HZGN.COM
welcome to my space
X
Welcome to:hzgn.com
Search:  
 HOME   Another 9 Exploits Found in IE

Another 9 Exploits Found in IE

Published by: cfz 2009-01-05

A performance-boosting feature found in Microsoft's Internet Explorer 5.5 and 6 has opened up nine vulnerabilities that can leave a user's PC wide open for remote exploit, according to the company that found the breach earlier this month.

Previous IE versions, as well as IE 6.1 are unaffected by the flaw, said officials at GreyMagic Software Tuesday, the Israeli firm who discovered the flaw. Last week, the company publicized a flaw in IE 5.5 and 6 that lets hackers steal Web cookies from Web sites and forge content to read local files and execute programs in the Document Object Model (DOM).

Microsoft officials were unaware of the vulnerability at press time. After last week's flaw was published, they berated GreyMagic for not giving their own engineers time to investigate the vulnerability.

F-Secure Weblog : News from the Lab::
The first is an attempt to exploit a Microsoft MDAC RDS. the way the ActiveX Control interacts with the IE browser to provide remote attackers complete
http://www.f-secure.com/weblog/
HOME
Tuesday's nine vulnerabilities all find their root in object caching, which performs security checks when people visit Web sites. In the time it takes for one page to unload and the other to load, these security checks determine whether both pages are in the same security zone and domain.

Crit.org::
Some useful citizen has created an installer that will nail IE with . Another Dangerous Browser Domain Name Exploit No popular articles found.
http://www.crit.org/categories/Exploits/
HOME
The problem, according to GreyMagic engineers, is that objects that are supposed to be inaccessible when the pages are unloaded and the references stored become open to exploit. In essence, the assumed-to-be-inaccessible pages are now interoperable with other documents, such as the attacker's page found on his or her site.

Viruslist.com - Analyst's Diary::
SWF exploits. Here is the list of files that I found: WIN 9,0115,0i.swf The plug-in is browser independent and attacks both IE and Firefox.
http://www.viruslist.com/en/weblog?page=1
HOME
[EXPL] Internet Explorer VML Buffer Overflow Download Exec (Exploit)::
Sep 21, 2006 The second problem was "fixed" using another char and then . sent to the securiteam mailing list, and can be found at the SecuriTeam web
http://www.derkeiler.com/Mailing-Lists/Securiteam/2006-09/msg00031.html
HOME
While the object caching vulnerability affects one area of the Web browser, there are nine separate methods for exploitation. Following are the methods and their potential impact. GreyMagic also published the exploits to compromise the vulnerability, but internetnews.com does not publish exploits:

  • showModalDialog - Full access in IE 5.5, "My Computer" zone access in IE 6.
  • external - Full DOM access on both versions.
  • createRange - Full DOM access on both versions.
  • elementFromPoint - Full DOM access on both versions.
  • getElementById - Full DOM access on both versions.
  • getElementsByName - Full DOM access on both versions.
  • getElementsByTagName - Full DOM access on both versions.
  • execCommand - read access to the loaded document.
  • clipboardData - read/write access to the clipboard, regardless of settings.

GreyMagic engineers recommend disabling Active Scripting until a patch is released, or upgrading to IE 6.1.


Massive DDoS Attack Hit DNS Root Servers
Web Vandalism on the Rise

PRINT Add to favorites
#If you have any other info about this subject , Please add it free.#
Your name:
E-mail:
Telphone:

Your comments:


If you have any other info about Another 9 Exploits Found in IE , Please add it free.
  • where can a 16 year old work in southern ca
  • how to have muscular body
  • i 039 ve got loads of homework to finish essays ect but it 039 s really late how do i keep my mind working
  • tell me honestly am i beautiful
  • am i too skinny am 13 5 2 and weigh 84lb 6 9 stone am worrid am under weight
  • would you think this guy is gay
  • should i bring this up at parent teacher conferences
  • recognising your emotions
  • why does politicians fail to deliver on their promises
  • can you guess where i 039 m from just by hearing my voice
  • glbt vintage indie hair for a guy desperate for new style pics inside
  • do i have to pluck my eyebrows im a guy so i reallyyy dont want to pic
  • what 039 s going on with the gas prices
  •  
  • i know this is a no brainer but is kellogs raisin bran good to eat if youre trying to loose weight
  • why is the role of an archaeologist important in history
  • 65 law pass for inmates serve 65 of there time instead of 85 pass in pa
  • if you had to choose would you rather
  • what colors look best with khaki pants and what color shoes
  • does your hair turn green if you want to dye your platinum blonde hair back to dark brown
  • what to expect while getting a tattoo answer any questions you can please
  • when you apply for a job and the employer applies for references are you aloud to ask what the references said
  • juicy party help what do you think
  • what color do my eye 039 s look
  • exactly what value do private insurance companies add to our health care system
  • my house was foreclosed on sold in an auction now what
  • is the reason obama cannot get a security clearance because of his involvement with a terrorist named ayers
  • are high waisted skinny jeans still in

  • About us -Site map -Advertisement -Jion us -Contact usExchange linksSponsor us
    Copyright© 2008 hzgn.com All Rights Reserved
    Site made&Support support@hzgn.com    E-mail: web@hzgn.com