<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; remote code execution</title>
	<atom:link href="http://www.darknet.org.uk/tag/remote-code-execution/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Windows Help Vulnerability Exploited In The Wild</title>
		<link>http://www.darknet.org.uk/2010/06/windows-help-vulnerability-exploited-in-the-wild/</link>
		<comments>http://www.darknet.org.uk/2010/06/windows-help-vulnerability-exploited-in-the-wild/#comments</comments>
		<pubDate>Fri, 18 Jun 2010 10:56:04 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[full-disclosure]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hacking xp]]></category>
		<category><![CDATA[hacking-windows-XP]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft patch tuesday]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[out of bound patch]]></category>
		<category><![CDATA[patch-tuesday]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[responsible disclosure]]></category>
		<category><![CDATA[tavis ormandy]]></category>
		<category><![CDATA[vulnerability disclosure]]></category>
		<category><![CDATA[windows xp exploit]]></category>
		<category><![CDATA[windows xp security]]></category>
		<category><![CDATA[windows xp vulnerability]]></category>
		<category><![CDATA[Windows-XP]]></category>
		<category><![CDATA[xp hacking]]></category>
		<category><![CDATA[xp security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2710</guid>
		<description><![CDATA[So the other big news this week apart from the AT&#038;T iPad/iPhone 4 screw-up is that a recently announced critical vulnerability in Windows XP is being exploited in the wild. It was disclosed fairly recently and is a vulnerability in the Windows XP help system disclosed by Tavis Ormandy, a Google researcher who has appeared [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>So the other big news this week apart from the <a href="http://www.darknet.org.uk/2010/06/iphone-4-pre-order-system-exposes-customer-data/">AT&#038;T iPad/iPhone 4</a> screw-up is that a recently announced critical vulnerability in <a href="http://www.darknet.org.uk/tag/windows-xp/">Windows XP</a> is being exploited in the wild.</p>
<p>It was disclosed fairly recently and is a vulnerability in the Windows XP help system disclosed by <a href="http://www.darknet.org.uk/tag/tavis-ormandy/">Tavis Ormandy</a>, a <a href="http://www.darknet.org.uk/tag/google/">Google</a> researcher who has appeared on this site quite a number of times.</p>
<p>It&#8217;s dangerous because a victim can be compromised completely (including remote code execution) just by visiting a malicious web page.</p>
<blockquote><p>Five days after it was disclosed in a highly controversial advisory, a critical vulnerability in Microsoft&#8217;s Windows XP operating system is being exploited by criminal hackers, researchers from anti-virus provider Sophos said on Tuesday.</p>
<p>The flaw in the Windows Help and Support Center was disclosed on Thursday by researcher Tavis Ormandy. His public advisory came just five days after he privately informed Microsoft of the defect, prompting fierce criticism from some circles that he hadn&#8217;t given the software giant adequate time to fix the hole. That made it easier for attackers to target the bug, which allows attackers to take complete control of vulnerable machines when a user views a specially designed webpage, the critics howled.</p>
<p>According to Sophos, researchers have seen the first case of a website using the vulnerability to install malicious software on victim machines. “This malware downloads and executes an additional malicious component (Troj/Drop-FS) on the victim’s computer, by exploiting this vulnerability,” they warned.</p></blockquote>
<p>Well there&#8217;s some discussion on the issue going on about responsible disclosure with people saying Tavis made the advisory public too quickly after informing Microsoft. It&#8217;s a fair comment considering Microsoft and it&#8217;s <a href="http://www.darknet.org.uk/tag/patch-tuesday/">Patch Tuesday</a> policy which limits the speed in which they can push patches out.</p>
<p>We all know how often Microsoft pushes <a href="http://www.darknet.org.uk/tag/out-of-band-patch/">out-of-bound patches</a> out, very rarely if at all.</p>
<p>Add the fact that Windows XP is coming to the end of it&#8217;s life-cycle soon, it&#8217;s unlikely they are going to be scrambling to get a patch out.</p>
<blockquote><p>Microsoft soon amended its own advisory on the vulnerability to say researchers are “aware of limited, targeted active attacks that use this exploit code.” Although the vulnerability also afflicts Windows Server 2003, Microsoft&#8217;s advisory said that OS wasn&#8217;t “currently at risk from these attacks.”</p>
<p>Ormandy&#8217;s advisory has reignited the age-old debate over full disclosure, in which researchers publish complete details of a vulnerability under the belief that it is the best way to ensure a company fixes it quickly. Ormandy has defended his decision to give Microsoft just five days of advanced warning saying in a recent tweet: “I&#8217;m getting pretty tired of all the &#8217;5 days&#8217; hate mail. Those five days were spent trying to negotiate a fix within 60 days.”</p>
