<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>ie-exploit &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://en.wordpress.com/tag/ie-exploit/</link>
	<description>Feed of posts on WordPress.com tagged "ie-exploit"</description>
	<pubDate>Wed, 02 Dec 2009 06:33:20 +0000</pubDate>

	<generator>http://en.wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[MS Internet Explorer XML Parsing Overflow]]></title>
<link>http://y2h4ck.wordpress.com/2008/12/17/ms-internet-explorer-xml-parsing-overflow/</link>
<pubDate>Wed, 17 Dec 2008 11:10:11 +0000</pubDate>
<dc:creator>y2h4ck</dc:creator>
<guid>http://y2h4ck.wordpress.com/2008/12/17/ms-internet-explorer-xml-parsing-overflow/</guid>
<description><![CDATA[À alguns dias foram divulgados diversos exploits para o Internet Explorer. Certamente estes exploits]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>À alguns dias foram divulgados diversos exploits para o Internet Explorer. Certamente estes exploits ja estavam circulando pela internet a muito tempo porém, só agora oficialmente.  A falha é muito grave e atinge tanto Windows XP quanto Vista. A falha não foi corrigida pela Microsoft, fiz varios testes aqui em VMs com Vista e XP fully Upgraded e o exploit continuou a ter efeito.</p>
<p>A falha consiste em um Buffer Overflow no tratamento de XML pelo browser onde podemos injetar qualquer código arbitrário. O exploit lançado como PoC pelo pessoal no Milw0rm e no site do Mut&#8217;s abre o calc.exe porém o shellcode pode facilmente ser modificado utilizando a vasta linha de Payloads oferecidos pelo MetaSploit Framework.</p>
<p>O exploit pode ser baixado em <a href="http://milw0rm.com/exploits/7403">http://milw0rm.com/exploits/7403</a></p>
<p>No blog do Mut&#8217;s você pode baixar um package com o shellcode especialmente para o Vista</p>
<p><a href="http://www.offensive-security.com/0day/iesploit-vista.rar">http://www.offensive-security.com/0day/iesploit-vista.rar</a></p>
<p>Abaixo seguem imagens mostrando a exploração bem sucedida de um Internet Explorer no Windows Vista.</p>
<p><img class="alignnone" src="http://3.bp.blogspot.com/_rar6qXehJDE/SUAW4SAbdSI/AAAAAAAAAB4/iiNWeqc_w2o/s400/vista-calc.jpg" alt="" width="400" height="251" /></p>
<p>Recomendo a todos que tenham muito cuidado ao utilizar o Internet Explorer porque sites com o exploit podem ser facilmente alocados em um HTML e a execução acaba sendo transparente para o usuários pois &#8230; basicamente não necessita de nenhuma interação para que seja bem sucedida. Estão ocorrendo diversos incidentes de segurança especialmente em sites de conteúdo pornografico.</p>
<p>Então &#8230; vamos usar Firefox + Sandboxie <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Abraços a todos.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[IE, safer than ever?!]]></title>
<link>http://sys4dmin.wordpress.com/2008/12/17/ie-safer-than-ever/</link>
<pubDate>Wed, 17 Dec 2008 09:45:33 +0000</pubDate>
<dc:creator>Shad0w</dc:creator>
<guid>http://sys4dmin.wordpress.com/2008/12/17/ie-safer-than-ever/</guid>
<description><![CDATA[&nbsp; &nbsp; Asta este pretenţia lor, cel puţin. Şi se mai laudă că ar fi băieţi ascultători, deşi ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>&#160; &#160; Asta este <a href="http://www.microsoft.com/windows/internet-explorer/download-ie.aspx">pretenţia lor</a>, cel puţin. Şi se mai laudă că ar fi <a href="http://blogs.zdnet.com/microsoft/images/ie7-we-heard-you.jpg">băieţi ascultători</a>, deşi eu le-am zis de mult să ofere Firefox în serviciul de actualizări automate..<br />
&#160; &#160; Cât de bine ne-au ascultat <a href="http://news.bbc.co.uk/2/hi/technology/7784908.stm">ne spune BBC ieri</a>.<br />
&#160; &#160; Safer and more secure than ever, dar 10k de site-uri infectate.. hmm, pretty good safety, isn&#8217;t it? </p>
<p>PS: îmi place poziţia oficială:<br />
&#8220;I cannot recommend people switch due to this one flaw,&#8221; said John Curran, head of Microsoft UK&#8217;s Windows group. </p>
<p><strong> Update: </strong> Se pare că băieţii au luat-o în serios şi au dat drumul <a href="http://blogs.msdn.com/securitytipstalk/archive/2008/12/17/download-urgent-security-update-for-internet-explorer.aspx">unui update</a>. </p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Evil Adsense Publisher 3443918307802676 ]]></title>
<link>http://joeduck.com/2007/11/23/evil-adsense-publisher-3443918307802676/</link>
<pubDate>Fri, 23 Nov 2007 22:20:02 +0000</pubDate>
<dc:creator>JoeDuck</dc:creator>
<guid>http://joeduck.com/2007/11/23/evil-adsense-publisher-3443918307802676/</guid>
<description><![CDATA[Some of my old posts here at WordPress started showing ads, which was odd since I didn&#8217;t put a]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Some of my old posts here at WordPress started showing ads, which was odd since I didn&#8217;t put any ads up.    At first I thought JoeDuck.com  had been hacked, but it now appears this is a form of Internet Explorer browser malware that is injecting advertising into the code as you surf.    I prefer Firefox to Explorer but the laptop is not working well with Firefox &#8211; I think a almost-full-disk memory issue but I don&#8217;t want to mess with it now.</p>
<p><a href="http://forums.seroundtable.com/showthread.php?t=1849&#38;page=2" title="SEO Roudntable">SEO Roundtable</a> has a discussion of another WP blog with this problem and the adsense publisher code is the same as in my problem.   That&#8217;s an old discussion so this probably infects a lot of IE browsers out there by now.</p>
<p>I&#8217;m wondering if I should be annoyed with Google for not having a system in place to alert people when they are getting adsense hijacked?   Google must know about this WP exploit, and since the code would alert them why can&#8217;t they have an automated routine to warn me?    Perhaps they can&#8217;t ID my compromised machine via an email address?   They almost certainly deleted this publisher by now &#8230; right?    Better email Mr. Adsense himself, <a href="http://shumans.com" title="Shuman G">Shuman</a>.</p>
</div>]]></content:encoded>
</item>

</channel>
</rss>
