<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; internet explorer vulnerability</title>
	<atom:link href="http://www.darknet.org.uk/tag/internet-explorer-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Microsoft Investigates IE CSS Cross-Origin Theft Vulnerability</title>
		<link>http://www.darknet.org.uk/2010/09/microsoft-investigate-ie-css-cross-origin-theft-vulnerability/</link>
		<comments>http://www.darknet.org.uk/2010/09/microsoft-investigate-ie-css-cross-origin-theft-vulnerability/#comments</comments>
		<pubDate>Wed, 08 Sep 2010 09:53:41 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[chris evans]]></category>
		<category><![CDATA[cross origin theft vulnerability]]></category>
		<category><![CDATA[css cross origin theft]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[IE-security]]></category>
		<category><![CDATA[ie8]]></category>
		<category><![CDATA[internet explorer security]]></category>
		<category><![CDATA[internet explorer vulnerability]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[internet-explorer-exploit]]></category>
		<category><![CDATA[poc]]></category>
		<category><![CDATA[proof-of-concept]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2946</guid>
		<description><![CDATA[There&#8217;s a lot of circumstantial evidence surround this as Microsoft themselves haven&#8217;t clarified or publicly announced anything related to the CSS Cross-Origin Theft bug &#8211; but it seems fairly clear. Some media sources are quoting it as a &#8216;new bug&#8216; &#8211; which it isn&#8217;t, according to other sources it has been known about for at [...]]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s a lot of circumstantial evidence surround this as <a href="http://www.darknet.org.uk/tag/microsoft/">Microsoft</a> themselves haven&#8217;t clarified or publicly announced anything related to the CSS Cross-Origin Theft bug &#8211; but it seems fairly clear.</p>
<p>Some media sources are quoting it as a &#8216;<a href="http://www.theregister.co.uk/2010/09/06/mystery_ie_bug/">new bug</a>&#8216; &#8211; which it isn&#8217;t, according to other sources it has been known about for at least 2 years and one paper has traced it back as far as 2002 (<a href="http://websec.sv.cmu.edu/css/css.pdf">PDF file</a>).</p>
<blockquote><p>Microsoft last Friday said it was looking into a long-known vulnerability in Internet Explorer (IE) that could be used to access users&#8217; data and Web-based accounts.</p>
<p>The bug can allow hackers to hijack Web mail accounts, steal data and send illicit tweets, said Google security engineer Chris Evans in a message posted on the Full Disclosure mailing list. Evans also published a demonstration that showed how the flaw in IE8 could be used to commandeer a user&#8217;s Twitter account and send unauthorized tweets.</p>
<p>The vulnerability, known as a &#8220;CSS cross-origin theft&#8221; bug, has a long history. Researchers at Carnegie Mellon University, who recently published a paper on the subject, have traced it back as far as 2002. Those researchers will present their paper at the Conference on Computer and Communications Security next month. Even so, the flaw received little attention until Evans blogged about it in December 2009. He had submitted a bug report for Chrome eight months earlier. </p></blockquote>
<p>Microsoft <a href="http://twitter.com/msftsecresponse/statuses/22934606564">did Tweet about</a> looking into something but haven&#8217;t named it although coincidentally it was just a few hours after the <a href="http://seclists.org/fulldisclosure/2010/Sep/64">public disclosure</a> of this flaw. A point of contention is that this bug has been known about for a long time and has been patched by all the other major browsers including <a href="http://www.darknet.org.uk/tag/chrome/">Chrome</a> and <a href="http://www.darknet.org.uk/tag/firefox/">Firefox</a>.</p>
<p>Another interesting point is that Chris Evans is actually a <a href="http://www.darknet.org.uk/tag/google/">Google</a> engineer. Earlier this year <a href="http://www.darknet.org.uk/tag/tavis-ormandy/">Tavis Ormandy</a> went public with a serious flaw in Windows once again stating Microsoft was unwilling to address it.</p>
<blockquote><p>Although Microsoft has not patched the vulnerability in IE8, other browsers, including Firefox, Chrome, Safari and Opera, have fixed the flaw. Google patched the bug in Chrome last January, while Mozilla did the same in July with Firefox 3.6.7 and Firefox 3.5.11.</p>
