Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 09-14-2003, 04:17 PM   #1
Lane
Will code for food...
 
Join Date: Apr 2001
Location: Buckeye, AZ
Posts: 8,496
I have found an IE6 exploit, what should I do?

It an exploit that lets the attacker execute any code on the victims computer and edit the registry too. The victim can be infected simply by visiting a webpage.

I have all windows security updates and patches installed, it still works on my browser. I asked a few people to test it, it worked for them too.

I tried to submit a form to microsoft, which said they would get back to me in 24 hours, but they havent.. and i would surprised if they even read that shit.

What do you suggest I should do about this?
__________________
Lane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 04:19 PM   #2
Lane
Will code for food...
 
Join Date: Apr 2001
Location: Buckeye, AZ
Posts: 8,496
I havent discovered it, i just found it on a webpage that tried to run ftp on my machine to download some exe files to my pc, and only zonealarm could stop it from happening...

i looked through the code to figure out how it works and demonstrated it with some other harmless code and verified that it works.
__________________
Lane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 04:21 PM   #3
Muff
Confirmed User
 
Join Date: Mar 2001
Location: Toronto
Posts: 1,782
If you want to get something done fucking going to Microsoft.

Goto the media. Goto wirednews.com cnn.com etc.. email them all and it will be patched in no time.
Muff is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 04:23 PM   #4
Lane
Will code for food...
 
Join Date: Apr 2001
Location: Buckeye, AZ
Posts: 8,496
I'm sure a lot of those proxy selling people install shit to people's computers with this method..
__________________
Lane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 04:23 PM   #5
Lonny
Confirmed User
 
Lonny's Avatar
 
Join Date: Jun 2003
Location: Riverside Ca.
Posts: 3,539
Good luck trying to send it to MSoft, The'll tell you to were aware of the problem wait for a patch to come out for the exploit...
__________________
Lonny is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 04:24 PM   #6
brand0n
been very busy
 
Join Date: Nov 2002
Location: the queen city
Posts: 26,983
set it up to run auto run a dialer and send all your traffic there

j/k yea what he said, contact the media
__________________
want to buy this spot for cheap? it is of course for sale. long term deals are always the best bet. brand0n/ at/ a o l dot commies.
brand0n is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 04:28 PM   #8
Rorschach
So Fucking Banned
 
Join Date: Aug 2002
Posts: 5,579
Switch to Linux.
Rorschach is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 04:29 PM   #9
Lane
Will code for food...
 
Join Date: Apr 2001
Location: Buckeye, AZ
Posts: 8,496
Quote:
Originally posted by EscortBiz
icq me ill give you the contact number of a top guy there
thanks
__________________
Lane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 04:29 PM   #10
Lonny
Confirmed User
 
Lonny's Avatar
 
Join Date: Jun 2003
Location: Riverside Ca.
Posts: 3,539
Quote:
Originally posted by Rorschach
Switch to Linux.
__________________
Lonny is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 04:30 PM   #11
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
Lane, not sure if it's the same exploit, but I recently had a web page create and execute an EXE file on my desktop without warning. I'm up to date with patches and I have active-x on prompt.

I copied the vbscript and changed the name of the file it executes to something harmless like notepad.exe - but I couldn't reproduce it, I kept getting warnings that the script wasn't permitted to execute the file. I'm still scratching my head.
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 04:32 PM   #12
Naughty
Confirmed User
 
Industry Role:
Join Date: Jul 2001
Location: Utopia
Posts: 6,482
Quote:
Originally posted by EscortBiz
icq me ill give you the contact number of a top guy there
Gotta love Escort P.I.
__________________
seks.ai for sale - ping me
Naughty is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 04:32 PM   #13
Lane
Will code for food...
 
Join Date: Apr 2001
Location: Buckeye, AZ
Posts: 8,496
Quote:
Originally posted by rowan
Lane, not sure if it's the same exploit, but I recently had a web page create and execute an EXE file on my desktop without warning. I'm up to date with patches and I have active-x on prompt.

I copied the vbscript and changed the name of the file it executes to something harmless like notepad.exe - but I couldn't reproduce it, I kept getting warnings that the script wasn't permitted to execute the file. I'm still scratching my head.

lol, i did almost the same thing, i had it run wordpad and change my homepage, but mine worked
__________________
Lane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 04:39 PM   #14
Lane
Will code for food...
 
