<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; ie7</title>
	<atom:link href="http://www.darknet.org.uk/tag/ie7/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>IE7 Exploit Also Affects IE5, IE6 and IE8! More Users In Trouble</title>
		<link>http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/</link>
		<comments>http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/#comments</comments>
		<pubDate>Mon, 15 Dec 2008 08:41:59 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[0 day exploit]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[0day ie exploit]]></category>
		<category><![CDATA[hacking internet explorer]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[IE-exploit]]></category>
		<category><![CDATA[ie5 exploit]]></category>
		<category><![CDATA[ie6 exploit]]></category>
		<category><![CDATA[ie7]]></category>
		<category><![CDATA[ie7 exploit]]></category>
		<category><![CDATA[ie8 exploit]]></category>
		<category><![CDATA[internet explorer security]]></category>
		<category><![CDATA[internet explorer vulnerability]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[internet-explorer-7]]></category>
		<category><![CDATA[internet-explorer-exploit]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[windows vulnerability]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1313</guid>
		<description><![CDATA[I&#8217;m sure you&#8217;ve heard about the Microsoft IE7 Exploit that allows Remote Code Execution on XP &#038; Vista, it turns out it&#8217;s actually much worse than first expected. The exploit also affects IE5.01, IE6 and IE8 on all OS versions! That&#8217;s a pretty worrying turn of events for MS especially as they are seemingly leaving [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>I&#8217;m sure you&#8217;ve heard about the <a href="http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/">Microsoft IE7 Exploit that allows Remote Code Execution on XP &#038; Vista</a>, it turns out it&#8217;s actually much worse than first expected.</p>
<p>The exploit also affects IE5.01, IE6 and IE8 on all OS versions! That&#8217;s a pretty worrying turn of events for MS especially as they are seemingly leaving it unpatched.</p>
<p>You can find a clarification of the various workarounds for the IE flaw <a href="http://blogs.technet.com/swi/archive/2008/12/12/Clarification-on-the-various-workarounds-from-the-recent-IE-advisory.aspx">on Technet here</a>.</p>
<blockquote><p>Researchers are warning that the unpatched security vulnerability in Microsoft&#8217;s Internet Explorer affects more versions of the browser than previously thought, and that steps users must take to prevent exploitation are harder than first published.</p>
<p>According to an <a href="http://www.microsoft.com/technet/security/advisory/961051.mspx">updated advisory from Redmond</a>, the bug that&#8217;s been actively exploited since Tuesday bites versions 5.01, 6, and 8 of the browser, which is by far the most widely used on the web. A previous warning from Microsoft only said that IE 7 was susceptible to the attacks. IE is susceptible when running on all supported versions of the Windows operating systems, Microsoft also says.</p>
<p>What&#8217;s more, while there is some protection from Vista&#8217;s User Account Control, the measure doesn&#8217;t altogether prevent the attack, according to <a href="http://msmvps.com/blogs/spywaresucks/archive/2008/12/12/1656545.aspx">this post</a> on the Spyware Sucks blog. Microsoft and others have suggested that those who must use IE in the next few weeks set the security level to high for the internet security zone or disable active scripting. These are sensible measures, but they don&#8217;t guarantee you won&#8217;t be pwned, according to <a href="http://secunia.com/blog/38/">this post</a> from the Secunia blog.</p></blockquote>
<p>Once again Firefox users for the win, this is a flaw in the whole family of Internet Explorer and must effect a shocking amount of users. I guess setting your Security Zone to high and disabling Active Scripting helps but then it also disables a lot of features on a lot of sites.</p>
<p>So you are losing out on the user experience of the web just to be more secure, mostly because Microsoft doesn&#8217;t want to release an ad-hoc patch.</p>
<p>Well <a href="http://www.google.com/chrome">Google Chrome</a> final version is out now too, so there&#8217;s another option for people.</p>
<blockquote><p>Secunia goes on to revise what it says is the cause of the vulnerability. Contrary to <a href="http://www.theregister.co.uk/2008/12/09/zero_day_ie_flaw_exploited/">earlier reports</a> that pinned the blame on the way IE handles certain types of data that use the extensible markup language, or XML, format, the true cause is faulty data binding, meaning exploit code need not use XML.</p>
<p>Microsoft has yet to say whether it plans to issue a fix ahead of next month&#8217;s scheduled release. For the moment, the volume of in-the-wild attacks remains relatively modest and limited mostly to sites based in China. But because attackers are injecting exploits into legitimate sites that have been compromised, we continue to recommend that users steer clear of IE until the hole has been closed.</p>
