PDA

View Full Version : New Ie Vulnerability



sharedholder
04-09-2004, 12:32 PM
:helpsmile: :lol: :lol:

Vulnerability in Internet Explorer ITS Protocol Handler


There is a cross-domain scripting vulnerability in the way ITS protocol handlers determine the security domain of an HTML component stored in a Compiled HTML Help (CHM) file. The HTML Help system "...uses the underlying components of Microsoft Internet Explorer to display help content. It supports HTML, ActiveX, Java, [and] scripting languages (JScript, and Microsoft Visual Basic Scripting Edition)." CHM files use the InfoTech Storage (ITS) format to store components such as HTML files, graphic files, and ActiveX objects. IE provides several protocol handlers that can access ITS files and individual CHM components: its:, ms-its:, ms-itss:, and mk:@MSITStore:. IE also has the ability to access parts of MIME Encapsulation of Aggregate HTML Documents (MHTML) using the mhtml: protocol handler.

When IE references an inaccessible or non-existent MHTML file using the ITS and mhtml: protocols, the ITS protocol handlers can access a CHM file from an alternate source. IE incorrectly treats the CHM file as if it were in the same domain as the unavailable MHTML file. Using a specially crafted URL, an attacker can cause arbitrary script in a CHM file to be executed in a different domain, violating the cross-domain security model.


News source (http://www.us-cert.gov/cas/techalerts/TA04-099A.html)

muchspl2
04-09-2004, 01:24 PM
:lol: no patch yet and it doesn't matter if you use modzilla or firefox
doesn't matter what browser you use

LSA
04-09-2004, 01:47 PM
That's cute.

shn
04-09-2004, 01:54 PM
I knew there was a reason why my *nix box would'nt open the KL FAQ.

I'm such a n00b. :)

LSA
04-09-2004, 02:10 PM
Originally posted by shn@9 April 2004 - 07:54
I knew there was a reason why my *nix box would'nt open the KL FAQ.

I'm such a n00b. :)
:rolleyes: What a n00b!

j/k!

fred devliegher
04-09-2004, 03:38 PM
no patch yet and it doesn't matter if you use modzilla or firefox

:huh:

Wait - I can ignore it when I use Firefox, or I'm skewered whatever I use ?

shn
04-09-2004, 03:51 PM
Originally posted by fred devliegher@9 April 2004 - 09:38

no patch yet and it doesn't matter if you use modzilla or firefox

:huh:

Wait - I can ignore it when I use Firefox, or I'm skewered whatever I use ?
Your Screwed!

http://psy.ed.asu.edu/~sean/gallery/sean-screwed.jpg

supersonic
04-09-2004, 04:26 PM
I heard about this one some time ago in the lounge( or talk clube or whatever).
All firewalls, security softwre, and antiviruses can't help ya now, so it all depends ont he dumb ass sitting on the computer :lol:

shn
04-11-2004, 07:29 PM
Your google toolbars have been owned too. Not too many people think about updating it.......especially when they use ie.

copy and paste this in google.

CAN-2002-1442

check your version. :)

Xero Grid
04-12-2004, 01:27 AM
:lol: It's a neverending battle. :lol:
What does the google toolbar do again? :rolleyes:

-- Xero Grid --

ninjamonkey
04-12-2004, 03:29 AM
can someone explain this to someone who has no idea what any of that means?

how was google toolbar owned?

when i installed it, it said it updated itself. thats why i dont update it. I didnt htink you even could. it said it does it automatically

shn
04-12-2004, 03:39 AM
Originally posted by ninjamonkey@11 April 2004 - 21:29
can someone explain this to someone who has no idea what any of that means?

how was google toolbar owned?

when i installed it, it said it updated itself. thats why i dont update it. I didnt htink you even could. it said it does it automatically
You are wrong. It does not update itself probably unless you specifically tell it to. I don't even use it in ie but the last time I checked my version it was 0.7.x.x.x and the newest version is at 2.0.

Read the advisory and you will see "How it is owned"

ninjamonkey
04-12-2004, 03:42 AM
from the google toolbar faq:

"How can I learn when a new version is available?

The Google Toolbar automatically updates itself when a new version is available. This may not happen immediately, but it will eventually. If you learn that there's a new version out and you've just got to have it, you can reinstall the toolbar to make sure you're driving the latest model. (You may need to uninstall first, though this shouldn't normally be necessary.) "


again, i read that advisory, but i dont understand it at all.

shn
04-12-2004, 03:48 AM
Originally posted by ninjamonkey@11 April 2004 - 21:42
from the google toolbar faq:

"How can I learn when a new version is available?

The Google Toolbar automatically updates itself when a new version is available. This may not happen immediately, but it will eventually. If you learn that there's a new version out and you've just got to have it, you can reinstall the toolbar to make sure you're driving the latest model. (You may need to uninstall first, though this shouldn't normally be necessary.) "


again, i read that advisory, but i dont understand it at all.
There are many things that can prevent a program from auto updating on any pc. Group policy and security settings is one. My toolbar never updated like I said, and the truth of the matter is there are people still running old versions.

But it's Windows so what else is new? I really could care less.

h1
04-12-2004, 06:17 AM
:lol: Last week it was stack-smashing, this week it's XSS, next week it'll be gangbanging midgets. :P