<p>Users of XP and Server 2003 should consider disabling features within Help Center that allow administrators to remotely log onto machines. </p></blockquote>
<p>Oh well, the debates about disclosure will rage on I guess, either way it&#8217;s out there now and it&#8217;s being exploited in the wild &#8211; so as of now it&#8217;s a real risk.</p>
<p>For individual users you can use the online application from Microsoft here:</p>
<p><a href="http://support.microsoft.com/kb/2219475">Vulnerability in Help Center could allow remote code execution</a></p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2010/06/15/windows_help_bug_exploited/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Windows+Help+Vulnerability+Exploited+In+The+Wild+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2710+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/06/windows-help-vulnerability-exploited-in-the-wild/&amp;t=Windows+Help+Vulnerability+Exploited+In+The+Wild" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/06/windows-help-vulnerability-exploited-in-the-wild/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/06/windows-help-vulnerability-exploited-in-the-wild/&amp;title=Windows+Help+Vulnerability+Exploited+In+The+Wild" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/06/windows-help-vulnerability-exploited-in-the-wild/&amp;title=Windows+Help+Vulnerability+Exploited+In+The+Wild" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/06/windows-help-vulnerability-exploited-in-the-wild/&amp;title=Windows+Help+Vulnerability+Exploited+In+The+Wild" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/06/windows-help-vulnerability-exploited-in-the-wild/&amp;title=Windows+Help+Vulnerability+Exploited+In+The+Wild" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F06%2Fwindows-help-vulnerability-exploited-in-the-wild%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/06/windows-help-vulnerability-exploited-in-the-wild/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jarlsberg &#8211; Learn Web Application Exploits and Defenses</title>
		<link>http://www.darknet.org.uk/2010/05/jarlsberg-learn-web-application-exploits-and-defenses/</link>
		<comments>http://www.darknet.org.uk/2010/05/jarlsberg-learn-web-application-exploits-and-defenses/#comments</comments>
		<pubDate>Fri, 07 May 2010 09:41:25 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[codelab]]></category>
		<category><![CDATA[cross-site-scripting]]></category>
		<category><![CDATA[csrf]]></category>
		<category><![CDATA[denial-of-service]]></category>
		<category><![CDATA[information disclosure]]></category>
		<category><![CDATA[jarlsberg]]></category>
		<category><![CDATA[learn web application security]]></category>
		<category><![CDATA[learn web hacking]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[security bugs]]></category>
		<category><![CDATA[vulnerable web app]]></category>
		<category><![CDATA[vulnerable web application]]></category>
		<category><![CDATA[web application codelab]]></category>
		<category><![CDATA[web application defense]]></category>
		<category><![CDATA[web security bugs]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2684</guid>
		<description><![CDATA[This codelab is built around Jarlsberg /yärlz&#8217;·bərg/, a small, cheesy web application that allows its users to publish snippets of text and store assorted files. &#8220;Unfortunately,&#8221; Jarlsberg has multiple security bugs ranging from cross-site scripting and cross-site request forgery, to information disclosure, denial of service, and remote code execution. The goal of this codelab is [...]]]></description>
			<content:encoded><![CDATA[<p>This codelab is built around Jarlsberg /yärlz&#8217;·bərg/,  a small, cheesy web application that allows its users to publish snippets of text and store assorted files. &#8220;Unfortunately,&#8221; Jarlsberg has multiple security bugs ranging from cross-site scripting and cross-site request forgery, to information disclosure, denial of service, and remote code execution. The goal of this codelab is to guide you through discovering some of these bugs and learning ways to fix them both in Jarlsberg and in general.</p>
<p align="center"><img src="http://farm5.static.flickr.com/4012/4586393286_56147108c3.jpg" alt="Jarlsberg Vulnerable Web Application" /></p>
<p>The codelab is organized by types of vulnerabilities. In each section, you&#8217;ll find a brief description of a vulnerability and a task to find an instance of that vulnerability in Jarlsberg. Your job is to play the role of a malicious hacker and find and exploit the security bugs. In this codelab, you&#8217;ll use both black-box hacking and white-box hacking. In black box hacking, you try to find security bugs by experimenting with the application and manipulating input fields and URL parameters, trying to cause application errors, and looking at the HTTP requests and responses to guess server behavior. You do not have access to the source code, although understanding how to view source and being able to view http headers (as you can in Chrome or LiveHTTPHeaders for Firefox) is valuable. Using a web proxy like <a href="http://www.darknet.org.uk/2010/01/burp-suite-v1-3-released-integrated-platform-for-attacking-web-applications/">Burp</a> or <a href="http://www.darknet.org.uk/2006/07/webscarab-web-application-analysis-new-version/">WebScarab</a> may be helpful in creating or modifying requests. In white-box hacking, you have access to the source code and can use automated or manual analysis to identify bugs. You can treat Jarlsberg as if it&#8217;s open source: you can read through the source code to try to find bugs. Jarlsberg is written in Python, so some familiarity with Python can be helpful.