Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

New IE bug causes concern [drag-and-drop on webpage activates bug]

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Latest Breaking News Donate to DU
 
truthisfreedom Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-26-04 04:43 AM
Original message
New IE bug causes concern [drag-and-drop on webpage activates bug]
http://www.computerweekly.com/articles/article.asp?liArticleID=132902&liArticleTypeID=1&liCategoryID=1&liChannelID=13&liFlavourID=1&sSearch=&nPage=1

Thursday 26 August 2004
New IE bug causes concern


Security researchers are warning of a bug in Internet Explorer that could allow attackers to infect a PC by persuading a user to click on a web image.


The vulnerability affects even Windows XP machines patched with Microsoft's Service Pack 2 (SP2), making it the most serious hole discovered in SP2 to date.


IE versions 5.01, 5.5 and 6 are not effective enough in the way they screen drag-and-drop events, allowing attackers to potentially slip code from the "internet" zone to the local machine, according to researchers.


In a demonstration posted online by a "white-hat" hacker using the internet pseudonym http-equiv, who discovered the flaw, a user drags a graphic from one part of a web page to another, and this action implants code in the user's startup folder, to be run the next time Windows launches.

<snip>
Printer Friendly | Permalink |  | Top
Kellanved Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-26-04 04:47 AM
Response to Original message
1. way worse than that
Edited on Thu Aug-26-04 04:48 AM by Kellanved
By now it suffices to click on the scroll bar.


Example:
http://www.mikx.de/scrollbar/



Also there are first in-the-wild uses of the mistake, made worse by the bug where SP2 doesn't mark the files as "downloaded"; allowing their execution without warning.

However this is not strictly a bug in SP2 - you are just as vulnerable without SP2.
Printer Friendly | Permalink |  | Top
 
leftyandproud Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-26-04 07:26 AM
Response to Reply #1
3. good lord people
get Mozilla already!

www.mozilla.com

version 9.3 rocks
Printer Friendly | Permalink |  | Top
 
kayell Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-26-04 07:40 AM
Response to Reply #3
4. You must be using Firefox 0.9.3. How would you compare it to Mozilla?
Edited on Thu Aug-26-04 07:42 AM by kayell
I like Mozilla. With the optional scheduling module, I have finally been able to replace not only IE, but also MS Outlook.
Printer Friendly | Permalink |  | Top
 
leftyandproud Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-26-04 08:26 AM
Response to Reply #4
6. yes..
Firefox is great...I love the tabs and the integrated google bar. I have never used Outlook (I prefer Yahoo mail, etc)...so I'm not sure if FF has a comparable mail function built in. I also use a seperate freeware download accelerator product for my downloads. There are several available that can integrate with firefox without any problems. From what I can tell, the two products and almost identical...but you may want to give firefox a whirl. It is a very quick download.

http://www.download.com/Mozilla-Firefox/3000-2356-10299359.html?tag=lst-0-2
Printer Friendly | Permalink |  | Top
 
George W. Dunce Donating Member (389 posts) Send PM | Profile | Ignore Thu Aug-26-04 11:52 AM
Response to Reply #6
18. Thunder Bird
is the mail application that is used with FireFox. I am using them both and I love them. The built in Google and Tabs are great.I also love the pop up blocker and I have yet to have my homepage hijacked with FireFox.I am on a really fast network here and I will say that FireFox is a tad bit slower then IE,but who cares it's still fast.
Printer Friendly | Permalink |  | Top
 
reprobate Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-26-04 09:20 AM
Response to Reply #4
14. Firefox is the browser portion on Mozilla.

Mozilla is the complete product with email and newsreader.

One thing I like about firefox is the extensions that add to it for many different functions like a google toolbar, autofill, themes, dictionary search, etc. This is a complete browser, unlike the crippled and aging IE.

Even a built in popup blocker.

Micro$oft should be ashamed.
Printer Friendly | Permalink |  | Top
 
Turanga Leela Donating Member (57 posts) Send PM | Profile | Ignore Thu Aug-26-04 11:16 AM
Response to Reply #3
17. Firefox Rocks!
Mr. Leela is a Linux guru/zealot...all our computers run Linux except his PowerBook, which has a Slackware/OS X dual boot. No Microsoft products allowed in this house! (I admit having an in-house tech support makes it a lot easier.) My desktop manager is IceWM, which is easily learned by anyone who's familiar with Windows

It is such a freedom to not have to worry about worms,viruses,trojan horses, BSODs...plus the system requirement are much more modest, so we can still have older machines that function perfectly well.
Printer Friendly | Permalink |  | Top
 
Cronus Protagonist Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-26-04 07:40 AM
Response to Reply #1
5. I'm glad to see it doesn't work in Mozilla
Now if they would only make a new version of Mozilla that works in SSL through firewalls, I'd upgrade my ageing version.... if it's not one thing, it's another.

