Register | Login
Views: 19364387
Main | Memberlist | Active users | ACS | Commons | Calendar | Online users
Ranks | FAQ | Color Chart | Photo album | IRC Chat
11-02-05 12:59 PM
2 users currently in General Chat: Ailure, Dark Vampriel | 1 guest
Acmlm's Board - I2 Archive - General Chat - Yet another vulnerability in IE | |
Pages: 1 2Add to favorites | "RSS" Feed | Next newer thread | Next older thread
User Post
Alastor the Stylish
Hey! I made a cool game! It's called "I poisoned half the food, so if you eat you might die!" Have a taco.


Level: 114

Posts: 4204/7620
EXP: 16258468
For next: 51099

Since: 03-15-04
From: Oregon, US

Since last post: 2 hours
Last activity: 2 hours
Posted on 01-02-05 05:35 AM Link | Quote
I'd like to delete IE, but the other person who uses this computer uses AOL's default browser, which I believe ceases to function if you delete IE.
HyperLamer
<||bass> and this was the soloution i thought of that was guarinteed to piss off the greatest amount of people

Sesshomaru
Tamaranian

Level: 118

Posts: 2761/8210
EXP: 18171887
For next: 211027

Since: 03-15-04
From: Canada, w00t!
LOL FAD

Since last post: 2 hours
Last activity: 2 hours
Posted on 01-02-05 05:48 AM Link | Quote
Well, teach him otherwise. The only reason I have IE installed (besides the rather stupid dependencies - nothing works without it ) is for testing page/layout designs.

Also, I agree with this being here. This is probably the most visited forum, and new exploit/virus info should be as well-spread as possible to ensure people don't get infected.

Originally posted by Tarale
There's a LoadImage API vulnerability, that affects BMP, ICO, CUR, ANI files...

Shit, could that be exploited by other programs? LoadImage is a pretty commonly-used function.

Originally posted by Dracoon
If you are just careful and only go to trusted sites, it won't happen, and then you don't have to worry about it...

Sure, until some 31337 script kiddie uploads the infection code to a trusted-but-insecure page (essentially anything that displays user input without proper filtering, such as a comments page on a blog, a message board, etc), or even a link you follow not knowing that it leads to. Or you come across a malicious site on Google. Or an ad server on a trusted site changes their policy and installs adware that changes your start page (seen it happen before). Or someone else visits a malicious page on the computer while you're not looking. Or you mis-type a URL. Etc, etc. The belief that visiting only trusted pages prevents these exploits - or even, that you will visit only trusted pages - is quite foolish.
Jesper
Busy, busy, busy.
Level: 69

Posts: 1486/2390
EXP: 2856000
For next: 13743

Since: 03-15-04
From: Sweden.

Since last post: 176 days
Last activity: 79 days
Posted on 01-02-05 05:50 AM Link | Quote
Originally posted by knuck
Originally posted by Jesper
No, he said "SWITCH AWAY FROM A BROWSER MADE BY TRAINED OTTERS TO ONE THAT HAS BEEN UPDATED IN THE PAST TWO YEARS".
aka "GET FIREFOX".
One day Zen Master Bo Wol asked Zen Master Jun Kang, "A long time ago, Zen Master Ma Jo said to the assembly,
Tarale
I'm not under the alfluence of incohol like some thinkle peop I am. It's just the drunker I sit here the longer I get.

Level: 73

Posts: 1098/2720
EXP: 3458036
For next: 27832

Since: 03-18-04
From: Adelaide, Australia

Since last post: 4 hours
Last activity: 2 hours
Posted on 01-02-05 05:54 AM Link | Quote
HyperHacker -- the LoadImage thing is exploitable, but I haven't heard of any exploits in the wild yet.

But yeah, the LoadImage thing worried me too.

