This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

W2k/ie Vuln - "workaround" Available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.theinquirer.net/?article=22649
19 April 2005
"…An attacker may execute any command as the logged-on user simply by having the user select a file. Executing the file is not required for exploitation, all it takes is selecting an innocent-looking file - maybe to delete it. The exploit applies to certain versions of Windows 2000. Since Microsoft still hasn't patched the hole, you'll have to have a look at the GreyMagic page for a workaround…"

- http://www.greymagic.com/security/advisories/gm015-ie/
19 Apr 2005
"…Solution:
Until a patch becomes available, disable the Web View by going to: Tools -> Folder Options -> Select 'Use Windows classic folders'…"


:oops: :ph34r:
FYI…

(RE: http://www.microsoft.com/technet/security/…n/MS05-024.mspx )

- http://isc.sans.org/diary.php?date=2005-05-10
Updated May 10th 2005 18:03 UTC
"…According the advisory, there is a problem in the way Windows Explorer "handles certain HTML characters in preview fields". A typical attack scenario is on the workaround section: "In a Web-based attack scenario, an attacker would have to host a Web site that contains a Web page that is used to exploit this vulnerability." "…an attacker would have to persuade them to visit the Web site, typically by getting them to click a link that takes them to the attacker's Web site. After they click the link, they would be prompted to perform an action. An attack could only occur after they performed these actions…Our good reader Juha-Matti wrote that this Microsoft patch will fix the flaw, published only five months ago, at http://www.greymagic.com/security/advisories/gm015-ie/ , discovered by Grey Magic Software with a Bugtraq ID 13248. Good Work!"

:blink: