Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-sigs] Confirmed Coverage of Microsoft IE Proof of Concept Exploit |
|---|---|
| Date: | Tue, 22 Nov 2005 15:45:43 -0500 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
Sourcefire VRT Advisory
Synopsis: The Sourcefire Vulnerability Research Team (VRT) has learned the release of proof of concept code that demonstrates the ability to execute code via a vulnerability in the way that Internet Explorer handles a Javascript event.
The Sourcefire VRT has confirmed that a rule identified as sid 4647, released on November 9, 2005, will generate events when an attempt is made to exploit this vulnerability including use of the proof of concept code.
Details: A vulnerability exists in the way Internet Explorer handles the window() function supplied to the javascript "onload" handler as a parameter. The conditions for exploitation occur when a page is opened in the browser that uses <body onload=window();>.
Detection: Sourcefire VRT rule packs released on November 9, 2005 contained sid 4647 that will generate events when an attempt is made to exploit this vulnerability, including use of the proof of concept code.
Note: Sid 4647 is NOT enabled by default, should detection for this vulnerability be required, this rule should be enabled.
Additional References:
Microsoft Security Advisory (911302) http://www.microsoft.com/technet/security/advisory/911302.mspx -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.0 (Darwin) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
iD8DBQFDg4N3Mpm0ve0NhMcRAneMAJ9Ee07dVuc7CmlnG3/Wb5dGLXp49gCeN43+ yAv+0SX0/RnQ0YiRImDTUdk= =DTsL -----END PGP SIGNATURE-----
------------------------------------------------------- This SF.Net email is sponsored by the JBoss Inc. Get Certified Today Register for a JBoss Training Course. Free Certification Exam for All Training Attendees Through End of 2005. For more info visit: http://ads.osdn.com/?ad_id=7628&alloc_id=16845&op=click _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-sigs] Bleedingsnort.com Daily Update, bleeding |
|---|---|
| Next by Date: | [Snort-sigs] Bleedingsnort.com Daily Update, bleeding |
| Previous by Thread: | [Snort-sigs] FP on NETBIOS SMB-DS Trans2 FIND_FIRST2 response overflow attempt, Russell Fulton |
| Next by Thread: | [Snort-sigs] FP for sid 2000538, Chich Thierry |
| Indexes: | [Date] [Thread] [Top] [All Lists] |