Jump to content

SP2 not safe


Redhat
 Share

Recommended Posts

Windows XP users Phelled by new Trojan

By Ashlee Vance in Chicago

Published Thursday 30th December 2004 19:56 GMT

A new Trojan horse - named Phel - that punishes users of Microsoft Windows XP operating system is in the wild.

Security software firm Symantec has issued a bulletin warning Windows XP users to be on the look out for the program, which is distributed as an .html file. The malicious code can attack systems running XP Service Pack 2. The vuln was first found in October, and Microsoft is busy trying to catch up to it.

Click Here

"Microsoft is taking this vulnerability very seriously, and an update to correct the vulnerability is currently in development," the company told ComputerWorld. "We will release the security update when the development and testing process is complete, and the update is found to effectively correct the vulnerability."

Symantec warns that users will see two Internet Explorer windows pop up when an .html file with Trojan.Phel.A is opened. If the code does its worst, the Trojan will automatically be executed every time a Windows user turns on his machine.

http://www.theregister.co.uk/2004/12/30/ms_phel_vuln/

Link to comment
Share on other sites

Microsoft Internet Explorer XP SP2 Fully Automated Remote Compromise

Although hundreds of millions of dollars have been spent on securing SP2, perfection is impossible. Through the joint effort of Michael Evanchik and Paul from Greyhats Security, a very critical vulnerability has been developed that can compromise a user's system without the need for user interaction besides visiting the malicious page. The vulnerability is not actually a vulnerability in itself, but rather it is uses multiple known holes in SP2 including Help ActiveX Control Related Topics Zone Security Bypass Vulnerability and Help ActiveX Control Related Topics Cross Site Scripting Vulnerability.

Vulnerable Systems:

* Microsoft Internet Explorer 6.0

* Microsoft Windows XP Pro SP2

* Microsoft Windows XP Home SP2

Proof of Concept:

See a proff of concept of the above code at: http://freehost07.websamba.com/greyhats/sp2rc.htm

* If an error is shown, press OK. This is normal.

* Notice in your startup menu a new file called Microsoft Office.hta. When run, this file will download and launch a harmless executable (which includes a pretty neat fire animation)

User Recommendations:

* Disable HTA files

* Disable Active Scripting in Internet Explorer

http://www.securiteam.com/windowsntfocus/6B00O2KC0C.html

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy