HOME FORUMS MEMBERS RECENT POSTS LOG IN  
× Авторизация
Имя пользователя:
Пароль:
Нет аккаунта? Регистрация
Баннер 1   Баннер 2
НОВЫЕ ТОРГОВАЯ НОВОСТИ ЧАТ
loading...
Скрыть
Вернуться   ANTICHAT > ОФФТОП > Forum for discussion of ANTICHAT
   
 
 
Опции темы Поиск в этой теме Опции просмотра

zero day exploit (fully-patched) IE 7
  #1  
Старый 10.12.2008, 02:51
Fugitif
Постоянный
Регистрация: 23.09.2007
Сообщений: 416
С нами: 9806786

Репутация: 869
По умолчанию zero day exploit (fully-patched) IE 7

Цитата:
Security researchers are reporting in-the-wild attacks targeting a previously unknown vulnerability in fully patched versions of Microsoft's Internet Explorer browser.

Internet users located in China report infections that result when using IE 7 to browse booby-trapped websites. Researchers from McAfee investigated the matter and found the exploits successfully target the Microsoft browser on both Windows XP Service Pack 3 and Vista SP 1.

The exploits contain shellcode that installs the Downloader-AZN, a well-known trojan that hijacks a PC's configuration settings and downloads additional pieces of malware. Anti-virus software from McAfee, and presumably other companies, detects the trojan - though at the time of writing, it appeared they didn't yet detect the zero-day exploit itself.

The attacks target a flaw in the way IE handles certain types of data that use the extensible markup language, or XML, format. The bug references already freed memory in the mshtml.dll file. According to IDG News, exploits work about one in three times, and only after a victim has visited a website that serves a malicious piece of javascript.

Microsoft researchers are looking in to the reports, a company spokesman said.

The reports came just hours ahead of Patch Tuesday, Microsoft's monthly release of security updates. The patches include a cumulative update for IE.
Source
 
Ответить с цитированием
 





Здесь присутствуют: 1 (пользователей: 0 , гостей: 1)
 


Быстрый переход




ANTICHAT ™ © 2001- Antichat Kft.