Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-sigs] Write up for 4148 |
|---|---|
| Date: | Tue, 16 May 2006 13:41:12 -0700 (PDT) |
Rule: WEB-CLIENT DHTML Editing ActiveX Object Access -- Sid:4148 -- Summary: Hostile web sites can upload arbitrary files from hosts using unpatched IE 5 browsers -- Impact: disclosure of arbitrary files, potentially including password caches. If combined with another attack allowing file search for strings characteristic of credit card numbers, this could be very bad. -- Detailed Information: An ActiveX object intended to provide for WYSIWYG editing on web forms and the like has a flaw which allows a hostile web site to upload arbitrary files from a browsing computer if that computer is using unpatched Internet Explorer 5 -- Affected Systems: Unpatched IE 5 -- Attack Scenarios: -- Ease of Attack: Simple. -- False Positives: Many sites use this feature legitimately for WYSIWYG editing on web forms. www.blackboard.com is one. -- False Negatives: -- Corrective Action: Patch all systems using IE 5. -- Contributors: Information summarized from rule references, no original/new data supplied, apart from FP source. -- Additional References: __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com ------------------------------------------------------- Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job easier Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642 _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Snort-sigs] Rule Set Completness, Roland Turner |
|---|---|
| Next by Date: | [Snort-sigs] Snort Community Rules Update, Sourcefire VRT |
| Previous by Thread: | [Snort-sigs] Fp: sig 1378, Michael Scheidell |
| Next by Thread: | [Snort-sigs] FP with webmails, Chich Thierry |
| Indexes: | [Date] [Thread] [Top] [All Lists] |