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>However, the security vulnerabilities covered are not Python-specific and you can do most of the lab without even looking at the code. You can run a local instance of Jarlsberg to assist in your hacking: for example, you can create an administrator account on your local instance to learn how administrative features work and then apply that knowledge to the instance you want to hack. Security researchers use both hacking techniques, often in combination, in real life. </p>
<p>If you wish to test the hosted version of Jarlsberg you can do so here:</p>
<p><a href="http://jarlsberg.appspot.com/start">http://jarlsberg.appspot.com/start</a></p>
<p>You can download Jarlsberg here:</p>
<p><a href="http://jarlsberg.appspot.com/jarlsberg-code.zip">jarlsberg-code.zip</a></p>
<p>Or read more <a href="http://jarlsberg.appspot.com/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Jarlsberg+%E2%80%93+Learn+Web+Application+Exploits+and+Defenses+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2684+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/05/jarlsberg-learn-web-application-exploits-and-defenses/&amp;t=Jarlsberg+%E2%80%93+Learn+Web+Application+Exploits+and+Defenses" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/05/jarlsberg-learn-web-application-exploits-and-defenses/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/05/jarlsberg-learn-web-application-exploits-and-defenses/&amp;title=Jarlsberg+%E2%80%93+Learn+Web+Application+Exploits+and+Defenses" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/05/jarlsberg-learn-web-application-exploits-and-defenses/&amp;title=Jarlsberg+%E2%80%93+Learn+Web+Application+Exploits+and+Defenses" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/05/jarlsberg-learn-web-application-exploits-and-defenses/&amp;title=Jarlsberg+%E2%80%93+Learn+Web+Application+Exploits+and+Defenses" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/05/jarlsberg-learn-web-application-exploits-and-defenses/&amp;title=Jarlsberg+%E2%80%93+Learn+Web+Application+Exploits+and+Defenses" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F05%2Fjarlsberg-learn-web-application-exploits-and-defenses%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/05/jarlsberg-learn-web-application-exploits-and-defenses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IE7 Exploit Also Affects IE5, IE6 and IE8! More Users In Trouble</title>
		<link>http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/</link>
		<comments>http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/#comments</comments>
		<pubDate>Mon, 15 Dec 2008 08:41:59 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[0 day exploit]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[0day ie exploit]]></category>
		<category><![CDATA[hacking internet explorer]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[IE-exploit]]></category>
		<category><![CDATA[ie5 exploit]]></category>
		<category><![CDATA[ie6 exploit]]></category>
		<category><![CDATA[ie7]]></category>
		<category><![CDATA[ie7 exploit]]></category>
		<category><![CDATA[ie8 exploit]]></category>
		<category><![CDATA[internet explorer security]]></category>
		<category><![CDATA[internet explorer vulnerability]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[internet-explorer-7]]></category>
		<category><![CDATA[internet-explorer-exploit]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[windows vulnerability]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1313</guid>
		<description><![CDATA[I&#8217;m sure you&#8217;ve heard about the Microsoft IE7 Exploit that allows Remote Code Execution on XP &#038; Vista, it turns out it&#8217;s actually much worse than first expected. The exploit also affects IE5.01, IE6 and IE8 on all OS versions! That&#8217;s a pretty worrying turn of events for MS especially as they are seemingly leaving [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>I&#8217;m sure you&#8217;ve heard about the <a href="http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/">Microsoft IE7 Exploit that allows Remote Code Execution on XP &#038; Vista</a>, it turns out it&#8217;s actually much worse than first expected.</p>
<p>The exploit also affects IE5.01, IE6 and IE8 on all OS versions! That&#8217;s a pretty worrying turn of events for MS especially as they are seemingly leaving it unpatched.</p>
<p>You can find a clarification of the various workarounds for the IE flaw <a href="http://blogs.technet.com/swi/archive/2008/12/12/Clarification-on-the-various-workarounds-from-the-recent-IE-advisory.aspx">on Technet here</a>.</p>