Join Date: Apr 2001
Location: Buckeye, AZ
Posts: 8,496
Quote:
Originally posted by Rorschach
Switch to Linux.
Uhm, lemme put it this way.. i wanna do something about it, i dont wanna just protect myself
__________________
Lane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 04:41 PM   #15
Lane
Will code for food...
 
Join Date: Apr 2001
Location: Buckeye, AZ
Posts: 8,496
another note: anti-virus software doesnt pick up this shit either.. i am running norton 2003 pro
__________________
Lane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 04:44 PM   #16
Forest
Confirmed User
 
Industry Role:
Join Date: Aug 2001
Location: Hollywood Fl.
Posts: 8,988
I agree with mutt

the media

wirednews

cnbc

msnbc

they have the platform to get microsofts attn
Forest is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 04:47 PM   #17
Lane
Will code for food...
 
Join Date: Apr 2001
Location: Buckeye, AZ
Posts: 8,496
Quote:
Originally posted by Forest
I agree with mutt

the media

wirednews

cnbc

msnbc

they have the platform to get microsofts attn
and how do i get the media's attention?
__________________
Lane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 04:53 PM   #18
Freestyleman
Confirmed User
 
Join Date: Sep 2002
Posts: 283
i guess you mean the vulnerable object code thing?
Freestyleman is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 05:03 PM   #19
Lane
Will code for food...
 
Join Date: Apr 2001
Location: Buckeye, AZ
Posts: 8,496
Quote:
Originally posted by Freestyleman
i guess you mean the vulnerable object code thing?
something like that
pretty much the same exploit that used to be on IE5 that was patched long ago, but there is way to do it on IE6
__________________
Lane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 05:03 PM   #20
SomeCreep
:glugglug
 
SomeCreep's Avatar
 
Join Date: Mar 2003
Location: Where the Wild Things Are
Posts: 26,118
tell securityfocus.com
__________________

Webair Hosting

I use and recommend Webair for hosting.
SomeCreep is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 05:51 PM   #21
Preacher
Confirmed User
 
Join Date: Feb 2003
Posts: 2,970
Preacher is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 06:13 PM   #22
RainMailer
Confirmed User
 
Join Date: Feb 2003
Location: Portland
Posts: 826
Where did you find this exploit? I want to see if my machines are vulnerable. Oh yeah Phoenix rocks I worked there for like 3 months. Had fun even tho I found myself lost in the desert a few times and enjoyed driving like a madman with the rest of the people in phoenix.
__________________
harbinc at gmail dot com
RainMailer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 06:33 PM   #23
extreme
Confirmed User
 
Industry Role:
Join Date: Oct 2002
Location: lalaland
Posts: 2,120
Its a well known vuln ... a variant of the latest IE vuln. Norton catched one variant of it but I guess it can be bypassed pretty easily with some mods. I think switching off DirectX makes you resistant to it. Microsoft will prob. come out with a patch in a few days.

Last edited by extreme; 09-14-2003 at 06:42 PM..
extreme is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 06:38 PM   #24
goBigtime
Confirmed User
 
Join Date: Nov 2002
Posts: 7,761
Quote:
Originally posted by Lane
It an exploit that lets the attacker execute any code on the victims computer and edit the registry too. The victim can be infected simply by visiting a webpage.

I have all windows security updates and patches installed, it still works on my browser. I asked a few people to test it, it worked for them too.

I tried to submit a form to microsoft, which said they would get back to me in 24 hours, but they havent.. and i would surprised if they even read that shit.

What do you suggest I should do about this?

I always thought you worked for Jupiter?
goBigtime is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 06:41 PM   #25
goBigtime
Confirmed User
 
Join Date: Nov 2002
Posts: 7,761
There are a couple exploits that were "patched" but not fixed.

They know about it, they just haven't fixed it yet.

http://www.microsoft.com/technet/tre...n/MS03-026.asp

http://www.microsoft.com/technet/tre...n/MS03-039.asp

http://www.microsoft.com/technet/tre...n/MS03-032.asp


There was a email on Bugtraq a few days ago giving an example how scripting doesn't even need to be enabled for it to work.


I posted it here a few days ago as well.


The best thing to do is to change your IE security level to HIGHEST (to turn off scripting, cookies, activeX etc) until it's properly patched.


I'm not sure if Mozilla or Opera is vulnerable on this one... someone said it was. I haven't had a chance to check yet.... but I've been thinking about switching to Mozilla for awhile now.


