Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Signatures
[Top] [All Lists]

[Snort-sigs] Confirmed Coverage of Microsoft IE Proof of Concept Exploit

Subject: [Snort-sigs] Confirmed Coverage of Microsoft IE Proof of Concept Exploit
Date: Tue, 22 Nov 2005 15:45:43 -0500
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Sourcefire VRT Advisory

Synopsis:
The Sourcefire Vulnerability Research Team (VRT) has learned the
release of proof of concept code that demonstrates the ability to
execute code via a vulnerability in the way that Internet Explorer
handles a Javascript event.

The Sourcefire VRT has confirmed that a rule identified as sid 4647,
released on November 9, 2005, will generate events when an attempt is
made to exploit this vulnerability including use of the proof of
concept code.

Details:
A vulnerability exists in the way Internet Explorer handles the
window() function supplied to the javascript "onload" handler as a
parameter. The conditions for exploitation occur when a page is opened
in the browser that uses <body onload=window();>.

Detection:
Sourcefire VRT rule packs released on November 9, 2005 contained sid 4647
that will generate events when an attempt is made to exploit this
vulnerability, including use of the proof of concept code.

Note: Sid 4647 is NOT enabled by default, should detection for this
vulnerability be required, this rule should be enabled.

Additional References:

Microsoft Security Advisory (911302)
http://www.microsoft.com/technet/security/advisory/911302.mspx
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (Darwin)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFDg4N3Mpm0ve0NhMcRAneMAJ9Ee07dVuc7CmlnG3/Wb5dGLXp49gCeN43+
yAv+0SX0/RnQ0YiRImDTUdk=
=DTsL
-----END PGP SIGNATURE-----



-------------------------------------------------------
This SF.Net email is sponsored by the JBoss Inc.  Get Certified Today
Register for a JBoss Training Course.  Free Certification Exam
for All Training Attendees Through End of 2005. For more info visit:
http://ads.osdn.com/?ad_id=7628&alloc_id=16845&op=click
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs

<Prev in Thread] Current Thread [Next in Thread>
  • [Snort-sigs] Confirmed Coverage of Microsoft IE Proof of Concept Exploit, Sourcefire VRT <=