<p>Plenty of other researchers have weighed in with additional details about the flaw. Links from <a href="http://isc.sans.org/diary.html?storyid=5470">SANS</a>, <a href="http://www.sophos.com/security/blog/2008/12/2204.html">Sophos</a> and <a href="http://hackademix.net/2008/12/12/more-bad-news-for-ie-users/">Hackademix</a>.</p></blockquote>
<p>I think an imminent danger is if people start using iframe vulnerabilies and XSS to inject this exploit into some more prominent sites &#8211; that could cause a huge spread of infections!</p>
<p>Anyway just let people using IE know that this is another reason they shouldn&#8217;t be using it! Show them how to download and install Firefox and please teach them to use Tabs!</p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2008/12/12/ie_zero_day_misconceptions/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=IE7+Exploit+Also+Affects+IE5%2C+IE6+and+IE8%21+More+Users+In+Trouble+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1313+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/&amp;t=IE7+Exploit+Also+Affects+IE5%2C+IE6+and+IE8%21+More+Users+In+Trouble" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/&amp;title=IE7+Exploit+Also+Affects+IE5%2C+IE6+and+IE8%21+More+Users+In+Trouble" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/&amp;title=IE7+Exploit+Also+Affects+IE5%2C+IE6+and+IE8%21+More+Users+In+Trouble" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/&amp;title=IE7+Exploit+Also+Affects+IE5%2C+IE6+and+IE8%21+More+Users+In+Trouble" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/&amp;title=IE7+Exploit+Also+Affects+IE5%2C+IE6+and+IE8%21+More+Users+In+Trouble" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F12%2Fie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Microsoft IE7 Exploit Allows Remote Code Execution on XP &amp; Vista</title>
		<link>http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/</link>
		<comments>http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/#comments</comments>
		<pubDate>Thu, 11 Dec 2008 08:43:09 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[0 day exploit]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[0day ie exploit]]></category>
		<category><![CDATA[hacking internet explorer]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[IE-exploit]]></category>
		<category><![CDATA[ie7]]></category>
		<category><![CDATA[ie7 exploit]]></category>
		<category><![CDATA[internet explorer security]]></category>
		<category><![CDATA[internet explorer vulnerability]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[internet-explorer-7]]></category>
		<category><![CDATA[internet-explorer-exploit]]></category>
		<category><![CDATA[patch-tuesday]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[windows vulnerability]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1303</guid>
		<description><![CDATA[It seems a new, fairly serious flaw has been discovered in Internet Explorer 7 &#8211; and as accounts go it&#8217;s been around for a couple of months in the underground. The worrying part is, patch Tuesday was yesterday and after testing it&#8217;s been discovered that this flaw WAS NOT patched in the updates. ISC reports [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>It seems a new, fairly serious flaw has been discovered in Internet Explorer 7 &#8211; and as accounts go it&#8217;s been around for a couple of months in the underground.</p>
<p>The worrying part is, <a href="http://www.darknet.org.uk/tag/patch-tuesday/">patch Tuesday</a> was yesterday and after testing it&#8217;s been discovered that this flaw <strong>WAS NOT</strong> patched in the updates.</p>
<p><a href="http://isc.sans.org/diary.html?storyid=5458">ISC reports</a> that it&#8217;s not currently widely used, but it has been found in the wild.</p>
<blockquote><p>Microsoft said it is investigating reports that a new exploit is going around that takes advantage of an unpatched security hole in Internet Explorer 7.</p>
<p>The SANS Internet Storm Center, which tracks hacking trends, said today that while the exploit does not appear to be widely in use at the moment, that situation is likely to change soon, since instructions showing criminals how to take advantage of this flaw have been posted online.</p>
<p>SANS emphasizes that this vulnerability is not one that was fixed in the massive bundle of patches that Microsoft issued yesterday. It is not clear what steps users can take to protect themselves against this threat, other than to browse the Web with something other than IE, such as Mozilla Firefox or Opera. This appears to be the type of vulnerability that could be used to give attackers complete control over an affected system merely by convincing users to browse to a specially-crafted hacked or malicious Web site. </p></blockquote>
<p>It seems the safest thing is not to use IE, which I personally have been doing since about 1998 anyway. But still, some people claim they have problems with Java or JavaScript or AJAX enabled sites with Firefox.</p>
<p>There&#8217;s always Opera, or even the new Google Chrome.</p>
<p>This exploit is a serious one as someone only needs to visit the site and remote code can be injected into their OS and executed.</p>