Swiftboat Veterans for Bush - TRUE!!!

JFK - Drop Bush Not Bombs! - FUCK BUSH
http://brainbuttons.com/home.asp?stashid=13
Printer Friendly | Permalink |  | Top
 
Cronus Protagonist Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-26-04 04:47 AM
Response to Original message
2. I'm glad I don't use IE
Another reason to use alternatives.

Swiftboat Veterans for Bush - TRUE!!!

JFK - Drop Bush Not Bombs! - FUCK BUSH
http://brainbuttons.com/home.asp?stashid=13
Printer Friendly | Permalink |  | Top
 
Blue_Roses Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-26-04 08:27 AM
Response to Original message
7. I love mozilla
I never use IE anymore
Printer Friendly | Permalink |  | Top
 
amber dog democrat Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-26-04 08:29 AM
Response to Original message
8. I am a Mac user
For reasons just like this. Not only does Microsoft make weak products but they the Windos OS is everyone's favorite target.

I use Safari. It just works.
Printer Friendly | Permalink |  | Top
 
Kellanved Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-26-04 08:34 AM
Response to Reply #8
9. Safari is a customized Konqueror
Certainly better than ie, but no reason for a sense of security.
Printer Friendly | Permalink |  | Top
 
amber dog democrat Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-26-04 08:39 AM
Response to Reply #9
10. I don't feel any safer -
but I am at a point where " friends don't let friends use IE "
As for security, what do you suggest ?
Printer Friendly | Permalink |  | Top
 
Kellanved Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-26-04 08:41 AM
Response to Reply #10
11. there is no security
Mac with Safari is about as secure as one can get. No internet connection is the only way to feel safe.
Printer Friendly | Permalink |  | Top
 
amber dog democrat Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-26-04 08:45 AM
Response to Reply #11
13. Short of putting in a router as a firewall
I suppose you are right.
Printer Friendly | Permalink |  | Top
 
reprobate Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-26-04 09:29 AM
Response to Reply #10
15. I use a router and zone alarm. Overkill? maybe.

But www.grc.com shows I'm not even on the internet. Go to the site and go to the 'shields up' section. it will test your connection and computer and show what ports if any are open to the outside world.
Printer Friendly | Permalink |  | Top
 
George W. Dunce Donating Member (389 posts) Send PM | Profile | Ignore Thu Aug-26-04 12:02 PM
Response to Reply #15
21. I don't think so...
At my house we have three PCs and one server on the network. I have a router with a built in firewall and I still use a firewall and anti-virus on all three pcs.In addition to that I run a bunch or Spy Ware apps once a week or so on all three, Spy Bot S&D, Hijack This, Add Aware6, CW Shredder, and BHO Demon. When you dealing with Micro$oft you need all the help you can get.
Printer Friendly | Permalink |  | Top
 
Invalence1 Donating Member (76 posts) Send PM | Profile | Ignore Thu Aug-26-04 08:41 AM
Response to Original message
12. Opera
I've been using Opera (currently ver. 7.51) for over a year now and love it. Recently upgraded to 7.54 but didn't like the "look/feel" so went back to ver.7.51.
Printer Friendly | Permalink |  | Top
 
loudsue Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-26-04 10:57 AM
Response to Original message
16. Some of us old farts sure wish you guys would speak English....
:hi: I truly admire people who know WTF they're doing with their computers, more than you'll ever know. I wish I was one of those people!!

However...I still can't compute my way out of a paper bag. I keep thinking (dreaming!) someday the 'good computer fairy' will send me someone to sit by my side, and 'splain all these things to me, until I "get it"! I HATE knowing that people can get into my computer, in spite of the "tools" I've been able to install.

As much as I love being on line, I still don't know how to research something, fluently (!), and I sure as hell don't understand how to make security work without getting everything so tangled up the darned computer won't even turn on.

:yourock: You guys rock. :yourock: While some of us just kinda 'roll'.... over.

:kick::kick:

Printer Friendly | Permalink |  | Top
 
Chovexani Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-26-04 11:57 AM
Response to Original message
19. Why the hell do people still use this piece of crap
Give me Firefox or give me death!
Printer Friendly | Permalink |  | Top
 
alfredo Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Aug-26-04 12:00 PM
Response to Original message
20. Read this link
Browse happy. This was featured on slashdot.org It will help you find a browser right for you.

http://browsehappy.com/

BTW, you guys who love Compose in Mozilla, there is a standalone.
http://www.nvu.com/download.html

there is an OSX version

http://www.macupdate.com/info.php/id/15699
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri May 03rd 2024, 02:53 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Latest Breaking News Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC