AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.php?date=2004-11-09
Updated November 9th 2004 18:25 UTC
"…The Storm Center has received several reports of a hostile email that contains a link (not an attachment) that points to code exploiting the recently announced Internet Explorer vulnerabilities. The email has text similar to this:
'Congratulations! PayPal has successfully charged $175
to your credit card. Your order tracking number is
A866DEC0, and your item will be shipped within three
business days.
To see details please click this 'link'
DO NOT REPLY TO THIS MESSAGE VIA EMAIL! This email is
being sent by an automated message system and the reply
will not be received.
Thank you for using PayPal.'
Clicking on the embedded link points the victim to a previously infected computer, downloads the exploit code, and infects the victim if the victim is using Internet Explorer on any Windows platform other than WinXP SP2. No patches are available (yet) from Microsoft…The best mitigation is to avoid using Internet Explorer until patches are available. Take a look at Firefox from the Mozilla project team as an optional browser. Version 1.0 was released today…" ( http://www.mozilla.org/download.html )
- http://isc.sans.org/diary.php?date=2004-11-09
Updated November 9th 2004 18:25 UTC
"…The Storm Center has received several reports of a hostile email that contains a link (not an attachment) that points to code exploiting the recently announced Internet Explorer vulnerabilities. The email has text similar to this:
'Congratulations! PayPal has successfully charged $175
to your credit card. Your order tracking number is
A866DEC0, and your item will be shipped within three
business days.
To see details please click this 'link'
DO NOT REPLY TO THIS MESSAGE VIA EMAIL! This email is
being sent by an automated message system and the reply
will not be received.
Thank you for using PayPal.'
Clicking on the embedded link points the victim to a previously infected computer, downloads the exploit code, and infects the victim if the victim is using Internet Explorer on any Windows platform other than WinXP SP2. No patches are available (yet) from Microsoft…The best mitigation is to avoid using Internet Explorer until patches are available. Take a look at Firefox from the Mozilla project team as an optional browser. Version 1.0 was released today…" ( http://www.mozilla.org/download.html )