As for removing IE -- you don't need to delete it (in fact, you'll break things if you do), but it's a good idea to perhaps HIDE it.
HyperLamer
<||bass> and this was the soloution i thought of that was guarinteed to piss off the greatest amount of people

Sesshomaru
Tamaranian

Level: 118

Posts: 2763/8210
EXP: 18171887
For next: 211027

Since: 03-15-04
From: Canada, w00t!
LOL FAD

Since last post: 2 hours
Last activity: 2 hours
Posted on 01-02-05 05:58 AM Link | Quote
Absolutely, the only place to find it is deep within the start menu. Not only do I not want it to show up but I also hate its icon. (Teh ugly!) But I need it to be semi-accessible for testing.
Violent J

Melon Bug
Level: 41

Posts: 89/749
EXP: 479154
For next: 991

Since: 05-05-04
From: The Lotus Pod

Since last post: 8 hours
Last activity: 8 hours
Posted on 01-02-05 10:46 AM Link | Quote
Pbh! What the hell is up with hackers trying to kill pcs! Its not funny! Would they like it if all there viruses were destroyed cuase of a virus they got!? No! So why do they do it! Sick Kicks? YES.
windwaker

Ball and Chain Trooper
WHY ALL THE MAYONNAISE HATE
Level: 61

Posts: 892/1797
EXP: 1860597
For next: 15999

Since: 03-15-04

Since last post: 4 days
Last activity: 6 days
Posted on 01-02-05 10:48 AM Link | Quote
Masfdja;sdfkajsdf

Not another IE bug >_____x. I mean, I can understand PHP exploits, but a bug accessed through HTML? Come ON.
Tarale
I'm not under the alfluence of incohol like some thinkle peop I am. It's just the drunker I sit here the longer I get.

Level: 73

Posts: 1102/2720
EXP: 3458036
For next: 27832

Since: 03-18-04
From: Adelaide, Australia

Since last post: 4 hours
Last activity: 2 hours
Posted on 01-02-05 10:50 AM Link | Quote
Originally posted by Sonicandtails
Pbh! What the hell is up with hackers trying to kill pcs! Its not funny! Would they like it if all there viruses were destroyed cuase of a virus they got!? No! So why do they do it! Sick Kicks? YES.


A lot of vulnerabilities are used now by corporations -- the most common corporate use of a vulnerability is to get spyware onto your machine so that corporations can target advertising to you.

A lot of viruses and trojans lately seem to be being developed with spammers' usage in mind -- they are frequently designed to take over your machine and turn it into a zombie that spammers can use to send their spam with. The spammers then hide behind your hacked computer... if anybody traces the spam back, they find YOU, not the spammer!

And all of this is done for -- you guessed it -- money.

They're not doing it cause it's "funny", they're doing it cause somebody's paying them to do it. And clearly, the spammers and corporations are paying well... this is becoming more widespread.

Only the script kiddies do shit like this for "sick kicks" and they're mostly harmless.


(edited by Tarale on 01-02-05 01:51 AM)
Violent J

Melon Bug
Level: 41

Posts: 93/749
EXP: 479154
For next: 991

Since: 05-05-04
From: The Lotus Pod

Since last post: 8 hours
Last activity: 8 hours
Posted on 01-02-05 10:52 AM Link | Quote
I know about Spyware and stuff but man, Ive had like 30 viruses that did bad shit to my PC and Im sick of it! I got one through a dl off Sonic-Cult once! Took out a few user Ids and shit. Thats why I just bought Norton and cracked Ad-aware.
Tarale
I'm not under the alfluence of incohol like some thinkle peop I am. It's just the drunker I sit here the longer I get.

Level: 73

Posts: 1103/2720
EXP: 3458036
For next: 27832

Since: 03-18-04
From: Adelaide, Australia

Since last post: 4 hours
Last activity: 2 hours
Posted on 01-02-05 10:59 AM Link | Quote
Originally posted by Sonicandtails
I know about Spyware and stuff but man, Ive had like 30 viruses that did bad shit to my PC and Im sick of it! I got one through a dl off Sonic-Cult once! Took out a few user Ids and shit. Thats why I just bought Norton and cracked Ad-aware.