<blockquote><p>Researchers are warning that the unpatched security vulnerability in Microsoft&#8217;s Internet Explorer affects more versions of the browser than previously thought, and that steps users must take to prevent exploitation are harder than first published.</p>
<p>According to an <a href="http://www.microsoft.com/technet/security/advisory/961051.mspx">updated advisory from Redmond</a>, the bug that&#8217;s been actively exploited since Tuesday bites versions 5.01, 6, and 8 of the browser, which is by far the most widely used on the web. A previous warning from Microsoft only said that IE 7 was susceptible to the attacks. IE is susceptible when running on all supported versions of the Windows operating systems, Microsoft also says.</p>
<p>What&#8217;s more, while there is some protection from Vista&#8217;s User Account Control, the measure doesn&#8217;t altogether prevent the attack, according to <a href="http://msmvps.com/blogs/spywaresucks/archive/2008/12/12/1656545.aspx">this post</a> on the Spyware Sucks blog. Microsoft and others have suggested that those who must use IE in the next few weeks set the security level to high for the internet security zone or disable active scripting. These are sensible measures, but they don&#8217;t guarantee you won&#8217;t be pwned, according to <a href="http://secunia.com/blog/38/">this post</a> from the Secunia blog.</p></blockquote>
<p>Once again Firefox users for the win, this is a flaw in the whole family of Internet Explorer and must effect a shocking amount of users. I guess setting your Security Zone to high and disabling Active Scripting helps but then it also disables a lot of features on a lot of sites.</p>
<p>So you are losing out on the user experience of the web just to be more secure, mostly because Microsoft doesn&#8217;t want to release an ad-hoc patch.</p>
<p>Well <a href="http://www.google.com/chrome">Google Chrome</a> final version is out now too, so there&#8217;s another option for people.</p>
<blockquote><p>Secunia goes on to revise what it says is the cause of the vulnerability. Contrary to <a href="http://www.theregister.co.uk/2008/12/09/zero_day_ie_flaw_exploited/">earlier reports</a> that pinned the blame on the way IE handles certain types of data that use the extensible markup language, or XML, format, the true cause is faulty data binding, meaning exploit code need not use XML.</p>
<p>Microsoft has yet to say whether it plans to issue a fix ahead of next month&#8217;s scheduled release. For the moment, the volume of in-the-wild attacks remains relatively modest and limited mostly to sites based in China. But because attackers are injecting exploits into legitimate sites that have been compromised, we continue to recommend that users steer clear of IE until the hole has been closed.</p>
<p>Plenty of other researchers have weighed in with additional details about the flaw. Links from <a href="http://isc.sans.org/diary.html?storyid=5470">SANS</a>, <a href="http://www.sophos.com/security/blog/2008/12/2204.html">Sophos</a> and <a href="http://hackademix.net/2008/12/12/more-bad-news-for-ie-users/">Hackademix</a>.</p></blockquote>
<p>I think an imminent danger is if people start using iframe vulnerabilies and XSS to inject this exploit into some more prominent sites &#8211; that could cause a huge spread of infections!</p>
<p>Anyway just let people using IE know that this is another reason they shouldn&#8217;t be using it! Show them how to download and install Firefox and please teach them to use Tabs!</p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2008/12/12/ie_zero_day_misconceptions/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=IE7+Exploit+Also+Affects+IE5%2C+IE6+and+IE8%21+More+Users+In+Trouble+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1313+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/&amp;t=IE7+Exploit+Also+Affects+IE5%2C+IE6+and+IE8%21+More+Users+In+Trouble" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/&amp;title=IE7+Exploit+Also+Affects+IE5%2C+IE6+and+IE8%21+More+Users+In+Trouble" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/&amp;title=IE7+Exploit+Also+Affects+IE5%2C+IE6+and+IE8%21+More+Users+In+Trouble" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/&amp;title=IE7+Exploit+Also+Affects+IE5%2C+IE6+and+IE8%21+More+Users+In+Trouble" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/&amp;title=IE7+Exploit+Also+Affects+IE5%2C+IE6+and+IE8%21+More+Users+In+Trouble" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F12%2Fie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/12/ie7-exploit-also-affects-ie5-ie6-and-ie8-more-users-in-trouble/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Microsoft IE7 Exploit Allows Remote Code Execution on XP &amp; Vista</title>
		<link>http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/</link>
		<comments>http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/#comments</comments>
		<pubDate>Thu, 11 Dec 2008 08:43:09 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[0 day exploit]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[0day ie exploit]]></category>
		<category><![CDATA[hacking internet explorer]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[IE-exploit]]></category>
		<category><![CDATA[ie7]]></category>
		<category><![CDATA[ie7 exploit]]></category>
		<category><![CDATA[internet explorer security]]></category>
		<category><![CDATA[internet explorer vulnerability]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[internet-explorer-7]]></category>
		<category><![CDATA[internet-explorer-exploit]]></category>
		<category><![CDATA[patch-tuesday]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[windows vulnerability]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1303</guid>
		<description><![CDATA[It seems a new, fairly serious flaw has been discovered in Internet Explorer 7 &#8211; and as accounts go it&#8217;s been around for a couple of months in the underground. The worrying part is, patch Tuesday was yesterday and after testing it&#8217;s been discovered that this flaw WAS NOT patched in the updates. ISC reports [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>It seems a new, fairly serious flaw has been discovered in Internet Explorer 7 &#8211; and as accounts go it&#8217;s been around for a couple of months in the underground.</p>
<p>The worrying part is, <a href="http://www.darknet.org.uk/tag/patch-tuesday/">patch Tuesday</a> was yesterday and after testing it&#8217;s been discovered that this flaw <strong>WAS NOT</strong> patched in the updates.</p>
<p><a href="http://isc.sans.org/diary.html?storyid=5458">ISC reports</a> that it&#8217;s not currently widely used, but it has been found in the wild.</p>
<blockquote><p>Microsoft said it is investigating reports that a new exploit is going around that takes advantage of an unpatched security hole in Internet Explorer 7.</p>
<p>The SANS Internet Storm Center, which tracks hacking trends, said today that while the exploit does not appear to be widely in use at the moment, that situation is likely to change soon, since instructions showing criminals how to take advantage of this flaw have been posted online.</p>
<p>SANS emphasizes that this vulnerability is not one that was fixed in the massive bundle of patches that Microsoft issued yesterday. It is not clear what steps users can take to protect themselves against this threat, other than to browse the Web with something other than IE, such as Mozilla Firefox or Opera. This appears to be the type of vulnerability that could be used to give attackers complete control over an affected system merely by convincing users to browse to a specially-crafted hacked or malicious Web site. </p></blockquote>
<p>It seems the safest thing is not to use IE, which I personally have been doing since about 1998 anyway. But still, some people claim they have problems with Java or JavaScript or AJAX enabled sites with Firefox.</p>
<p>There&#8217;s always Opera, or even the new Google Chrome.</p>
<p>This exploit is a serious one as someone only needs to visit the site and remote code can be injected into their OS and executed.</p>
<blockquote><p>According to SANS, the exploit works against fully-patched Windows XP and Windows 2003 systems with Internet Explorer 7.</p>
<p>In a statement e-mailed to Security Fix, Microsoft said once it is done with its investigation, the company &#8220;will take appropriate action to help protect customers. This may include providing a security update through the monthly release process, an out-of-cycle update or additional guidance to help customers protect themselves.&#8221; </p></blockquote>
<p>Once again it&#8217;s demonstrated how stupid &#8216;Patch Tuesday&#8217; is and how half of the people on the Internet are going to be vulnerable to this serious flaw until the first Tuesday in January.</p>
<p>I really hope Microsoft pushes out an emergency patch outside their schedule ASAP.</p>
<p>You can find a list of the sites known to be distributing the code on <a href="http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20081210">Shadowserver here</a>.</p>
<p></p>
<p>Source: <a href="http://voices.washingtonpost.com/securityfix/2008/12/exploit_for_unpatched_internet.html?nav=rss_blog">Security Fix</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+IE7+Exploit+Allows+Remote+Code+Execution+on+XP+%26+Vista+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1303+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/&amp;t=Microsoft+IE7+Exploit+Allows+Remote+Code+Execution+on+XP+%26+Vista" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/&amp;title=Microsoft+IE7+Exploit+Allows+Remote+Code+Execution+on+XP+%26+Vista" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/&amp;title=Microsoft+IE7+Exploit+Allows+Remote+Code+Execution+on+XP+%26+Vista" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/&amp;title=Microsoft+IE7+Exploit+Allows+Remote+Code+Execution+on+XP+%26+Vista" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/&amp;title=Microsoft+IE7+Exploit+Allows+Remote+Code+Execution+on+XP+%26+Vista" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F12%2Fmicrosoft-ie7-exploit-allows-remote-code-execution-on-xp-vista%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/12/microsoft-ie7-exploit-allows-remote-code-execution-on-xp-vista/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

