim not to have a problem. His computer could have exploded and he would say things are still fine.
yea, because i would get so much further in life about lying about your posts. you got me scott, thats what i live for. in fact, this isnt really even me, im just one of his friends doing this because his competer exploded, wait im lying, he doesnt have any friends. at work i dont even have SP2 on my PC. we use a dhcp server and are behind a firewall, but again, i must be lying just to make you look like an ass for posting this...oh wait, didnt have to post this for that to happen.....
why would he be an ass for posting the virus warning thing?
Users browsing this forum: No registered users and 3 guests
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot post attachments in this forum