Don't effing crack Ad-Aware. Support the companies that keep your machine clean -- either pay for the pro version, or use the free version.

As for the viruses, I have to wonder what you were doing to get 30 of them. Patch your installation of Windows.
windwaker

Ball and Chain Trooper
WHY ALL THE MAYONNAISE HATE
Level: 61

Posts: 896/1797
EXP: 1860597
For next: 15999

Since: 03-15-04

Since last post: 4 days
Last activity: 6 days
Posted on 01-02-05 11:02 AM Link | Quote
Keep in mind that the pro version isn't any better than the free one .
Violent J

Melon Bug
Level: 41

Posts: 100/749
EXP: 479154
For next: 991

Since: 05-05-04
From: The Lotus Pod

Since last post: 8 hours
Last activity: 8 hours
Posted on 01-02-05 11:05 AM Link | Quote
I noticed that after I did it. Plus I wouldent crack programs but my stepdad and mom went through bankruptcy so we cant buy much anymore. I was lucky enough to get a 20 dollar MP3 player this year for christmas. Plus my Stepdad asked me to do it cuase SpyBeGone sucked alot.
Tarale
I'm not under the alfluence of incohol like some thinkle peop I am. It's just the drunker I sit here the longer I get.

Level: 73

Posts: 1104/2720
EXP: 3458036
For next: 27832

Since: 03-18-04
From: Adelaide, Australia

Since last post: 4 hours
Last activity: 2 hours
Posted on 01-02-05 11:08 AM Link | Quote
Well the free version is fine, and there is other free stuff out there like Spybot Search and Destroy. Try it out. There's also free antivirus programs out there like AVG and stuff. If you're really broke, rather than crack software, you should look at all the free software that's out there. Believe it or not, there is a lot of good free software out there that doesn't have spyware in it....

As for the pro version of AdAware not being better than the free one -- if it was better at scanning software, there'd be a few... issues. I wouldn't trust Lavasoft anymore, that's for sure!
Violent J

Melon Bug
Level: 41

Posts: 102/749
EXP: 479154
For next: 991

Since: 05-05-04
From: The Lotus Pod

Since last post: 8 hours
Last activity: 8 hours
Posted on 01-02-05 11:10 AM Link | Quote
I had AVG untill I found some viruses i had I couldent get rid of. So my Stepdads Bday present from me was Norton. Even though we all use it he really wanted it and he plays with it everyday.
Kitten Yiffer

Purple wand
Furry moderator
Vivent l'exp����¯�¿�½������©rience de signalisation d'amusement, ou bien !
Level: 135

Posts: 7041/11162
EXP: 28824106
For next: 510899

Since: 03-15-04
From: Sweden

Since last post: 3 hours
Last activity: 4 min.
Posted on 01-02-05 04:56 PM Link | Quote
Originally posted by Sonicandtails
Pbh! What the hell is up with hackers trying to kill pcs! Its not funny! Would they like it if all there viruses were destroyed cuase of a virus they got!? No! So why do they do it! Sick Kicks? YES.
They do becuse they can, and becuse they find it fun to have control over someone else computer.

Controlling somone's else computer is fun, as long you don't destroy the data thought. And as long it's someone you know. >.>

The amount of Spyware decreased when I stopped using IE, or well. I actually think I got thoose crap thought my sisters. Which use Firefox the most now.
HyperLamer
<||bass> and this was the soloution i thought of that was guarinteed to piss off the greatest amount of people

