[37583] in bugtraq
Official IFRAME patch - make sure it installs correctly
daemon@ATHENA.MIT.EDU (Berend-Jan Wever)
Thu Dec 2 15:52:29 2004
Message-ID: <000f01c4d808$d7622d10$0100a8c0@grotedoos>
From: "Berend-Jan Wever" <skylined@edup.tudelft.nl>
To: <full-disclosure@lists.netsys.com>, <bugtraq@securityfocus.com>
Date: Thu, 2 Dec 2004 01:49:52 +0100
MIME-Version: 1.0
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
The IFRAME vulnerability has been patched, see http://www.microsoft.com/technet/security/bulletin/ms04-040.mspx
*** Make sure you are patched after installing ***
I installed it using "Automatic Updates" (on Win2ksp4), rebooted and loaded my InternetExploiter.html: IT STILL WORKED!!
Even though both "Automatic Updates" and "http://windowsupdate.microsoft.com" reported that I was patched!?!
I manually downloaded the exe and ran it, rebooted and now I'm finally truely patched.
It might just have been a glitch on my system, but you might wanna check anyway: InternetExploiter.html can still be downloaded from my website.
Berend-Jan Wever
<skylined@edup.tudelft.nl>
http://www.edup.tudelft.nl/~bjwever
SkyLined in #SkyLined on EFNET