Btw, this exploit also works in Outlook. Meaning, you can just get emailed the exploit & a trojan and you're infected.

One of the drawbacks of using the most popular applications I guess

Last edited by goBigtime; 09-14-2003 at 06:44 PM..
goBigtime is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 06:46 PM   #26
Snowone
Confirmed User
 
Join Date: Jul 2002
Location: Around the Bend
Posts: 183
Quote:
Originally posted by SomeCreep
tell securityfocus.com
Yep. These guys will get miscrsoft's attention. And will get the media attention.
Snowone is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 06:48 PM   #27
goBigtime
Confirmed User
 
Join Date: Nov 2002
Posts: 7,761
Quote:
Originally posted by Snowone


Yep. These guys will get miscrsoft's attention. And will get the media attention.

Securityfocus knows about them, MicroSoft knows about them.

One of these exploits has been talked about on there (BugTraq) for almost a year.
goBigtime is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 06:53 PM   #28
goBigtime
Confirmed User
 
Join Date: Nov 2002
Posts: 7,761
Lane,

You can rename mshta.exe or block it with your (software) firewall... try that & see if the exploit you found still works.

If you need a good software firewall, search for pf2.exe on google and get version 2.0.15... the last freeware version.
goBigtime is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 06:55 PM   #29
foe
Confirmed User
 
Join Date: May 2002
Location: CT
Posts: 5,246
post a link to it here, I would like to see what it does
foe is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 06:56 PM   #30
Lane
Will code for food...
 
Join Date: Apr 2001
Location: Buckeye, AZ
Posts: 8,496
Ok, i just found out that this has been submitted to securityfocus.. they also confirm that it allows execution of arbitrary code.. they also say, "Currently we are not aware of any vendor-supplied patches for this issue."
__________________
Lane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 06:59 PM   #31
goBigtime
Confirmed User
 
Join Date: Nov 2002
Posts: 7,761
a temporary fix is here..

http://www.securityfocus.com/archive/1/336625


You basically change the registry key that identifies the evil content type...

Content Type application/hta

And change it to something that someone wouldnt guess.. like


HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\ Content Type\application/htaHqlkriyuYUW4234HDSehn

instead of

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\ Content Type\application/hta
goBigtime is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 07:00 PM   #32
Lane
Will code for food...
 
Join Date: Apr 2001
Location: Buckeye, AZ
Posts: 8,496
Quote:
Originally posted by goBigtime
Lane,

You can rename mshta.exe or block it with your (software) firewall... try that & see if the exploit you found still works.

If you need a good software firewall, search for pf2.exe on google and get version 2.0.15... the last freeware version.
I think that would solve the problem.. But i didnt really post this to figure out how to protect myself.. There are scammers out there installing dialers and proxies to people's computers. I'm just surprised that an exploit that works since IE5 still isn't fixed.

First I was searching google for the pieces of code, but only getting info about the IE5 exploit, and it would say the windowsupdate patches would fix it, blah blah... Now on securityfocus i found the same exploit and they also say that there is no patch for this.. I'm just pissed that its so easy to hack someones pc and do whatever you want with it..
__________________
Lane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 07:02 PM   #33
goBigtime
Confirmed User
 
Join Date: Nov 2002
Posts: 7,761
I think the other one might be good too/better... since they wont be able to execute .hta files....

But this is all just for MS03-032 there were two other bad ones recently.
goBigtime is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 07:03 PM   #34
goBigtime
Confirmed User
 
Join Date: Nov 2002
Posts: 7,761
Quote:
Originally posted by Lane

I'm just pissed that its so easy to hack someones pc and do whatever you want with it..

Welcome to Windows
goBigtime is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 09:59 PM   #35
hyper
Confirmed User
 
Join Date: Mar 2002
Location: Mass Ass
Posts: 5,294
[email protected]
__________________
hyper is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 10:02 PM   #36
cluck
Confirmed User
 
Join Date: Dec 2002
Location: New Jersey
Posts: 5,248
Just use a run of the mill browser hijack registry changing script and make it edit the IE security settings. Then use an activex dialer type script and point it to the exe of your choice. I've been able to do this for at least 2 years.
__________________
icq 279990726
www.mcdonalds.com <- great money making opportunity
cluck is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-14-2003, 10:04 PM   #37
Jimbo
Confirmed User
 
Industry Role:
Join Date: Oct 2001
Location: Montreal
Posts: 3,989
use the exploit on your traffic to auto download/exec a patch of this exploit.
__________________
free sex videos
Jimbo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2003, 01:15 AM   #38
butcherboy
Confirmed User
 
Join Date: Feb 2003
Location: Planet E.
Posts: 183
Hi man!