<p>IE9 includes a fix for the vulnerability. Microsoft plans to ship a public beta of IE9 on Sept. 15.</p>
<p>On Friday, Evans explained why he was adding to the patch pressure by crafting a proof-of-concept. &#8220;I have been unsuccessful in persuading the vendor to issue a fix,&#8221; he said of Microsoft.</p>
<p>Microsoft issued a statement Friday saying it was investigating Evans&#8217; reports, but declined to answer questions on Monday, including whether earlier versions of IE were vulnerable or why it has not yet addressed the bug.</p>
<p>&#8220;We&#8217;re currently unaware of any attacks trying to use the claimed vulnerability or of customer impact,&#8221; said Jerry Bryant, a group manager with the Microsoft Security Response Center, in the e-mailed statement. </p></blockquote>
<p>In the case of Tavis Ormandy it was the <a href="http://www.darknet.org.uk/2010/06/windows-help-vulnerability-exploited-in-the-wild/">Windows Help Vulnerability Exploited In The Wild</a>, I expect with this vulnerability going public and with an accompanying proof of concept we may well see this CSS attack in the wild too.</p>
<p>IF you are interested you can see the PoC for the bug here:</p>
<p><a href="http://scary.beasts.org/misc/twitter.html">http://scary.beasts.org/misc/twitter.html</a></p>
<p>Source: <a href="http://www.networkworld.com/news/2010/090710-microsoft-investigates-two-year-old-ie.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+Investigates+IE+CSS+Cross-Origin+Theft+Vulnerability+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2946+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/09/microsoft-investigate-ie-css-cross-origin-theft-vulnerability/&amp;t=Microsoft+Investigates+IE+CSS+Cross-Origin+Theft+Vulnerability" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/09/microsoft-investigate-ie-css-cross-origin-theft-vulnerability/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/09/microsoft-investigate-ie-css-cross-origin-theft-vulnerability/&amp;title=Microsoft+Investigates+IE+CSS+Cross-Origin+Theft+Vulnerability" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/09/microsoft-investigate-ie-css-cross-origin-theft-vulnerability/&amp;title=Microsoft+Investigates+IE+CSS+Cross-Origin+Theft+Vulnerability" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/09/microsoft-investigate-ie-css-cross-origin-theft-vulnerability/&amp;title=Microsoft+Investigates+IE+CSS+Cross-Origin+Theft+Vulnerability" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/09/microsoft-investigate-ie-css-cross-origin-theft-vulnerability/&amp;title=Microsoft+Investigates+IE+CSS+Cross-Origin+Theft+Vulnerability" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F09%2Fmicrosoft-investigate-ie-css-cross-origin-theft-vulnerability%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/09/microsoft-investigate-ie-css-cross-origin-theft-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Releases Out-Of-Band Patch For IE 0-Day Vulnerability</title>
		<link>http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/</link>
		<comments>http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 08:01:14 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[crc-16]]></category>
		<category><![CDATA[data execution prevention]]></category>
		<category><![CDATA[dep]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hacking-IE]]></category>
		<category><![CDATA[ie 0day]]></category>
		<category><![CDATA[IE-exploit]]></category>
		<category><![CDATA[IE-security]]></category>
		<category><![CDATA[IE-vulnerability]]></category>
		<category><![CDATA[internet explorer security]]></category>
		<category><![CDATA[internet explorer vulnerability]]></category>
		<category><![CDATA[internet explorere 0day]]></category>
		<category><![CDATA[internet-explorer-exploit]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft patch tuesday]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[oob patch]]></category>
		<category><![CDATA[out of band patch]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2457</guid>
		<description><![CDATA[Ah Microsoft is treating this one seriously after France and Germany advised users to avoid IE. The current strain being exploited only targets IE6 users, but one security company has developed an exploit for IE8 which also bypasses DEP (Data Execution Prevention). It was rumoured this was the exploit used last week to compromise Google [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Ah <a href="http://www.darknet.org.uk/tag/microsoft/">Microsoft</a> is treating this one seriously after <a href="http://www.eweek.com/c/a/Security/France-Germany-Say-Avoid-IE-Until-Security-Vulnerability-Patched-321481/">France and Germany advised users to avoid IE</a>.</p>
<p>The current strain being exploited only targets IE6 users, but one security company has developed an exploit for IE8 which also bypasses DEP (Data Execution Prevention).</p>
<p>It was rumoured this was the exploit used last week to compromise Google and various other high profile networks. Although I am skeptical as to why anyone was using IE inside Google? Perhaps doing cross browser testing for development, who knows.</p>
<blockquote><p>Microsoft will release an out-of-band patch Jan. 21 to fix the Internet Explorer vulnerability at the center of recent attacks on Google and other enterprises.</p>
<p>According to Microsoft, the patch is slated to be ready around 1 p.m. EST. If all goes according to plan, the patch will close a hole that has prompted France and Germany to advise users to avoid IE and the U.S. State Department to demand answers from China. Attackers have used the vulnerability to hit IE 6. Microsoft so far has said it has only seen limited, targeted attacks using the vulnerability.</p>
<p>Meanwhile, security researchers have continued to uncover information about the origin of the attack. Joe Stewart, director of malware research for SecureWorks&#8217; Counter Threat Unit, said his analysis of the code for the main Trojan involved in the attacks shows a more direct link to China. </p></blockquote>
<p>It&#8217;s very rare for them to push an <a href="http://www.darknet.org.uk/tag/out-of-band-patch/">out-of-band patch</a> for anything but I guess there are still a LOT of IE users out there and this is a serious flaw.</p>
<p>It does seem to originate from China with the only discussions about the technical parts of the flaw and implementation being discussed on Chinese language sites.</p>
<p>As can be seen by a Google search here (<a href="http://www.google.com/search?q="crc_ta[16]"&#038;ie=utf-8&#038;oe=utf-8&#038;aq=t&#038;rls=org.mozilla:en-US:official&#038;client=firefox-a">&#8220;crc_ta[16]&#8220;</a>), after the first few English news sites reporting the flaw the rest of the results are in Chinese.</p>
<blockquote><p>According to Stewart, the code includes a CRC (cyclic redundancy check) algorithm implementation released as part of a Chinese-language paper on optimizing CRC algorithms for use in microcontrollers.</p>
<p>&#8220;This CRC -16 implementation seems to be virtually unknown outside of China, as shown by a Google search for one of the key variables, &#8216;crc_ta[16],&#8217;&#8221; Stewart noted in a SecureWorks blog post Jan. 20. &#8220;At the time of this writing, almost every page with meaningful content concerning the algorithm is Chinese.&#8221;</p>
<p>Up until this finding, Stewart told eWEEK, the factors leading people to point to China were patterns similar to previous Chinese malware.</p>
<p>&#8220;Unfortunately, when investigating malware, nothing is conclusive because digital evidence can be forged,&#8221; he said. &#8220;However, I believe the use of the Chinese algorithm certainly gives more credence to the attack code being Chinese in origin.&#8221;</p></blockquote>
<p>They really have no choice but to release this patch when faced with government pressure, you should see it hitting your Windows Update sometime today (Jan 21st).</p>
<p>Let&#8217;s hope this patch has been tested properly and doesn&#8217;t subject users to another <a href="http://www.darknet.org.uk/2009/12/microsoft-leaves-users-waiting-for-black-screen-of-death-fix/">black screen of death</a>.</p>
<p>It&#8217;s good to see some proactive initiatives by Microsoft, I hope they continue through 2010.</p>
<p></p>
