FYI…
-
http://securitylabs.websense.com/content/Alerts/3259.aspx
12.10.2008 - "…
No user interaction is necessary for the exploit to be successful.
A computer may become infected by simply visiting a malicious Web site. This vulnerability exists in the way XML is processed within Internet Explorer 7…"
-
http://isc.sans.org/diary.html?storyid=5458
Last Updated: 2008-12-11 09:50:54 UTC …(Version: 3) - "…Update: Microsoft published a bulletin regarding this issue*… In addition,
shadowserver.org published a list of infected sites**. Note that this list may not be complete. The best mitigating action from the bulletin is probably to enable DEP for Internet Explorer 7…
*
http://www.microsoft.com/technet/security/…ory/961051.mspx
December 10, 2008 - "…Suggested Actions… Workarounds:
Microsoft has tested the following workarounds. Although these workarounds will not correct the underlying vulnerability, they help block known attack vectors…
• Set Internet and Local intranet security zone settings to "High" to prompt before running ActiveX Controls and Active Scripting in these zones…
• Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and Local intranet security zone…
• Enable DEP for Internet 7…
IE7 0-Day Exploit Sites
**
http://www.shadowserver.org/wiki/pmwiki.ph…lendar.20081210
10 December 2008 - "…the first step you can take is to block the above domains and/or IP addresses. These sites are for the most part hosting a bunch of bad stuff and not just an IE7 exploit. However, there are certainly sites that we have missed and new ones that will pop up frequently, so this will not stop completely stop it all either. The only other real option against this exploit for now is an obvious one and that's to just not use IE7 until the issue has been resolved…"
>
http://isc.sans.org/diary.html?storyid=5458
Last Updated: 2008-12-11 09:50:54 UTC …(Version: 3) - "…UPDATE 2: …we received log files showing that attackers using SQL injection are now. The SQL Injection attacks are similar to those we've described multiple times before (see
http://isc.sans.org/diary.html?storyid=4565 , for example). The important part includes the target URL that is injected:
… rtrim(convert(varchar(4000),['+@C+']))+''''')FETCH NEXT FROM …
This domain is not listed by Shadowserver yet. The
1.js script on the domain links to multiple other HTML documents of which one is called
ie7.htm … If executed successfully, the script will download the binary from http ://www [dot] steoo [dot] com/admin/win.exe.
This is a game password stealer which has sporadic detection (
http://www.virustotal.com/analisis/244ae03…9c50b614fddde6a ) – there are some big names still missing it. In any case, the attackers are picking this quickly so make sure that you are following recommendations from Microsoft's advisory which will help reduce exposure or,
if you can, use an alternative browser until this has been fixed."
_____
-
http://securitylabs.websense.com/content/Alerts/3260.aspx
12.11.2008 - "Websense… has discovered that the Taiwanese search engine "
look.tw" has been compromised and is infecting site visitors with malicious code. The Web
site has been injected with a recently announced Internet Explorer 7 Zero Day Attack (
http://securitylabs.websense.com/content/Alerts/3259.aspx ). The exploit on the site attempts to download a malicious excutable called "
ieupdate.exe". The download location is currently down, but could come back at any moment."
