Author Topic: **VERY IMPORTANT** - New Exploit Spoofs Web Sites!!  (Read 1406 times)

0 Members and 1 Guest are viewing this topic.

Offline Mysterious Benefactor

  • Systems Manager /
  • Administrator
  • NEW SUPERNAL SCEPTER
  • *****
  • Posts: 16282
  • Karma: +205/-12203
  • Gender: Male
    • View Profile
**VERY IMPORTANT** - New Exploit Spoofs Web Sites!!
« on: December 18, 2004, 09:38:54 PM »
Security researchers have uncovered a spoofing flaw in Internet Explorer that could turn out to be the perfect holiday gift for scammers. Are you at risk?
(This bug HAS been confirmed on a FULLY PATCHED Windows XP system with IE 6.0 and Service Pack 2, so XP users ARE NOT EXEMPT!!)

Offline Josette

  • Full A ed Newest Fervor Post
  • NEW ASCENDANT
  • ******
  • Posts: 4601
  • Karma: +75/-3069
  • Gender: Female
    • View Profile
Re: New IE Exploit Spoofs Web Sites
« Reply #1 on: December 21, 2004, 08:23:04 AM »
I posted this at wpuniverse and someone there posted:

In fact, these browsers are affected:

    * Microsoft Internet Explorer ( 5.01, 5.5 en 6),
    * Mozilla (all versions)
    * Mozilla Firefox (all versions)
    * Safari (version 1.x, possibly other versions)
    * Opera (version 7.x, possibly other versions)
    * Konqueror (version 3.x, possibly other versions)

and then provided this link to a place where one can test one's browser:

http://secunia.com/multiple_browsers_window_injection_vulnerability_test/

and this one for more information:

http://secunia.com/secunia_research/2004-13/advisory/
Josette

Offline Mysterious Benefactor

  • Systems Manager /
  • Administrator
  • NEW SUPERNAL SCEPTER
  • *****
  • Posts: 16282
  • Karma: +205/-12203
  • Gender: Male
    • View Profile
Re: **VERY IMPORTANT** - New Exploit Spoofs Web Sites!!
« Reply #2 on: December 21, 2004, 05:28:37 PM »
Thank you for posting the additional info Josette. Updating everyone was on my list of things to do today, but you beat me to it.  ;)

This situation is one that's really quite serious and one that everyone should be following VERY closely because it's not simply a Windows vs. Mac vs. Linux thing - this vulnerabilty cuts completely across EVERY operating system because the vulnerability is within the browser software itself and not the individual systems. For instance,  once I'd had a chance to visit Secunia via the link eWEEK provided in their article, I discovered that the Windows versions of IE 6, Mozilla 1.7.3,  Firefox 1.0, Netscape 7.2 and Opera 7.54 all have it - the Linux versions of Mozilla 1.7.3, Firefox 1.0, Netscape 7.2 and Opera 7.54 and Linux Gnome's Epiphany 1.2.8 and Galeon 1.3 (which are both based on Mozilla) all have it - and I had a friend check IE 6 and Safari 1.2.4 on her Mac and they all have it! The only browser that I checked that didn't have it was the Linux KDE browser Konqueror 3.3.2. But that's only because I later discovered that last week I'd already installed  the patch to fix it as part of my regular Linux updates. And it's worth noting that as of this moment Konqueror is the ONLY browser to have addressed the problem (though that doesn't surprise me because Linux's KDE developers always seem to be on top of these things).

Netscape is honestly my favorite browser of choice (and has been since 1996) and I greatly prefer its features to those of Konqueror. But one thing's for certain - I'll be using Konqueror until the other browsers finally get their acts together and provide their own patches...

Offline jtfolden

  • Newbie
  • *
  • Posts: 8
  • Karma: +1/-60
  • Gender: Male
    • View Profile
    • Dark Shadows : Resurrected
Re: **VERY IMPORTANT** - New Exploit Spoofs Web Sites!!
« Reply #3 on: December 26, 2004, 06:07:11 AM »
7.54 and Linux Gnome's Epiphany 1.2.8 and Galeon 1.3 (which are both based on Mozilla) all have it - and I had a friend check IE 6 and Safari 1.2.4 on her Mac and they all have it! The only browser that I

Just for the record, I just tested this on my Mac OS X 10.3.7 system with Safari 1.2.4 (v125.12) and it "appears" that if you have Pop-Up Blocking enabled then the exploit does not work. Once I turned off the Pop-Up blocking then the exploit showed up so some mac users might be able to safe-guard against this.
http://www.darkshadows-resurrected.com/ - A Guide To The 1990's Revival Series
http://thebluewhale.darkshadows-resurrected.com - A brand new message board for the discussion of DS, Buffy / Angel, and more!
The Dream Is Alive

Offline Mysterious Benefactor

  • Systems Manager /
  • Administrator
  • NEW SUPERNAL SCEPTER
  • *****
  • Posts: 16282
  • Karma: +205/-12203
  • Gender: Male
    • View Profile
Re: **VERY IMPORTANT** - New Exploit Spoofs Web Sites!!
« Reply #4 on: December 27, 2004, 11:44:42 PM »
so some mac users might be able to safe-guard against this.

Hmmm...I forwarded your info to my friend with the Mac and asked her to double-check the specifics of her system and browser. She said that she's using the exact same setup as you - and she redid the tests - yet the exploit continues to show up whether she has pop-up blocking set up in Safari or not. I wonder what it is that you seem to be doing differently?  [hdscrt]


Available Patch Update:
Unless Secunia has yet to add the info for other patches to their site, it would certainly seem as if the patch for Linux's Konqueror is still the ONLY one available.  >:(

Offline jtfolden

  • Newbie
  • *
  • Posts: 8
  • Karma: +1/-60
  • Gender: Male
    • View Profile
    • Dark Shadows : Resurrected
Re: **VERY IMPORTANT** - New Exploit Spoofs Web Sites!!
« Reply #5 on: December 28, 2004, 06:16:34 AM »
Hmmm...I forwarded your info to my friend with the Mac and asked her to double-check the specifics of her system and browser. She said that she's using the exact same setup as you - and she redid the tests - yet the exploit continues to show up whether she has pop-up blocking set up in Safari or not. I wonder what it is that you seem to be doing differently? 

Hmm, that really is odd because I tested it several times, clearing caches etc..., (and just tested it again this very minute) and consistently found no exploit with pop-up blocking activated. Weird.

http://www.darkshadows-resurrected.com/ - A Guide To The 1990's Revival Series
http://thebluewhale.darkshadows-resurrected.com - A brand new message board for the discussion of DS, Buffy / Angel, and more!
The Dream Is Alive