<p>Source: <a href="http://www.eweek.com/c/a/Security/Microsoft-IE-Patch-for-ZeroDay-Vulnerability-Coming-Tomorrow-804909/">eWeek</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+Releases+Out-Of-Band+Patch+For+IE+0-Day+Vulnerability+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2457+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/&amp;t=Microsoft+Releases+Out-Of-Band+Patch+For+IE+0-Day+Vulnerability" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/&amp;title=Microsoft+Releases+Out-Of-Band+Patch+For+IE+0-Day+Vulnerability" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/&amp;title=Microsoft+Releases+Out-Of-Band+Patch+For+IE+0-Day+Vulnerability" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/&amp;title=Microsoft+Releases+Out-Of-Band+Patch+For+IE+0-Day+Vulnerability" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/&amp;title=Microsoft+Releases+Out-Of-Band+Patch+For+IE+0-Day+Vulnerability" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F01%2Fmicrosoft-releases-out-of-band-patch-for-ie-0-day-vulnerability%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/01/microsoft-releases-out-of-band-patch-for-ie-0-day-vulnerability/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>IE7 Exploit Also Affects IE5, IE6 and IE8! More Users In Trouble</title>
		<link>http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/</link>
		<comments>http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/#comments</comments>
		<pubDate>Mon, 15 Dec 2008 08:41:59 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[0 day exploit]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[0day ie exploit]]></category>
		<category><![CDATA[hacking internet explorer]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[IE-exploit]]></category>
		<category><![CDATA[ie5 exploit]]></category>
		<category><![CDATA[ie6 exploit]]></category>
		<category><![CDATA[ie7]]></category>
		<category><![CDATA[ie7 exploit]]></category>
		<category><![CDATA[ie8 exploit]]></category>
		<category><![CDATA[internet explorer security]]></category>
		<category><![CDATA[internet explorer vulnerability]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[internet-explorer-7]]></category>
		<category><![CDATA[internet-explorer-exploit]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[windows vulnerability]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1313</guid>
		<description><![CDATA[I&#8217;m sure you&#8217;ve heard about the Microsoft IE7 Exploit that allows Remote Code Execution on XP &#038; Vista, it turns out it&#8217;s actually much worse than first expected. The exploit also affects IE5.01, IE6 and IE8 on all OS versions! That&#8217;s a pretty worrying turn of events for MS especially as they are seemingly leaving [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>I&#8217;m sure you&#8217;ve heard about the <a href="http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/">Microsoft IE7 Exploit that allows Remote Code Execution on XP &#038; Vista</a>, it turns out it&#8217;s actually much worse than first expected.</p>
<p>The exploit also affects IE5.01, IE6 and IE8 on all OS versions! That&#8217;s a pretty worrying turn of events for MS especially as they are seemingly leaving it unpatched.</p>
<p>You can find a clarification of the various workarounds for the IE flaw <a href="http://blogs.technet.com/swi/archive/2008/12/12/Clarification-on-the-various-workarounds-from-the-recent-IE-advisory.aspx">on Technet here</a>.</p>
<blockquote><p>Researchers are warning that the unpatched security vulnerability in Microsoft&#8217;s Internet Explorer affects more versions of the browser than previously thought, and that steps users must take to prevent exploitation are harder than first published.</p>
<p>According to an <a href="http://www.microsoft.com/technet/security/advisory/961051.mspx">updated advisory from Redmond</a>, the bug that&#8217;s been actively exploited since Tuesday bites versions 5.01, 6, and 8 of the browser, which is by far the most widely used on the web. A previous warning from Microsoft only said that IE 7 was susceptible to the attacks. IE is susceptible when running on all supported versions of the Windows operating systems, Microsoft also says.</p>
<p>What&#8217;s more, while there is some protection from Vista&#8217;s User Account Control, the measure doesn&#8217;t altogether prevent the attack, according to <a href="http://msmvps.com/blogs/spywaresucks/archive/2008/12/12/1656545.aspx">this post</a> on the Spyware Sucks blog. Microsoft and others have suggested that those who must use IE in the next few weeks set the security level to high for the internet security zone or disable active scripting. These are sensible measures, but they don&#8217;t guarantee you won&#8217;t be pwned, according to <a href="http://secunia.com/blog/38/">this post</a> from the Secunia blog.</p></blockquote>