<blockquote><p>According to SANS, the exploit works against fully-patched Windows XP and Windows 2003 systems with Internet Explorer 7.</p>
<p>In a statement e-mailed to Security Fix, Microsoft said once it is done with its investigation, the company &#8220;will take appropriate action to help protect customers. This may include providing a security update through the monthly release process, an out-of-cycle update or additional guidance to help customers protect themselves.&#8221; </p></blockquote>
<p>Once again it&#8217;s demonstrated how stupid &#8216;Patch Tuesday&#8217; is and how half of the people on the Internet are going to be vulnerable to this serious flaw until the first Tuesday in January.</p>
<p>I really hope Microsoft pushes out an emergency patch outside their schedule ASAP.</p>
<p>You can find a list of the sites known to be distributing the code on <a href="http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20081210">Shadowserver here</a>.</p>
<p></p>
<p>Source: <a href="http://voices.washingtonpost.com/securityfix/2008/12/exploit_for_unpatched_internet.html?nav=rss_blog">Security Fix</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+IE7+Exploit+Allows+Remote+Code+Execution+on+XP+%26+Vista+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1303+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/&amp;t=Microsoft+IE7+Exploit+Allows+Remote+Code+Execution+on+XP+%26+Vista" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/&amp;title=Microsoft+IE7+Exploit+Allows+Remote+Code+Execution+on+XP+%26+Vista" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/&amp;title=Microsoft+IE7+Exploit+Allows+Remote+Code+Execution+on+XP+%26+Vista" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/&amp;title=Microsoft+IE7+Exploit+Allows+Remote+Code+Execution+on+XP+%26+Vista" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/&amp;title=Microsoft+IE7+Exploit+Allows+Remote+Code+Execution+on+XP+%26+Vista" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F12%2Fmicrosoft-ie7-exploit-allows-remote-code-execution-on-xp-vista%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Microsoft Plugs 11 Serious Flaws in December Update</title>
		<link>http://www.darknet.org.uk/2007/12/microsoft-plugs-11-serious-flaws-in-december-update/</link>
		<comments>http://www.darknet.org.uk/2007/12/microsoft-plugs-11-serious-flaws-in-december-update/#comments</comments>
		<pubDate>Thu, 13 Dec 2007 09:25:17 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[december update]]></category>
		<category><![CDATA[hacking internet explorer]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[IE6]]></category>
		<category><![CDATA[ie7]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[vista-vulnerabilities]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[windows flaws]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/12/microsoft-plugs-11-serious-flaws-in-december-update/</guid>
		<description><![CDATA[Seen as though we&#8217;ve been having a good bash on Microsoft recently, here&#8217;s some more relevant news. The December update from Microsoft has delivered patches for 11 series flaws spanning both IE6 &#038; IE7 and all their currently supported operating systems (Windows 2000, Windows XP and Windows Vista). So if you are running Windows, make [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Seen as though we&#8217;ve been having a good bash on Microsoft recently, here&#8217;s some more relevant news. The December update from Microsoft has delivered patches for 11 series flaws spanning both IE6 &#038; IE7 and all their currently supported operating systems (Windows 2000, Windows XP and Windows Vista).</p>
<p>So if you are running Windows, make sure you get your updates downloaded and installed before you&#8217;re away from your PC during this festive season.</p>
<blockquote><p>Microsoft today released software updates to plug at least 11 security holes in PCs powered by its Windows operating systems and other software. Windows users can download the fixes either directly through the Microsoft Update Web site or via Automatic Updates.</p>
<p>December&#8217;s seven update bundles includes fixes for four separate security holes in Internet Explorer 6 and IE7, vulnerabilities that are considered critical for Windows 2000, Windows XP and Windows Vista users. Microsoft rates a flaw &#8220;critical&#8221; if it can be exploited to break into vulnerable systems with little or no help from the user, save perhaps for browsing a Web site or by clicking on a malicious link in an e-mail or instant message. </p></blockquote>
<p>Seems like even though Internet <del datetime="2007-12-13T07:37:05+00:00">Exploder</del> Explorer is such a &#8216;stable&#8217; and &#8216;mature&#8217; product &#8211; it&#8217;s not immune to serious problems. I&#8217;m sorry but it&#8217;s a web-browser..how complicated can it be!</p>
