CDROM-Guide forums  

PDA

View Full Version : ALL READ NOW - Thanks Demo


   
zack371
Mar 05, 2002, 11:19 AM
OK Guys and Gals,

This is a serious security hole in Internet Explorer. It will allow any .exe file to be run on your system with no warning. I have tested it in IE, Outlook and OE. It works. I have all the latest security patches, updates, etc.

Demo was kind enough to post the problem here. Demo M8, I have removed your original message as we have had some trouble with people sendding virii, etc to forum members in the past, and I did not want this exploit gettting sent around. I am posting below your original post that you had linked to, except I have edited out the code.

There is a severe IE, Outlook and Outlook Express security problem that has not been fixed as yet.

I was caught with this one over the weekend (I think) and My HD was formated, thankfully I had just taken a backup. BTW S the mail which caught me was intended for you but they spelt the name wrong.

This code will run even if active scripting and activex have been disabled in your internet settings, which if it isn't it should be.

If you copy and paste the following text into notepad and save it as something.htm and then run the page it will launch Calc.exe Please change the path "c:/windows/system32/calc.exe" to reflect that of your calc.exe. This example was first released by researchers on a website called Greymagic software and is now spread all over the internet, otherwise I would NOT be posting the information.

Exploit code removed. -Zack

A simple solution to this problem was found by Axel Pettinger and Garland Hopkins and requires a REG edit.

HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Internet Settings\Zones\0]
and change the value of "1004" (DWORD) from "0" to "3".

Before starting back up your registry.

I have tested this registry hack and can verify that it works, well at least in win2k. BTW this registry hack will have to be done on each user account you have on your computer.


I have tested the registry hack myself and it fixed the problem. Everyone should apply this fix ASAP, as this is a nasty little exploit. . .

Demo, Cheers for posting this info man. :tup:

-Zack

http://www.mindshatter.com/zack/smanback1.gif

hammy18_99
Mar 05, 2002, 12:26 PM
thx for the info guys

Demo
Mar 05, 2002, 04:48 PM
Hi

Zack I have no problem with you removing the original message and fully understand the reason why. The main thing is that the message is still getting across to people how serious this is.

I believe that the code is able to open any files on your computer not just EXE files. With a little ingenuity (not too much though) this code could totally destroy all the data on your HD and may even be able to destroy your BIOS.

One thing I must stress is that the email that got me was not a result of posting on this forum but take heed of what Zack said and do the registry hack. I would also disable ActiveX, Active Scripting and Java scripting first.

Don't forget even if you don't use IE but you use Outlook or Outlook express then you will need to change the settings in IE to protect yourself as both these programs use the settings from IE.

uk_trader
Mar 06, 2002, 12:08 PM
Hi I was just wondering whether norton no script would prevent the code from running. Ill be doing the registry hack but something like no script would be better for ppl uncomfortable with editing the registry.

Demo
Mar 07, 2002, 05:58 AM
Hi

I don't use Norton No Script so I can't be 100% sure of my answer but I would be very surprised if it does work in this case. I would have thought that the program was watching for activex, java etc but this vulnerability runs even if you have turned all these off.

Devil-Man
Mar 14, 2002, 10:06 AM
yep, it's just straight html exploits
Tested it myself and made calculator open on my own pc :)

zack371
Mar 14, 2002, 12:09 PM
FYI Guys,

I update my Norton AV last week, and did a scan and it picked up the .htm file that I had used to test the exploit. . . Wonder when MS will fix it???

-Zack