<p>Once again Firefox users for the win, this is a flaw in the whole family of Internet Explorer and must effect a shocking amount of users. I guess setting your Security Zone to high and disabling Active Scripting helps but then it also disables a lot of features on a lot of sites.</p>
<p>So you are losing out on the user experience of the web just to be more secure, mostly because Microsoft doesn&#8217;t want to release an ad-hoc patch.</p>
<p>Well <a href="http://www.google.com/chrome">Google Chrome</a> final version is out now too, so there&#8217;s another option for people.</p>
<blockquote><p>Secunia goes on to revise what it says is the cause of the vulnerability. Contrary to <a href="http://www.theregister.co.uk/2008/12/09/zero_day_ie_flaw_exploited/">earlier reports</a> that pinned the blame on the way IE handles certain types of data that use the extensible markup language, or XML, format, the true cause is faulty data binding, meaning exploit code need not use XML.</p>
<p>Microsoft has yet to say whether it plans to issue a fix ahead of next month&#8217;s scheduled release. For the moment, the volume of in-the-wild attacks remains relatively modest and limited mostly to sites based in China. But because attackers are injecting exploits into legitimate sites that have been compromised, we continue to recommend that users steer clear of IE until the hole has been closed.</p>
<p>Plenty of other researchers have weighed in with additional details about the flaw. Links from <a href="http://isc.sans.org/diary.html?storyid=5470">SANS</a>, <a href="http://www.sophos.com/security/blog/2008/12/2204.html">Sophos</a> and <a href="http://hackademix.net/2008/12/12/more-bad-news-for-ie-users/">Hackademix</a>.</p></blockquote>
<p>I think an imminent danger is if people start using iframe vulnerabilies and XSS to inject this exploit into some more prominent sites &#8211; that could cause a huge spread of infections!</p>
<p>Anyway just let people using IE know that this is another reason they shouldn&#8217;t be using it! Show them how to download and install Firefox and please teach them to use Tabs!</p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2008/12/12/ie_zero_day_misconceptions/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=IE7+Exploit+Also+Affects+IE5%2C+IE6+and+IE8%21+More+Users+In+Trouble+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1313+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/&amp;t=IE7+Exploit+Also+Affects+IE5%2C+IE6+and+IE8%21+More+Users+In+Trouble" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/&amp;title=IE7+Exploit+Also+Affects+IE5%2C+IE6+and+IE8%21+More+Users+In+Trouble" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/&amp;title=IE7+Exploit+Also+Affects+IE5%2C+IE6+and+IE8%21+More+Users+In+Trouble" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/&amp;title=IE7+Exploit+Also+Affects+IE5%2C+IE6+and+IE8%21+More+Users+In+Trouble" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/&amp;title=IE7+Exploit+Also+Affects+IE5%2C+IE6+and+IE8%21+More+Users+In+Trouble" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F12%2Fie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Microsoft IE7 Exploit Allows Remote Code Execution on XP &amp; Vista</title>
		<link>http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/</link>
		<comments>http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/#comments</comments>
		<pubDate>Thu, 11 Dec 2008 08:43:09 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[0 day exploit]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[0day ie exploit]]></category>
		<category><![CDATA[hacking internet explorer]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[IE-exploit]]></category>
		<category><![CDATA[ie7]]></category>
		<category><![CDATA[ie7 exploit]]></category>
		<category><![CDATA[internet explorer security]]></category>
		<category><![CDATA[internet explorer vulnerability]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[internet-explorer-7]]></category>
		<category><![CDATA[internet-explorer-exploit]]></category>
		<category><![CDATA[patch-tuesday]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[windows vulnerability]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1303</guid>