Sending bugs to M$soft is useless! Taking media attention...hum and so what will happen? It's better to send this stuff to Anti-virus software companies...

And this any many more exploits you can find here:
http://www.guninski.com

This guy discovered them since few years! Send them to M$soft and ... nothing happens from them...
__________________
---some wise words goes here--
butcherboy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2003, 01:43 AM   #39
blazin
Confirmed User
 
Join Date: Aug 2002
Posts: 2,781
Quote:
Originally posted by butcherboy
It's better to send this stuff to Anti-virus software companies...
them...
Good idea, Ask for some loot too!
blazin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2003, 01:47 AM   #40
com
Confirmed User
 
Join Date: Aug 2003
Location: Portland, Oregon
Posts: 4,541
From experience if you submit proof of concept code to MS or even a warning they'll tell you to shut up and come out with a patch a month later.
__________________

Real. Professional. Hosting.
.:Expect Nothing Less:.
320-078-843 :: www.realprohosting.com :: [email protected]
com is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2003, 03:52 AM   #41
wsjb78
Confirmed User
 
Join Date: Jun 2002
Location: Cyberspace
Posts: 594
I rather tend to think if MS fixes that exploit they will create at least two new exploits by doing so...

wsjb78

__________________
<br>Check backlinks of your sites
Get your Daily Google PR list here
ICQ: 171751720 <--> Always looking for new Sponsors

wsjb78 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2003, 04:03 AM   #42
joseph4829
Confirmed User
 
Join Date: Jul 2003
Location: Dallas, TX
Posts: 1,706
Quote:
Originally posted by Muff
If you want to get something done fucking going to Microsoft.

Goto the media. Goto wirednews.com cnn.com etc.. email them all and it will be patched in no time.
I agree.
__________________
Joe, Master Web Developer, ICQ: 280 889 133
CollegeSucks.com: Trade Links (PR 6) / $2 Advertising

On average, my site sends back 3 times as much traffic. Trade links?
joseph4829 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2003, 04:06 AM   #43
bigdog
Confirmed User
 
Join Date: Jul 2001
Posts: 6,964
thats why it very import to run a software firewall to see what applications are try trying to acccess the internet and your computer
bigdog is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-15-2003, 07:05 AM   #44
TheFLY
So Fucking Banned
 
Join Date: Jan 2001
Location: http://www.thefly.net/ --- Quit your job and live off steady traffic.
Posts: 11,856
Yeah Lane sent me the code -- it's amazingly simple... It would be cool Lane if Wired magazine or something gave our industry some credit for being honest about this crap... That would be refreshing...
TheFLY is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2003, 10:24 PM   #45
Lane
Will code for food...
 
Join Date: Apr 2001
Location: Buckeye, AZ
Posts: 8,496
**BUMP**

its about fucking time Microsoft patched this shit. my pc just autodownloaded the IE patch. if you still havent, just go to windowsupdate and get your shit fixed.

i wonder how many fresh proxy suppliers will go out of biz now! haha
__________________
Lane is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2003, 10:27 PM   #46
makefuckingmoney
Confirmed User
 
Join Date: Oct 2003
Posts: 3,277
haha
microsoft
eeks
makefuckingmoney is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2003, 10:36 PM   #47
JDog
Confirmed User
 
Join Date: Feb 2003
Location: Canby, OR
Posts: 7,453
Quote:
Originally posted by ikonworx
Good luck trying to send it to MSoft, The'll tell you to were aware of the problem wait for a patch to come out for the exploit...
Yep, exactly what will happen! Kill Bill Gates Sounds good"

jDoG
__________________
NSCash now powering ReelProfits.com
ALSO FEATURING: NSCash.com :: SoloDollars.com :: ReelProfits.com :: BiminiBucks.com :: VOD
PROGRAMS COMING SOON: Greedy Bucks :: Vengeance Cash
NOW OFFERING OVER 60 SITES
CONTACT :: JAMES SMITH :: CHIEF TECHNOLOGY OFFICER :: ICQ (711385133)
JDog is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.