r3d1405241470 0 Report post Posted December 6, 2004 A new win ie xp sp2 exploit, worser than ever. "]....Security experts have identified a modified exploit that can target computers running Windows XP SP2.Although the exploit is tricky to perform, it combines two vulnerabilities in Internet Explorer 6 with a series of ActiveX exploits to break security settings in computers running SP2. It runs when a user moves a file or an image from one part of a Web page to another, but in the process the exploit downloads code to machines that circumnavigates Local Computer security settings in SP2.....Researchers at Danish security company Secunia have labelled the vulnerability as "highly critical" because it allows hackers to access local resources and bypass security features in Windows XP SP2."This is the most serious vulnerability for SP2 that we have the moment," said Thomas Kristensen. "The problem is that by exploiting this vulnerability in IE it's possible to drag a file into the local security zone and change the settings. On an SP2 system, this shouldnât be a problem, but it is still possible to bypass the security with an Active X control."..."It's a series of events you have to perform before you are able to bypass security settings," said Kristensen. "It is complicated. But they are several minor issues that can be compromised so it's possible to circumnavigate the security settings." we expect that SP2 was supposed to tightly lock down the security issues with IE 6, but this was clearly a compromise in it security. The solution was to disable the drag-and-drop or copy-and-paste options on Internet Explorer and set the security level to "high" in the Internet zone. Share this post Link to post Share on other sites
shaldengeki1405241473 0 Report post Posted December 6, 2004 O_o;; I think it goes without saying that the bigger the corporation releasing the software, the more vulnerable it is. They can't be very efficient or secure with that large of a company, so they just do the best they can for as little money spent as possible.Which is why I'm not using IE, I'm using Firefox. Share this post Link to post Share on other sites
rmdort 0 Report post Posted December 7, 2004 i cant WTF are the IE experts doing....... More n more holes .. more n more patches to download.... i m feeling dizzy with this Windows..... I should have chosen linux on my COM Share this post Link to post Share on other sites
Abystar1405241473 0 Report post Posted December 9, 2004 I don't think this is problem of SP2. but we can use windows update for the latest bug fix... Share this post Link to post Share on other sites