		<description><![CDATA[It seems a new, fairly serious flaw has been discovered in Internet Explorer 7 &#8211; and as accounts go it&#8217;s been around for a couple of months in the underground. The worrying part is, patch Tuesday was yesterday and after testing it&#8217;s been discovered that this flaw WAS NOT patched in the updates. ISC reports [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>It seems a new, fairly serious flaw has been discovered in Internet Explorer 7 &#8211; and as accounts go it&#8217;s been around for a couple of months in the underground.</p>
<p>The worrying part is, <a href="http://www.darknet.org.uk/tag/patch-tuesday/">patch Tuesday</a> was yesterday and after testing it&#8217;s been discovered that this flaw <strong>WAS NOT</strong> patched in the updates.</p>
<p><a href="http://isc.sans.org/diary.html?storyid=5458">ISC reports</a> that it&#8217;s not currently widely used, but it has been found in the wild.</p>
<blockquote><p>Microsoft said it is investigating reports that a new exploit is going around that takes advantage of an unpatched security hole in Internet Explorer 7.</p>
<p>The SANS Internet Storm Center, which tracks hacking trends, said today that while the exploit does not appear to be widely in use at the moment, that situation is likely to change soon, since instructions showing criminals how to take advantage of this flaw have been posted online.</p>
<p>SANS emphasizes that this vulnerability is not one that was fixed in the massive bundle of patches that Microsoft issued yesterday. It is not clear what steps users can take to protect themselves against this threat, other than to browse the Web with something other than IE, such as Mozilla Firefox or Opera. This appears to be the type of vulnerability that could be used to give attackers complete control over an affected system merely by convincing users to browse to a specially-crafted hacked or malicious Web site. </p></blockquote>
<p>It seems the safest thing is not to use IE, which I personally have been doing since about 1998 anyway. But still, some people claim they have problems with Java or JavaScript or AJAX enabled sites with Firefox.</p>
<p>There&#8217;s always Opera, or even the new Google Chrome.</p>
<p>This exploit is a serious one as someone only needs to visit the site and remote code can be injected into their OS and executed.</p>
<blockquote><p>According to SANS, the exploit works against fully-patched Windows XP and Windows 2003 systems with Internet Explorer 7.</p>
<p>In a statement e-mailed to Security Fix, Microsoft said once it is done with its investigation, the company &#8220;will take appropriate action to help protect customers. This may include providing a security update through the monthly release process, an out-of-cycle update or additional guidance to help customers protect themselves.&#8221; </p></blockquote>
<p>Once again it&#8217;s demonstrated how stupid &#8216;Patch Tuesday&#8217; is and how half of the people on the Internet are going to be vulnerable to this serious flaw until the first Tuesday in January.</p>
<p>I really hope Microsoft pushes out an emergency patch outside their schedule ASAP.</p>
<p>You can find a list of the sites known to be distributing the code on <a href="http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20081210">Shadowserver here</a>.</p>
<p></p>
<p>Source: <a href="http://voices.washingtonpost.com/securityfix/2008/12/exploit_for_unpatched_internet.html?nav=rss_blog">Security Fix</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+IE7+Exploit+Allows+Remote+Code+Execution+on+XP+%26+Vista+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1303+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/&amp;t=Microsoft+IE7+Exploit+Allows+Remote+Code+Execution+on+XP+%26+Vista" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/&amp;title=Microsoft+IE7+Exploit+Allows+Remote+Code+Execution+on+XP+%26+Vista" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/&amp;title=Microsoft+IE7+Exploit+Allows+Remote+Code+Execution+on+XP+%26+Vista" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/&amp;title=Microsoft+IE7+Exploit+Allows+Remote+Code+Execution+on+XP+%26+Vista" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/&amp;title=Microsoft+IE7+Exploit+Allows+Remote+Code+Execution+on+XP+%26+Vista" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F12%2Fmicrosoft-ie7-exploit-allows-remote-code-execution-on-xp-vista%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

