BugTraq
POS#1 Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part III Nov 05 2003 05:51PM
http-equiv@excite.com (1 malware com) (1 replies)
Re: POS#1 Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part III Nov 06 2003 09:02AM
Kurt Seifried (kurt seifried org) (1 replies)
Re: POS#1 Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part III Nov 07 2003 05:22PM
Art Manion (amanion cert org) (1 replies)
--On Thursday, November 06, 2003 2:02 AM -0700 Kurt Seifried
<kurt (at) seifried (dot) org [email concealed]> wrote:

>> In our never-ending quest for entertainment, we commece from
>> this date forward to end-2004 our POS series of findings. That
>> is the 'perfect operating system'. Today we debut and regurgitate
>> new and not so new for fun as follows. A warm up for the New Year if
>> you will !:
>
> This is easy to avoid. Just set the kill bit for the affected Active
> component, Adodb.Stream for which the CLSID is
> 4B106874-DD36-11D0-8B44-00A024DD9EFF.

{4B106874-DD36-11D0-8B44-00A024DD9EFF} is the Local Troubleshooter control.

The ADODB.Stream control, an important part of several current IE exploits,
is {00000566-0000-0010-8000-00AA006D2EA4}.

MS KB article about the kill bit:

<http://support.microsoft.com/support/kb/articles/q240/7/97.asp>

Disable Active scripting for untrusted sites.

- Art

[ reply ]
Re: POS#1 Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part III Nov 07 2003 09:38PM
Kurt Seifried (bt seifried org) (2 replies)
Re: POS#1 Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part III Nov 08 2003 03:37PM
James C. Slora Jr. (Jim Slora phra com)
Re: POS#1 Self-Executing HTML: Internet Explorer 5.5 and 6.0 Part III Nov 07 2003 11:14PM
Mike Healan (mike spywareinfo com)


 

Privacy Statement
Copyright 2010, SecurityFocus