<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; browser</title>
	<atom:link href="http://www.darknet.org.uk/tag/browser/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Hackers&#8217; Project &#8211; Browser Exploit Code Hiding</title>
		<link>http://www.darknet.org.uk/2006/11/hackers-project-browser-exploit-code-hiding/</link>
		<comments>http://www.darknet.org.uk/2006/11/hackers-project-browser-exploit-code-hiding/#comments</comments>
		<pubDate>Sun, 19 Nov 2006 07:04:52 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Programming]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[browser-exploit]]></category>
		<category><![CDATA[Browser-Hacking]]></category>
		<category><![CDATA[browser-security]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hiding-exploits]]></category>
		<category><![CDATA[software-hacking]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/11/hackers-project-browser-exploit-code-hiding/</guid>
		<description><![CDATA[Hackers are developing new software that will help hide browser attack code from some types of security software. The software, called VoMM (eVade o&#8217; Matic Module), uses a variety of techniques to mix up known exploit code so as to make it unrecognizable to some types of antivirus software. Using these techniques, VoMM &#8220;can create [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Hackers are developing new software that will help hide browser attack code from some types of security software.</p>
<p>The software, called VoMM (eVade o&#8217; Matic Module), uses a variety of techniques to mix up known exploit code so as to make it unrecognizable to some types of antivirus software.</p>
<p>Using these techniques, VoMM &#8220;can create an endless number of variants of an exploit,&#8221; said Aviv Raff, one of the developers behind the project.</p>
<p>&#8220;It aims to provide several techniques out of the box to make browser exploits (mostly) undetectable,&#8221; according to a blog posting by one of the project&#8217;s founders, a hacker going by the name of &#8220;LMH.&#8221; That posting <a href="http://blog.info-pull.com/2006/10/13/vml-exploit-and-idsantivirus-engines-evasion-doom-or-vomm/">can be found here</a>.</p>
<p>The software users server-side scripting technology to create new versions of the exploit code, which then get delivered to browser users when they visit the attacker&#8217;s Web site. By making a number of cosmetic changes to the code that do not affect its functionality, VoMM creates a new version of the malicious software that cannot be detected by &#8220;signature-based&#8221; techniques.</p>
<p>Signature-based antivirus products analyze known malware and then create a digital fingerprint that allows the antivirus software to identify malicious code. By adding extra components &#8212; tabs and spaces, and random comments and variable names &#8212; that are not included in known signatures, VOMM creates software that can evade detection.</p>
<p>The VoMM code is expected to be included in a new module for the upcoming 3.0 version of the widely used Metasploit hacking toolkit, Raff said. Metasploit developer HD Moore is also developing the VoMM software. Raff&#8217;s blog posting on the project <a href="http://aviv.raffon.net/2006/10/15/VoMMTakingBrowserExploitsToTheNextLevel.aspx">can be found here</a>. </p>
<p></p>
<p>Source: <a href="http://www.infoworld.com/article/06/10/18/HNhackersproject_1.html">Infoworld</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Hackers%E2%80%99+Project+%E2%80%93+Browser+Exploit+Code+Hiding+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D375+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/11/hackers-project-browser-exploit-code-hiding/&amp;t=Hackers%E2%80%99+Project+%E2%80%93+Browser+Exploit+Code+Hiding" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/11/hackers-project-browser-exploit-code-hiding/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/11/hackers-project-browser-exploit-code-hiding/&amp;title=Hackers%E2%80%99+Project+%E2%80%93+Browser+Exploit+Code+Hiding" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/11/hackers-project-browser-exploit-code-hiding/&amp;title=Hackers%E2%80%99+Project+%E2%80%93+Browser+Exploit+Code+Hiding" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/11/hackers-project-browser-exploit-code-hiding/&amp;title=Hackers%E2%80%99+Project+%E2%80%93+Browser+Exploit+Code+Hiding" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/11/hackers-project-browser-exploit-code-hiding/&amp;title=Hackers%E2%80%99+Project+%E2%80%93+Browser+Exploit+Code+Hiding" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F11%2Fhackers-project-browser-exploit-code-hiding%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/11/hackers-project-browser-exploit-code-hiding/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Month of Browser Bugs (MoBB)</title>
		<link>http://www.darknet.org.uk/2006/07/month-of-browser-bugs-mobb/</link>
		<comments>http://www.darknet.org.uk/2006/07/month-of-browser-bugs-mobb/#comments</comments>
		<pubDate>Tue, 04 Jul 2006 18:02:27 +0000</pubDate>
		<dc:creator>Tiago Faria</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[browser-exploit]]></category>
		<category><![CDATA[browser-flaws]]></category>
		<category><![CDATA[gouki]]></category>
		<category><![CDATA[H-D-Moore]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/07/month-of-browser-bugs-mobb/</guid>
		<description><![CDATA[Get ready for a complete month of fun with H D Moore&#8217;s Month of Browser Bugs. Quoting from Browser Fun blog: This blog will serve as a dumping ground for browser-based security research and vulnerability disclosure. To kick off this blog, we are announcing the Month of Browser Bugs (MoBB), where we will publish a [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Get ready for a complete month of fun with H D Moore&#8217;s Month of Browser Bugs.</p>
<p>Quoting from <a href="http://browserfun.blogspot.com/">Browser Fun</a> blog:</p>
<blockquote><p>This blog will serve as a dumping ground for browser-based security research and vulnerability disclosure. To kick off this blog, we are announcing the Month of Browser Bugs (MoBB), where we will publish a new browser hack, every day, for the entire month of July. The hacks we publish are carefully chosen to demonstrate a concept without disclosing a direct path to remote code execution. Enjoy!</p></blockquote>
<p>He say&#8217;s he has plenty of vulnerabilities to go around.</p>
<p></p>
<p>You can also read his post at <a href="http://metasploit.blogspot.com/2006/07/month-of-browser-bugs.html">Metasploit&#8217;s blog</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Month+of+Browser+Bugs+%28MoBB%29+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D277+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/07/month-of-browser-bugs-mobb/&amp;t=Month+of+Browser+Bugs+%28MoBB%29" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/07/month-of-browser-bugs-mobb/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/07/month-of-browser-bugs-mobb/&amp;title=Month+of+Browser+Bugs+%28MoBB%29" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/07/month-of-browser-bugs-mobb/&amp;title=Month+of+Browser+Bugs+%28MoBB%29" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/07/month-of-browser-bugs-mobb/&amp;title=Month+of+Browser+Bugs+%28MoBB%29" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/07/month-of-browser-bugs-mobb/&amp;title=Month+of+Browser+Bugs+%28MoBB%29" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F07%2Fmonth-of-browser-bugs-mobb%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/07/month-of-browser-bugs-mobb/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Information about the Internet Explorer Exploit createTextRange Code Execution</title>
		<link>http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/</link>
		<comments>http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/#comments</comments>
		<pubDate>Mon, 27 Mar 2006 05:52:03 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[IE-exploit]]></category>
		<category><![CDATA[internet-explorer-exploit]]></category>
		<category><![CDATA[poc]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/</guid>
		<description><![CDATA[Internet Storm Center&#8217;s always informative Diary has some good information. At the urging of Handler Extraordinaire Kyle Haugsness, I tested the sploit on a box with software-based DEP and DropMyRights&#8230; here are the results: Software-based DEP protecting core Windows programs: sploit worked Software-based DEP protecting all programs: sploit worked DropMyRights, config&#8217;ed to allow IE to [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Internet Storm Center&#8217;s always informative Diary has some good information.</p>
<blockquote><p>At the urging of Handler Extraordinaire Kyle Haugsness, I tested the sploit on a box with software-based DEP and DropMyRights&#8230; here are the results:</p>
<p>Software-based DEP protecting core Windows programs: sploit worked<br />
Software-based DEP protecting all programs: sploit worked<br />
DropMyRights, config&#8217;ed to allow IE to run (weakest form of DropMyRights protection): sploit worked<br />
Active Scripting Disabled: sploit failed</p>
<p>So, go with the last one, if you are concerned.  By the way, you should be concerned.</p></blockquote>
<p>It didn&#8217;t take long for the exploits to appear for that IE vulnerability.  One has been making the rounds that pops the calculator up (no, I&#8217;m not going to point you to the PoC code, it is easy enough to find if you read any of the standard mailing lists), but it is a relatively trivial mod to turn that into something more destructive.  For that reason, SANS is raising Infocon to yellow for the next 24 hours.</p>
<p>Microsoft recommends you turn Active Scripting OFF to protect against this vulnerability.</p>
<p>Source: <a href="http://isc.sans.org/diary.php?storyid=1212">ISC</a></p>
<p>Yah I know, yet another reason to dump Internet Explorer and grab Firefox, not that anyone reading this site would be using Internet Exploder..</p>
<p>The code is along the lines of:</p>
<p>&lt;code&gt;&lt;input type=&#8221;checkbox&#8221; id=&#8217;c'&gt;<br />
&lt;script&gt;<br />
	r=document.getElementById(&#8220;c&#8221;);<br />
	a=r.createTextRange();<br />
&lt;/script&gt;&lt;/code&gt;</p>
<p>You can find the <a href="http://www.bleedingsnort.com/cgi-bin/viewcvs.cgi/sigs/EXPLOIT/EXPLOIT_IE_Vulnerabilities?view=markup">Bleeding Snort rule for the IE Exploit here</a>.</p>
<p><a href="http://computerworld.co.nz/news.nsf/news/E637038E81642345CC25713B0015F841">Microsoft has now confirmed this.</a></p>
<blockquote><p>&#8220;We&#8217;re still investigating, but we have confirmed this vulnerability and I am writing a Microsoft Security Advisory on this,&#8221; writes Lennart Wistrand, security program manager with the Microsoft Security Response Center, in a blog posting. &#8220;We will address it in a security update.&#8221;</p></blockquote>
<p></p>
<p>There is also a <a href="http://news.com.com/Third%20party%20offers%20temporary%20IE%20fix/2100-1002_3-6054583.html?tag=nefd.top">3rd party fix for this from eEye</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Information+about+the+Internet+Explorer+Exploit+createTextRange+Code+Execution+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D135+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/&amp;t=Information+about+the+Internet+Explorer+Exploit+createTextRange+Code+Execution" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/&amp;title=Information+about+the+Internet+Explorer+Exploit+createTextRange+Code+Execution" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/&amp;title=Information+about+the+Internet+Explorer+Exploit+createTextRange+Code+Execution" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/&amp;title=Information+about+the+Internet+Explorer+Exploit+createTextRange+Code+Execution" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/&amp;title=Information+about+the+Internet+Explorer+Exploit+createTextRange+Code+Execution" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F03%2Finformation-about-the-internet-explorer-exploit-createtextrange-code-execution%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

