[34883] in bugtraq

home help back first fref pref prev next nref lref last post

Still Vulnerable in MSIE

daemon@ATHENA.MIT.EDU (Greg Kujawa)
Fri May 14 13:31:59 2004

Date: 14 May 2004 14:36:49 -0000
Message-ID: <20040514143649.16379.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: Greg Kujawa <greg.kujawa@diamondcellar.com>
To: bugtraq@securityfocus.com



With the latest vendor AV definitions and all of the Microsoft Security Updates my MSIE 6 application still was vulnerable to some apparent cross-site scripting exploit. I was hit with one of the many Agobot variants when exiting a site detailing some IE vulnerabilities (http://www.hnc3k.com). The site exit led to a series of pop-up and pop-under ads. 

All of these site redirects apparently resulted in a www2.flingstone.com site dropping in a infamous.exe file onto my computer. All the while I saw no prompts to download or execute anything whatsoever. All I did was close the windows that were coming up.

Just an FYI since even the latest updates on all fronts cannot ensure peace of mind.

home help back first fref pref prev next nref lref last post