Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Information-Security-News
[Top] [All Lists]

[ISN] New IE Bugs Open Up XP SP2 To Attack

Subject: [ISN] New IE Bugs Open Up XP SP2 To Attack
Date: Thu, 21 Oct 2004 03:11:48 -0500 (CDT)
http://www.informationweek.com/story/showArticle.jhtml;jsessionid=OLRHTRVYFRIOGQSNDBGCKH0CJUMEKJVN?articleID=50900322

By TechWeb.com 
Oct. 20, 2004

Two new vulnerabilities in Internet Explorer 6.0 were unveiled by a
security firm Wednesday that hackers could exploit to bypass security
features even in Microsoft's most secure OS, Windows XP SP2.

According to Danish security company Secunia, the "highly critical"  
vulnerabilities stem from a flaw in IE's drag-and-drop feature and in
the browser's security zone. Hackers could exploit these bugs by
enticing users to malicious Web sites, where specially crafted
files--including image and help files--could compromise the PC,
leaving it open to attack or hijack.

Both bugs can be exploited to circumvent Windows XP SP2's Local
Computer zone lockdown security feature, said Secunia.

"This has been confirmed on a fully patched system with Internet
Explorer 6.0 and Microsoft Windows XP SP2," wrote Secunia in its
online alert.

As is its usual practice when it touts critical problems in IE,
Secunia recommended that users either disable Active Scripting in the
browser, or switch to an alternate, such as Mozilla's Firefox.



_________________________________________
Open Source Vulnerability Database (OSVDB) Everything is Vulnerable - 
http://www.osvdb.org/

<Prev in Thread] Current Thread [Next in Thread>
  • [ISN] New IE Bugs Open Up XP SP2 To Attack, InfoSec News <=