Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


August 23, 2004

New IE Flaw Also Affects Windows XP SP2

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

End of Article

   Previous  1  [2]  Next  


Reader Comments
Such crap. Who drags and drops things from their browser onto their harddrive with regularity? I wish the same people that constantly pick apart Microsoft products for these flaws would also dedicate their time to some of these "oh-so-secure" opensource projects.

md_detroit August 23, 2004 (Article Rating: )



created another proof-of-concept based on http-equiv's code that hides both
the image to drag and the local folder you drop it to. As a result using the
window scrollbar will install malware in your startup folder.

A little 5x5 pixel "drop zone" will automaticly follow your mouse. Just drag
the window scrollbar as usual (and a hidden image at the same moment) and
whereever you release the mouse button you will drop an exe file to your
shell:startup (as long as you remain inside the browser window of course).

Demo website: http://www.mikx.de/scrollbar/

Dragging the window scrollbar is a common behavior - even if i can't believe
there was a world before mouse wheels. A common user will probably don't
recognize the installation at all.
______________________

Care to reply again, md_detroit?
"
onFocus="clearText(this)"
TABINDEX="2" >Hey MD, you know..pot/kettle=black? You might do a little research...if you bothered you would find <NOTE THE BELOW SNIP WAS TAKEN FROM THE FULL DISCOSURE LIST, PROPS TO MIKX, WHO I'VE SNIPPED HERE>

_________________________
To proof it's not a "hype" created by the media or companies like secunia, "mikx" <mikx@mikx.de>
created another proof-of-concept based on http-equiv's code that hides both
the image to drag and the local folder you drop it to. As a result using the
window scrollbar will install malware in your startup folder.

A little 5x5 pixel "drop zone" will automaticly follow your mouse. Just drag
the window scrollbar as usual (and a hidden image at the same moment) and
whereever you release the mouse button you will drop an exe file to your
shell:startup (as long as you remain inside the browser window of course).

Demo website: http://www.mikx.de/scrollbar/

Dragging the window scrollbar is a common behavior - even if i can't believe
there was a world before mouse wheels. A common user will probably don't
recognize the installation at all.
______________________

Care to reply again, md_detroit?


BartLansing August 23, 2004 (Article Rating: )


Here you go, disaffected misfit high school kids, here's a loaded gun, let's show your parents how much you hate them! Over here Islamic terrorists, how would you like a simple recipe to make the equivilent of C4 out of common home products, kill the infidel, viva gihad! Evil hacker scumbags, here it is, a blueprint for your next malware attack, complete with sample source, still beats SP2, could do some real damage with this one -- enjoy!

Oh hey, don't forget these are just to prove it's not media hype, you understand, don't actually use any of these to kill people or destroy IT... oh hell, they already left, hmm...

Thing about all of the above, in the immortal words of Andrew Dice Clay, "upside down it's all the same s#!t." The inherent danger of these constructs has been well proven. Release of these "proofs of concept" makes them available to uninspired creeps who likely never would've come up with anything close on their own. The only thing it will prove is as obvious and predictable as it is tragic: that these "researchers'" work can and will be used against us, the computing public -- remember us? Yes that's right, the people you don't give a damn about... well, looking forward to the destruction your work will spawn this time, good job, keep it up, heaven knows we can always use more mayhem.

-Mark McGinty

mmcginty_SQL August 24, 2004 (Article Rating: )


"Who drags and drops things from their browser onto their harddrive with regularity?"

Mac users do. Of course, this vulnerability doesn't affect them, so it doesn't really matter. They can go on using their computers without worry.

WinThose August 25, 2004 (Article Rating: )


Dear Mr. MD_Detroit,

Just how much does MS pay you to say sweet things about them? Your denial of something occurring reminds me of riverboat personnel that deny official, written military testamonials. Just because you claim that it's not important doesn't make it so.

It's getting to the point with the MS browser that one needs to question the value of it's integration to the OS. This integration is its biggest problem. It's quite funny when you think that MS did this on purpose in order to stifle its competition. The continuing blow-back on MS from the secuity leaks--that they designed--will be their own undoing. LOL!

Thanks,
BM_MN

bm_mn August 25, 2004 (Article Rating: )


You have got to be kidding. Detroit is right, you people really are losers

elmurid August 27, 2004 (Article Rating: )


Mr Md_detroit and Mr Elmurid, it is a rather a rude gesture to dismiss emphatically the evidence put forward by Mr BartLansing. Go to <a href='http://www.mikx.de/scrollbar/' target='_blank'>http://www.mikx.de/scrollbar/</a> and see the evidence before you demonstrate you sheer ignorance.

truehighspeed August 28, 2004 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

WinInfo Short Takes: Week of November 9, 2009

An often irreverent look at some of the week's other news, including some more Windows 7 sales momentum, some Sophos stupidity, Microsoft's cloud computing self-loathing, more whining from the browser makers, Zoho's "Fake Office," and much, much more ...

Understanding File-Size Limits on NTFS and FAT

A general confusion about files sizes on FAT seems to stem from FAT32's file-size limit of 4GB and partition-size limit of 2TB. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events Introduction to Identity Lifecycle Manager "2"

SQL Server Security: How to Secure, Monitor & Audit Your Databases

Protecting Mobile Users' Data

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement