Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Information-Security-News
[Top] [All Lists]

[ISN] Experts warn of trick to bypass IE download warnings

Subject: [ISN] Experts warn of trick to bypass IE download warnings
Date: Mon, 17 Jan 2005 00:23:39 -0600 (CST)
http://www.nwfusion.com/news/2005/0114experwarn.html

By Paul Roberts
IDG News Service
01/14/05

A computer security researcher and an anti-virus company are warning
Microsoft customers about an unpatched hole in the company's Internet
Explorer Web browser that could allow a remote attacker to bypass
security warnings and download malicious content onto vulnerable
systems.

The warnings came after the hole was identified on the Bugtraq
Internet security discussion list by someone using the name "Rafel
Ivgi." The hole affects Internet Explorer (IE) version 6.0.0,
including the version released with Windows XP Service Pack 2. The
vulnerability allows malicious attackers to bypass warnings designed
to inform users when a file is being passed to their computer using a
specially-crafted HTML Web document.

Microsoft was not able to comment on the hole in time for this story.

Security software company Symantec issued a vulnerability alert about
the hole Friday and cited Ivgi, which also provided code proving that
the hole existed.

According to the Bugtraq message and Symantec alert, an IE feature
designed to catch references to file downloads does not detect a
particular HTML event, known as "onclick," when it is combined with
the common HTML tag, which designates the beginning and ending of the
main part of a Web page.

Malicious Internet users could use the onclick event in combination
with another function called "createElement" to create an IFRAME, or
"inline frame," which is an HTML element that allows external objects
to be inserted into another HTML document. Attackers could link the
IFRAME to a malicious Web page that downloaded a malicious file to the
user's computer when the page was clicked on, without generating a
warning in the Information bar, Symantec said.

There is no patch available for the new hole, and no specific exploit
code is required to take advantage of the hole, Symantec said.

IE users are advised to avoid links provided by unknown or untrusted
sources, to keep from being lured to a malicious Web site. IE users
can also configure the browser to disable the execution of script code
and active content, though doing so could have adverse effects on the
way IE functions, Symantec said.

The news comes just three days after Microsoft issued software patches
for several serious Windows security holes and released a new tool
that lets users remove malicious software from their PCs, and amid
increasing competition in the Web browser market from the Mozilla
Foundation's Firefox browser.

On Tuesday, the Redmond, Wash., software company published security
bulletins and patches for two critical holes, one in the Windows HTML
Help system and the other in Windows code that handles cursor,
animated cursor and icon formats.



_________________________________________
Open Source Vulnerability Database (OSVDB) Everything is Vulnerable - 
http://www.osvdb.org/

<Prev in Thread] Current Thread [Next in Thread>
  • [ISN] Experts warn of trick to bypass IE download warnings, InfoSec News <=