Digital Kaos

internet explorer-

-could turn your Windows XP machine into a web server, Microsoft warns ...

 
Home Register FAQ Calendar Search Today's Posts Mark Forums Read Links


Navigation »Digital Kaos > PC Advisor > General PC Chat » internet explorer-

Welcome Header
Reply
 
LinkBack Thread Tools Display Modes

 Old 8th February, 2010, 06:38 AM   #1
V.I.P. Member
 
gmb45's Avatar
 
Join Date: Nov 2008
Location: nottingham
Receivers: evox
Posts: 10,057
Thanks: 371
Thanked 929 Times in 750 Posts
Downloads: 28
Uploads: 15
gmb45 is on a distinguished road
Default internet explorer-


-could turn your Windows XP machine into a web server, Microsoft warns


A design feature - or possibly bug - or possibly both - means that internet Explorer can be turned into a web server which will leave your computer's files open to being read online, according to a hacker who demonstrated it at the Blackhat DC conference.
"The flaw, said to extend across all versions of Internet Explorer, is not subject to a patching fix, according to Jorge Luis Alvarez Medina, the Argentina-based security consultant with Core Security Technologies who elaborated on the attack technique during his demo. Indeed, microsoft advised anyone concerned about the potential for this type of attack to run IE in "protected mode," a workaround that Medina also advised. "
Microsoft has, not unsurprisingly, issued a security advisory about it.
It's broadly encouraging, suggesting that it's only going to be effective against IE (all versions) in XP. Versions of Windows above that seem to be OK.
"Our investigation so far has shown that if a user is using a version of Internet Explorer that is not running in Protected Mode an attacker may be able to access files with an already known filename and location. These versions include Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 Service 4; Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4; and Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8 on supported editions of Windows XP Service Pack 2, Windows XP Service Pack 3, and Windows Server 2003 Service Pack 2. Protected Mode prevents exploitation of this vulnerability and is running by default for versions of Internet Explorer on Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008."
And XP users run IE in protected mode, don't they?
"Other workarounds in IE, according to Medina, would include setting "IE Network Protocol Lockdown," adjusting the security level setting for the Internet and Intranet Zones to "high," and disabling Active Scripting for the Internet and Intranet Zones with a custom setting."
Disabling Active Scripting is otherwise known as "turning off Javascript and ActiveX". This is entirely feasible, though it then renders much of the modern web useless; for example sites like Google Maps, which rely on Ajax technology (which Microsoft invented), won't work without Javascript.
So what's to be done if we want the modern web? Over to Medina:
"But he also noted that since this attack appears to only work against IE, users might want to consider using "a different browser to navigate untrusted Web sites." Medina said it doesn't appear that the IE flaw is subject to patching because it encompasses design features related to how IE and Windows Explorer handle zone elevation, HTML code and MIME types."
Just to expand on that:
"[Medina] said the dialog with Microsoft's security team about the exploit so far has indicated that Microsoft thinks this is not something it can fix because the flaw is so much a part of the fundamental design of the browser. "
In other words, it's not a bug - it's a feature. Certainly for the writers of malware it is. And it's one more reason for people to move on from XP. Let's hope the government is listening.
__________________
top dk poster
CLICK ME TO VOTE FOR DIGITAL-KAOS
click here for helpful tips


nagravision 3 is being rolled out all over the uk, AND THERES NO FIX

If you find some 1s post useful use the thanks button bottom right of each post,or reputation button on the left,please dont post thanks etc it just clogs the forum up




gmb45 is offline   Reply With Quote
Reply
» Digital Kaos > PC Advisor > General PC Chat


Bookmarks

Tags
explorer-, internet

Thread Tools
Display Modes



All times are GMT. The time now is 03:13 PM.

This forum is best viewed with
Spreadfirefox Affiliate Button

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.1

Digital Kaos does not condone any illegal operations, including obtaining premium tv for free. Digital Kaos does not accept responsibilty for the loss of any equipment used.
Everything discussed on this forum is for experimental and educational purposes only. Use the information at your own risk.