<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; internet-exploder</title>
	<atom:link href="http://www.darknet.org.uk/tag/internet-exploder/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Zalewski (lcamtuf) Strikes Again &#8211; More Vulnerabilites in IE and Firefox</title>
		<link>http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/</link>
		<comments>http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/#comments</comments>
		<pubDate>Wed, 06 Jun 2007 05:12:51 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[firefox-vulnerability]]></category>
		<category><![CDATA[hacking-firefox]]></category>
		<category><![CDATA[hacking-IE]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[IE-vulnerability]]></category>
		<category><![CDATA[internet-exploder]]></category>
		<category><![CDATA[internet-explorer]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/</guid>
		<description><![CDATA[Our Polish friend and expert security researcher, Michal Zalewski (lcamtuf), known for his endless stream of vulnerabilities in all manners of software, has struck again. This time with some pretty serious flaws in both Internet Exploder Explorer and Firefox. This time it&#8217;s 4, 2 in IE and 2 in Firefox. The first which effects fully [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Our Polish friend and expert security researcher, Michal Zalewski (lcamtuf), known for his endless stream of vulnerabilities in all manners of software, has struck again.</p>
<p>This time with some pretty serious flaws in both Internet <del datetime="2007-06-06T05:03:42+00:00">Exploder</del> Explorer and Firefox. This time it&#8217;s 4, 2 in IE and 2 in Firefox.</p>
<p>The first which effects fully patched IE6 and IE7 is pretty serious and can result in cookie theft,  cooking setting, page hijacking or memory corruption.</p>
<p>It&#8217;s based on a page update Race Condition (aka bait and switch vuln).</p>
<blockquote><p>When Javascript code instructs MSIE6/7 to navigate away from a page that meets same-domain origin policy (and hence can be scriptually accessed and modified by the attacker) to an unrelated third-party site, there is a window of opportunity for concurrently executed Javascript to perform actions with the permissions for the old page, but actual content for the newly loaded page</p></blockquote>
<p>The demo can be found here:</p>
<p><a href="http://lcamtuf.coredump.cx/ierace/">http://lcamtuf.coredump.cx/ierace/</a></p>
<p>The more serious of the two Firefox flaws is marked MAJOR and not CRITICAL and deals with the way the browser handles IFRAMEs (Cross-site IFRAME hijacking)</p>
<blockquote><p>Javascript can be used to inject malicious code, including key-snooping event handlers, on pages that rely on IFRAMEs to display contents or store state data / communicate with the server.</p></blockquote>
<p>A demo can be found here:</p>
<p><a href="http://lcamtuf.coredump.cx/ifsnatch/">http://lcamtuf.coredump.cx/ifsnatch/</a></p>
<p>The full e-mail with details of his vulnerabilities can be found here:</p>
<p><a href="http://lists.grok.org.uk/pipermail/full-disclosure/2007-June/063712.html">[Full-disclosure] Assorted browser vulnerabilities</a></p>
<p></p>
<p>You can also read more at <a href="http://www.theregister.co.uk/2007/06/05/browser_vulns_identified/">The Register</a> or <a href="http://www.eweek.com/article2/0,1759,2141952,00.asp">eWeek</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Zalewski+%28lcamtuf%29+Strikes+Again+%E2%80%93+More+Vulnerabilites+in+IE+and+Firefox+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D594+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/&amp;t=Zalewski+%28lcamtuf%29+Strikes+Again+%E2%80%93+More+Vulnerabilites+in+IE+and+Firefox" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/&amp;title=Zalewski+%28lcamtuf%29+Strikes+Again+%E2%80%93+More+Vulnerabilites+in+IE+and+Firefox" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/&amp;title=Zalewski+%28lcamtuf%29+Strikes+Again+%E2%80%93+More+Vulnerabilites+in+IE+and+Firefox" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/&amp;title=Zalewski+%28lcamtuf%29+Strikes+Again+%E2%80%93+More+Vulnerabilites+in+IE+and+Firefox" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/&amp;title=Zalewski+%28lcamtuf%29+Strikes+Again+%E2%80%93+More+Vulnerabilites+in+IE+and+Firefox" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F06%2Fzalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/06/zalewski-lcamtuf-strikes-again-more-vulnerabilites-in-ie-and-firefox/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>3Com&#8217;s TippingPoint Finds New IE Vulnerabilities</title>
		<link>http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/</link>
		<comments>http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/#comments</comments>
		<pubDate>Tue, 20 Jun 2006 07:27:29 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[3com]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[internet-exploder]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[intrusion-detection]]></category>
		<category><![CDATA[intrusion-prevention]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[tippingpoint]]></category>
		<category><![CDATA[vunerabilities]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/</guid>