Sesshomaru
Tamaranian

Level: 118

Posts: 2775/8210
EXP: 18171887
For next: 211027

Since: 03-15-04
From: Canada, w00t!
LOL FAD

Since last post: 2 hours
Last activity: 2 hours
Posted on 01-03-05 07:13 AM Link | Quote
It IS fun to be able to take control of someone's computer and freak them out or DoS people. But you shouldn't do it to strangers, that's mean. Do it for revenge, or pranking friends (just don't screw stuff up). Unfortunately these people usually don't have such morals, and will just try to get as many systems infected as possible. Often they're designed to do one or more of the following:
-Steal data; anything from useless stuff to source codes to credit card numbers and passwords.
-Leave a program on the machine, usually an IRC bot, that can be commanded in groups to DoS a particular site (send a whole lot of garbage data to it all at once, overwhelming their system). Personally I wouldn't mind having my system used for this, if I was able to choose whether or not to participate. Some sites just need to be shut down.
-Install a web server on the system, allowing the attacker to store their own files on it. This is usually done to a few select systems in universities or other such places with fast connections for hosting warez.
-Give the attacker total control of the system.

Getting back on topic though, another IE vulnerability was discovered. (I'd post info, but the only link I know of has the exploit code on it, which probably shouldn't be so easily-accessible to some people. ) Basically, bad CSS combined with unclosed tags can crash the browser. (And knowing IE, someone'll probably find a way to install viruses through it. The problem is pointer corruption which is a very common exploit for viruses, but I don't know if it's useable in this case, since the circumstances are rather unusual. Pretty sure it's a data pointer, so the worst it can do is cause a page fault.)
Tarale
I'm not under the alfluence of incohol like some thinkle peop I am. It's just the drunker I sit here the longer I get.

Level: 73

Posts: 1118/2720
EXP: 3458036
For next: 27832

Since: 03-18-04
From: Adelaide, Australia

Since last post: 4 hours
Last activity: 2 hours
Posted on 01-03-05 07:21 AM Link | Quote
You know what's fun? Taking over PC's that are in the same house/building as you.

I have VNC on my PC (which is the shared computer here) and I was doing Windows Updates through it (I was sitting in my room with my Mac). I saw the mouse move, which meant somebody was at the computer, and I then they closed Windows Update...... so I opened Notepad and typed "The Matrix has you, JP...."

Minutes later, my housemate knocked on my bedroom door to inform me that "Neo" or "Morpheus" is in the computer, and they're hacking it....

On the other IE vulnerability.... So now CSS doesn't just look crap in IE, it breaks it too?


(edited by Tarale on 01-02-05 10:22 PM)
Scatterheart

Panser
Level: 29

Posts: 48/342
EXP: 143409
For next: 4476

Since: 06-06-04
From: Sydney, Australia

Since last post: 17 hours
Last activity: 4 hours
Posted on 01-03-05 11:22 AM Link | Quote


"Follow the white rabbit"

My IE doesn't even work anymore!
It loads up nothing but what's in my favorites list. Everything else, is just some search place but no matter what you type in, it just returns back to there.

Even when someone send me a link in MSN Messenger, I have to copy and paste the URL in Mozilla. Can be a pain in the ass.

Recently, I installed Norton Symantec 2005. Found maybe 300 problems? Many of which were different programs infected with the one virus. My computer's a little faster now. But not at it's best.


(edited by Scatterheart on 01-03-05 02:23 AM)
Jesper
Busy, busy, busy.
Level: 69

Posts: 1507/2390
EXP: 2856000
For next: 13743

Since: 03-15-04
From: Sweden.

Since last post: 176 days
Last activity: 79 days
Posted on 01-03-05 07:50 PM Link | Quote
Originally posted by Scatterheart
My IE doesn't even work anymore!
It loads up nothing but what's in my favorites list. Everything else, is just some search place but no matter what you type in, it just returns back to there.
Run Ad-Aware.


Now.
Pages: 1 2Add to favorites | "RSS" Feed | Next newer thread | Next older thread
Acmlm's Board - I2 Archive - General Chat - Yet another vulnerability in IE | |


ABII


AcmlmBoard vl.ol (11-01-05)
© 2000-2005 Acmlm, Emuz, et al



Page rendered in 0.012 seconds.