<blockquote><p>Microsoft also issued critical updates to fix at least two different problems with the way Windows handles the processing and display of various video and audio files. The first of those is a serious vulnerability in the &#8220;Windows media file format&#8221; &#8212; chiefly, files that end in &#8220;.asf&#8221; and &#8220;.wmv&#8221; &#8212; used principally by the Windows Media Player software bundled with the operating system. Another patch addresses a critical flaw in most versions of &#8220;DirectX,&#8221; a Windows component that handles the display of a variety of video file formats (files that end in &#8220;.wav&#8221; and &#8220;.avi&#8221; for example). Again, these are especially dangerous flaws because they can be exploited merely by getting users to view maliciously crafted video files via a Web browser or e-mail.</p>
<p><strong>Of the seven patch bundles released today, only two did not affect Windows Vista systems, suggesting that the vulnerable components were carried over into Vista from older versions of the OS despite the multi-year secure coding review conducted for Vista. That said, two of the bundles were released to plug security holes that were found exclusively in Vista.</strong> </p></blockquote>
<p>This news directly related to what we have been discussing recently, how previous Windows flaws carry over into the supposidly &#8216;all-new&#8217; Windows Vista.</p>
<p>Only <strong>TWO</strong> of the problems did not effect Vista, which shows that the problems that effect an <strong>OLD</strong> (8 years old now) OS like Windows 2000 are still effecting Vista.</p>
<p></p>
<p>Source: <a href="http://blog.washingtonpost.com/securityfix/2007/12/microsoft_plugs_11_windows_sec.html">Security Fix</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+Plugs+11+Serious+Flaws+in+December+Update+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D766+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/12/microsoft-plugs-11-serious-flaws-in-december-update/&amp;t=Microsoft+Plugs+11+Serious+Flaws+in+December+Update" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/12/microsoft-plugs-11-serious-flaws-in-december-update/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/12/microsoft-plugs-11-serious-flaws-in-december-update/&amp;title=Microsoft+Plugs+11+Serious+Flaws+in+December+Update" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/12/microsoft-plugs-11-serious-flaws-in-december-update/&amp;title=Microsoft+Plugs+11+Serious+Flaws+in+December+Update" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/12/microsoft-plugs-11-serious-flaws-in-december-update/&amp;title=Microsoft+Plugs+11+Serious+Flaws+in+December+Update" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/12/microsoft-plugs-11-serious-flaws-in-december-update/&amp;title=Microsoft+Plugs+11+Serious+Flaws+in+December+Update" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F12%2Fmicrosoft-plugs-11-serious-flaws-in-december-update%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/12/microsoft-plugs-11-serious-flaws-in-december-update/feed/</wfw:commentRss>
		<slash:comments>27</slash:comments>
		</item>
		<item>
		<title>IE 7 Flaw Could Help Phishers &#8211; Error Message Processing</title>
		<link>http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/</link>
		<comments>http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/#comments</comments>
		<pubDate>Wed, 18 Apr 2007 08:03:18 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[hacking-ie7]]></category>
		<category><![CDATA[ie7]]></category>
		<category><![CDATA[ie7-flaw]]></category>
		<category><![CDATA[internet-explorer-7]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/</guid>
		<description><![CDATA[Ah another way for phishers and people wanting to steal login credentials to con IE7 users. Yet another reason to use Firefox or Opera? Not saying these browsers are perfect&#8230;but look at the amount of problems Internet Exploder Explorer has had. The flaw lies in the way IE7 processes a locally stored HTML error message [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Ah another way for phishers and people wanting to steal login credentials to con IE7 users.</p>
<p>Yet another reason to use Firefox or Opera?</p>
<p>Not saying these browsers are perfect&#8230;but look at the amount of problems Internet <del datetime="2007-04-18T07:58:30+00:00">Exploder</del> Explorer has had.</p>
<blockquote><p>The flaw lies in the way IE7 processes a locally stored HTML error message page that is typically shown when the user cancels the loading of a Web page, said Aviv Raff, a security researcher based in Israel.</p>
<p>The error message tells the user that &#8220;navigation to the Web page was canceled,&#8221; and offers the user the opportunity to &#8220;refresh the page.&#8221; If the refresh link is clicked, IE can be tricked into displaying the wrong Web address for a page. Raff has published proof of concept code that shows how IE can be made to display a Web page on his Web site as if it is from the cnn.com domain. </p></blockquote>
<p>I&#8217;m not sure if any phishers would go to this length to try and con people into visiting their sites, but with some of the creative things they&#8217;ve been coming up with lately, it wouldn&#8217;t surprise me!</p>
<blockquote><p>This flaw could be exploited by phishers who want to make their spoofed Web sites appear legitimate, Raff said.</p>
<p>&#8220;I can inject a script that will display anything I want in the page when the user clicks the &#8216;refresh&#8217; link,&#8221; he said via instant message. &#8220;Combining this with the design flaw, an attacker can render in the browser whatever he wants with whatever URL he wants in the address bar.&#8221;</p>
<p>This type of bug is known as a cross-site scripting vulnerability. It affects IE 7 on Vista and Windows XP, Raff added.</p></blockquote>
<p>Vista is vulnerable too, so be careful. And don&#8217;t use IE!</p>
<p><em>Yes this article was originally published about a month ago, we know that&#8230;.thanks.</em></p>
<p></p>
<p>Source: <a href="http://www.networkworld.com/news/2007/031407-new-ie-7-bug-could.html?fsrc=rss-security">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=IE+7+Flaw+Could+Help+Phishers+%E2%80%93+Error+Message+Processing+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D508+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/&amp;t=IE+7+Flaw+Could+Help+Phishers+%E2%80%93+Error+Message+Processing" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/&amp;title=IE+7+Flaw+Could+Help+Phishers+%E2%80%93+Error+Message+Processing" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/&amp;title=IE+7+Flaw+Could+Help+Phishers+%E2%80%93+Error+Message+Processing" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/&amp;title=IE+7+Flaw+Could+Help+Phishers+%E2%80%93+Error+Message+Processing" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/&amp;title=IE+7+Flaw+Could+Help+Phishers+%E2%80%93+Error+Message+Processing" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F04%2Fie-7-flaw-could-help-phishers-error-message-processing%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/04/ie-7-flaw-could-help-phishers-error-message-processing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Internet Explorer 7 (IE7) Vulnerability Hits the Streets</title>
		<link>http://www.darknet.org.uk/2006/12/internet-explorer-7-ie7-vulnerability-hits-the-streets/</link>
		<comments>http://www.darknet.org.uk/2006/12/internet-explorer-7-ie7-vulnerability-hits-the-streets/#comments</comments>
		<pubDate>Mon, 04 Dec 2006 16:11:45 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[explorer-7]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[ie-7]]></category>
		<category><![CDATA[ie7]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[internet-explorer-7]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[vista]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/12/internet-explorer-7-ie7-vulnerability-hits-the-streets/</guid>
		<description><![CDATA[This was a while back, but with Microsoft&#8217;s security record it&#8217;s pretty much inevitable.. Even before release (as with Vista) flaws were found. Introduction A vulnerability has been discovered in Internet Explorer, which can be exploited by malicious people to disclose potentially sensitive information. Please use the test below, to see an example of how [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>This was a while back, but with Microsoft&#8217;s security record it&#8217;s pretty much inevitable..</p>
<p>Even before release (as with Vista) flaws were found.</p>
<p><strong>Introduction</strong></p>
<p>A vulnerability has been discovered in Internet Explorer, which can be exploited by malicious people to disclose potentially sensitive information.</p>
<p>Please use the test below, to see an example of how this vulnerability can be exploited, and also to determine whether or not your browser is vulnerable.</p>
<p><strong>Test Case / Demonstration</strong></p>
<p>The test will try to read content from http://news.google.com/ in the context of your browser.</p>
<p>Follow the source link below for the test.</p>
<p>So much for the &#8220;You wanted it easier and more secure&#8221; slogan found on Microsoft&#8217;s IE Website.</p>
<p></p>
<p>Source: <a href="http://secunia.com/Internet_Explorer_Arbitrary_Content_Disclosure_Vulnerability_Test/">Secunia</a</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Internet+Explorer+7+%28IE7%29+Vulnerability+Hits+the+Streets+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D378+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/12/internet-explorer-7-ie7-vulnerability-hits-the-streets/&amp;t=Internet+Explorer+7+%28IE7%29+Vulnerability+Hits+the+Streets" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/12/internet-explorer-7-ie7-vulnerability-hits-the-streets/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/12/internet-explorer-7-ie7-vulnerability-hits-the-streets/&amp;title=Internet+Explorer+7+%28IE7%29+Vulnerability+Hits+the+Streets" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/12/internet-explorer-7-ie7-vulnerability-hits-the-streets/&amp;title=Internet+Explorer+7+%28IE7%29+Vulnerability+Hits+the+Streets" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/12/internet-explorer-7-ie7-vulnerability-hits-the-streets/&amp;title=Internet+Explorer+7+%28IE7%29+Vulnerability+Hits+the+Streets" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/12/internet-explorer-7-ie7-vulnerability-hits-the-streets/&amp;title=Internet+Explorer+7+%28IE7%29+Vulnerability+Hits+the+Streets" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F12%2Finternet-explorer-7-ie7-vulnerability-hits-the-streets%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/12/internet-explorer-7-ie7-vulnerability-hits-the-streets/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