		<description><![CDATA[What? New vulnerabilities in Internet Explorer? You can hack Internet Exploder Explorer? Never! 3Com Corp&#8217;s TippingPoint division has discovered and disclosed two critical new vulnerabilities in Microsoft&#8217;s Internet Explorer through 3Com&#8217;s Zero Day Initiative (ZDI). The vulnerabilities could have allowed an attacker to gain control of a PC if the user was logged in with [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>What? New vulnerabilities in Internet Explorer?</p>
<p>You can hack Internet <del datetime="2006-06-20T04:39:29+00:00">Exploder</del> Explorer? Never!</p>
<blockquote><p>3Com Corp&#8217;s TippingPoint division has discovered and disclosed two critical new vulnerabilities in Microsoft&#8217;s Internet Explorer through 3Com&#8217;s Zero Day Initiative (ZDI). </p>
<p>The vulnerabilities could have allowed an attacker to gain control of a PC if the user was logged in with administrative rights. </p></blockquote>
<p>Sounds a bit like an advert for TippingPoint to me.</p>
<blockquote><p>Under the ZDI, 3Com rewards researchers who, while keeping the vulnerabilities confidential, alert 3Com to these vulnerabilities. </p>
<p>3Com can in turn alert the software vendor so that a patch can be prepared, while IPS prepares the security filter and distributes it to customers.</p></blockquote>
<p>Interesting initiative though.</p>
<p></p>
<p>Source: <a href="http://star-techcentral.com/tech/story.asp?file=/2006/6/20/technology/20060620093012&#038;sec=technology">The Star</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=3Com%E2%80%99s+TippingPoint+Finds+New+IE+Vulnerabilities+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D259+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/&amp;t=3Com%E2%80%99s+TippingPoint+Finds+New+IE+Vulnerabilities" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/&amp;title=3Com%E2%80%99s+TippingPoint+Finds+New+IE+Vulnerabilities" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/&amp;title=3Com%E2%80%99s+TippingPoint+Finds+New+IE+Vulnerabilities" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/&amp;title=3Com%E2%80%99s+TippingPoint+Finds+New+IE+Vulnerabilities" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/&amp;title=3Com%E2%80%99s+TippingPoint+Finds+New+IE+Vulnerabilities" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F06%2F3coms-tippingpoint-finds-new-ie-vulnerabilities%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/06/3coms-tippingpoint-finds-new-ie-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Proof of Concept for Internet Explorer Modal Dialog Exploit</title>
		<link>http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/</link>
		<comments>http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/#comments</comments>
		<pubDate>Tue, 02 May 2006 03:32:48 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[IE-exploit]]></category>
		<category><![CDATA[internet-exploder]]></category>
		<category><![CDATA[internet-explorer-exploit]]></category>
		<category><![CDATA[modal-dialog]]></category>
		<category><![CDATA[proof-of-concept]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/</guid>
		<description><![CDATA[Pretty interesting and imaginative way to exploit the flaw in IE&#8230;yeah I know linked to ActiveX again, all the more reason to use Firefox right? It just shows that the browser really is a point of entry, this could be useful for a penetration test, another way to show how easy it is to get [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Pretty interesting and imaginative way to exploit the flaw in IE&#8230;yeah I know linked to ActiveX again, all the more reason to use Firefox right?</p>
<p>It just shows that the browser really is a point of entry, this could be useful for a penetration test, another way to show how easy it is to get in via internet explorer, the frequency with which IE exploits have been coming out recently is scarier than normal.</p>
<blockquote><p>A particular scenario was identified that involved the exploitation of the modal ActiveX prompt delivered by some systems.  The user is asked to type a certain string of characters (ala captcha).  A prompt will be displayed (hopefully during the time the user is typing the string) to install the Microsoft Surround Video Control.</p>
<p>If you&#8217;re still typing the &#8220;captcha&#8221; when the prompt appears, you&#8217;ll install the control.  This works as advertised against all systems EXCEPT Windows XP SP2 and Windows Server 2003 SP1.  If the software you install hoses your box, just remember that it&#8217;s signed by Microsoft.  In<br />
other words&#8230; don&#8217;t look at me.</p></blockquote>
<p>You can check the PoC here:</p>
<p><a href="http://www.darknet.org.uk/content/ie_modal_test.html">Proof of Concept for IE Modal Dialog Issue</a></p>
<p>It just crashes IE for me, I&#8217;m not sure if it&#8217;s a null pointer or what, but I&#8217;m sure there&#8217;s some way to exploit it to take over the machine, it&#8217;s a another vulnerability, which usually can be mashed together with a couple of others to get complete control.</p>
<p></p>
<p>By Matthew Murphy spotted on Vulnwatch</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Proof+of+Concept+for+Internet+Explorer+Modal+Dialog+Exploit+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D169+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/&amp;t=Proof+of+Concept+for+Internet+Explorer+Modal+Dialog+Exploit" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/&amp;title=Proof+of+Concept+for+Internet+Explorer+Modal+Dialog+Exploit" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/&amp;title=Proof+of+Concept+for+Internet+Explorer+Modal+Dialog+Exploit" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/&amp;title=Proof+of+Concept+for+Internet+Explorer+Modal+Dialog+Exploit" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/&amp;title=Proof+of+Concept+for+Internet+Explorer+Modal+Dialog+Exploit" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F05%2Fproof-of-concept-for-internet-explorer-modal-dialog-exploit%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/05/proof-of-concept-for-internet-explorer-modal-dialog-exploit/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>New Critical MEGApatch fixes 10 Vulnerabilities in Internet Explorer</title>
		<link>http://www.darknet.org.uk/2006/04/new-critical-megapatch-fixes-10-vulnerabilities-in-internet-explorer/</link>
		<comments>http://www.darknet.org.uk/2006/04/new-critical-megapatch-fixes-10-vulnerabilities-in-internet-explorer/#comments</comments>
		<pubDate>Thu, 13 Apr 2006 02:18:33 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[IE-exploit]]></category>
		<category><![CDATA[internet-exploder]]></category>
		<category><![CDATA[internet-explorer-exploit]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/04/new-critical-megapatch-fixes-10-vulnerabilities-in-internet-explorer/</guid>
		<description><![CDATA[Well how many does that leave unpatched? 30+ if I remember correctly from the PivX page that got taken down mysteriously. Microsoft on Tuesday released a &#8220;critical&#8221; Internet Explorer update that fixes 10 vulnerabilities in the Web browser, including a high-profile bug that is already being used in cyberattacks. The Redmond, Wash., software giant sent [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Well how many does that leave unpatched? 30+ if I remember correctly from the PivX page that got taken down mysteriously.</p>
<blockquote><p>Microsoft on Tuesday released a &#8220;critical&#8221; Internet Explorer update that fixes 10 vulnerabilities in the Web browser, including a <strong>high-profile bug that is already being used</strong> in cyberattacks.</p>
<p>The Redmond, Wash., software giant sent out the IE megafix as part of its monthly Patch Tuesday cycle of bulletins. In addition, Microsoft delivered two bulletins for &#8220;critical&#8221; Windows flaws, one for an &#8220;important&#8221; vulnerability in Outlook Express and one for a &#8220;moderate&#8221; bug in a component of FrontPage and SharePoint. </p></blockquote>
<p>I think this whole Patch Tuesday is a stupid idea in itself, why can&#8217;t they release patches for critical vulnerabilities ASAP?</p>
<p>Some pretty scary news though eh? For normal users anyway.</p>
<blockquote><p>Eight of the 10 vulnerabilities repaired by the IE update could be abused to gain complete control over a Windows computer running vulnerable versions of the Web browser.</p></blockquote>
<p>Apparently they say, only one has been used&#8230;the one we talked about previously (<a href="http://www.darknet.org.uk/2006/03/information-about-the-internet-explorer-exploit-createtextrange-code-execution/">The CreateTextRange Exploit</a>).</p>
<blockquote><p>According to Microsoft&#8217;s bulletin, three of the 10 vulnerabilities fixed by the update had been publicly disclosed. Only the CreateTextRange flaw was being exploited in attacks, the software maker said.</p></blockquote>
<p>Basically you can get complete control of the machine just by getting a user to visit a maliciously built web page, good stuff!</p>
<p></p>
<p>Source: <a href="http://news.com.com/Critical+megapatch+sews+up+10+holes+in+IE/2100-1002_3-6060038.html?tag=nefd.lede">News.com</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=New+Critical+MEGApatch+fixes+10+Vulnerabilities+in+Internet+Explorer+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D149+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/04/new-critical-megapatch-fixes-10-vulnerabilities-in-internet-explorer/&amp;t=New+Critical+MEGApatch+fixes+10+Vulnerabilities+in+Internet+Explorer" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/04/new-critical-megapatch-fixes-10-vulnerabilities-in-internet-explorer/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/04/new-critical-megapatch-fixes-10-vulnerabilities-in-internet-explorer/&amp;title=New+Critical+MEGApatch+fixes+10+Vulnerabilities+in+Internet+Explorer" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/04/new-critical-megapatch-fixes-10-vulnerabilities-in-internet-explorer/&amp;title=New+Critical+MEGApatch+fixes+10+Vulnerabilities+in+Internet+Explorer" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/04/new-critical-megapatch-fixes-10-vulnerabilities-in-internet-explorer/&amp;title=New+Critical+MEGApatch+fixes+10+Vulnerabilities+in+Internet+Explorer" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/04/new-critical-megapatch-fixes-10-vulnerabilities-in-internet-explorer/&amp;title=New+Critical+MEGApatch+fixes+10+Vulnerabilities+in+Internet+Explorer" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F04%2Fnew-critical-megapatch-fixes-10-vulnerabilities-in-internet-explorer%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/04/new-critical-megapatch-fixes-10-vulnerabilities-in-internet-explorer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

