• »Sign In
  • »Sign Up
  • Check Out
  • »FAQs

    China Electronics Wholesaler

    E-mail:
    Password:
    • SHOPPING
    • NEWS
    • KNOWLEDGE
    • FROUM
    0 Items(s)(US$0.000)
    • All Topics
    • >>
    • Audio
    • Submit a New Story
    • 5
    • dig it

    0day Treasure Hunt: Researcher Hides IE Attack on Web

    Security researcher Aviv Raff has published code that would allow someone to take control of a computer running Internet Explorer, but there's a catch. He's not saying exactly where he's hidden the attack.

    "Somewhere in my blog, I embedded a proof-of-concept code which exploits this 0day vulnerability," Raff wrote in a Wednesday blog posting. A 0day attack is a previously undisclosed software flaw that has not been fixed by the software maker.

    The bug, which affects Internet Explorer 7 and IE 8, could allow an attacker to run unauthorized software on a victim's computer. Raff informed Microsoft of the flaw on Tuesday and the software vendor has not yet patched it, Raff said.

    Microsoft didn't get much time to fix the bug, but Raff said he didn't feel that Microsoft would address the issue quickly unless he went public with the vulnerability.

    When he has followed Microsoft's responsible disclosure guidelines in the past, the company has been too slow to fix bugs, he said via instant message. "The last time I used their Responsible Disclosure policy it took them six months to fix one line of code."

    For Raff's attack to work, the hacker would first have to put a small amount of HTML code on a Web site and then persuade the victim to use a specific Internet Explorer feature on that site, he said.

    The Israeli hacker said that the idea of disclosing his attack in a treasure hunt came from a local custom of playing such games during Israel's Independence Day, which falls on Thursday.

    Raff has put the code on his own Web site, and he will offer clues as to what people must do to trigger the flaw over the next few days. When triggered, Raff's proof-of-concept code launches two copies of Microsoft's calculator software on the victim's computer, but it could be altered to do something malicious.

    Next Wednesday, he will release full details of the bug along with his proof-of-concept code.

    Microsoft was unable to immediately comment for this story.

    Submitted:
    10 days ago
    Submitter:
    robot_post
    Topic:
    Audio
    Source:
    www.pcworld.com
    • AMD Jumps to 12-core Chip, Skips 8-core Chip Plans
    • Internet Archive Challenges FBI's Secret Records Demand
    • EBay to Turn on Feedback System Changes
    • Clearwire Venture Promises New Kinds of Services
    • Web Attack Worm Infecting Hapless Sites
    • Microsoft Should Sideline Search, Focus on Strengths
     
    1GB Metallic 1.5 Inch OLED Display MP4 Watch Player, MP4P-WAT-005
    Sample Price:US$53.053
     
    2GB Metallic 1.5 Inch OLED Display MP4 Watch Player, MP4P-WAT-005
    Sample Price:US$56.342
    Comments (0)
    • Add Your Comment
    • Please login or register to submit your comment.
      • What are the benefits of having a Dig account?
      • Share your opinion by posting comments on the stories that interest you
      • Dig the stories that you like and help determine what should be popular on Digg
      • Create a network of friends, so you can help each other find interesting stories
      • Start building a history of content that you've Dugg, for easy reference later
     
    4GB Metallic 1.5 Inch OLED Display MP4 Watch Player, MP4P-WAT-005
    Sample Price:US$61.347
     
    1.5inch OLED Screen Mens Metallic Watch 1GB MP4 Player, MP4P-WAT-006
    Sample Price:US$51.337
    CUSTOMER SERVICE SHOPPING HELP MY ACCOUNT COMPANY INFO TOOLS & RESOURCES
    • Contact Us
    • RMA Request
    • Looking for a item
    • Send Us a Message
    • Shopping Process
    • Return Policy
    • FAQs
    • Knowledge Base
    • Login/Register
    • My Account
    • Order History
    • My Wish list
    • About Us
    • Wholesale News
    • Customer Comments
    • Site Map
    • Downloads
    • Search
    • Links

    visamastercarddiscoverecheckamexpaypalPayPal Verified

    Submit your website to 20 Search Engines - FREE with ineedhits! Submit Your Site To The Web's Top 50 Search Engines for Free!
    Policies | Privacy Notice | Copyright © 2006 China Electronics Wholesaler Inc. All rights reserved.