Another Internet Explorer Exploit (September 2006)

Friday, September 1st, 2006

A new Internet Explorer bug was published on Monday. It’s been given a CVE (2006-4446) and affects IE 6.0 SP1. It’s worth considering alternative browsers. Details from bugtraq indicate that it’s a buffer overflow in the DirectAnimation.PathControl COM Object(daxctle.ocx)… could cause DoS and possibly remote code execution.    Send article as PDF   

IE 7 INCOMPATIBLE with WORDPRESS blogs using the stattraq plugin

Wednesday, August 30th, 2006

I’ve FINALLY tracked down what was causing the issue with displaying my page in Internet Explorer 7 (RC1). It turns out that the stattraq plugin in wordpress (stattraq site) is part of the problem. Now, I don’t understand exactly WHY… because I do have stattraq on each of the sites, but one… onlineradiotv.com carried this […]

Other MS patch news as well as a Yahoo vulnerability?

Monday, August 14th, 2006

Or lack of currently available patch as the case may be. From the previous link it appears that there was at least one previously announced vulnerability that was not addressed in the recent patch day from Microsoft. From MS… “this is a DoS only issue that was not addressed in MS06-040, but will be addressed […]

Being cautious on the web…

Monday, August 14th, 2006

Incidents.org is reporting on the defacement of a security related web site (winsnort.com). They say they usually decline to comment on those because the attention is what the defacers thrive on. However, it does pay to keep your browser updated and antivirus current. What’s more…. Several days ago there was the news that the President […]

Mozilla Firefox user-agent spoofing

Tuesday, August 1st, 2006

Sometimes you run across a site that’s a browser snob. You know the type…. you visit it in Mozilla Firefox or (anything other than IE) and it says, “you must use Internet Explorer version 6 or newer to use this site. Well, some browsers have nice ways of changing the user agent through the menus, […]

Fasten your seatbelts – Browser vulnerability a day to be announced in July

Monday, July 3rd, 2006

I hope there aren’t too many browser developers that have planned on taking July off….. I ran across browserfun.blogspot.com where it is planned to release information on a web browser vulnerability EACH DAY for the month of July. This comes to us from HD Moore of Metasploit. Judging from This securityfocus article, most of the […]

Exploits a plenty – IE / Excel (Firefox?)

Thursday, June 29th, 2006

There are a number of vulnerabilities that are currently unpatched, but have working publicly known exploits for Excel (*2) and Internet Explorer (2 vulnerabilities here as well.) Proof of Concept code has been released for both the Excel and Internet Explorer vulnerabilities. This means, with the code publicly available, it won’t be long before it’s […]

Interesting spyware push download tactic…

Thursday, May 11th, 2006

Incidents.org has another interesting post about a spyware site. One of the handlers ran across it while doing a search for an educational institution. (They’ve used a wildcard in the dns record so that they can get traffic to {fillinkeyword}.nastydomain.com) Anyway… the main page tries to install WinAntiSpyware2006FreeInstall.cab from WinSoftware Corporation, Inc. It gives the […]

The Vista stories keep coming – Vista bad news for small security companies

Wednesday, May 10th, 2006

VuNet has an article today on the coming of Vista and the imminent doom of the smaller security companies. The hardest hit will be anti-spyware and personal firewall vendors they say. It may well be true, it does sound like a different approach to user permissions (limited priviliges by default?) IE7 running in a sandbox, […]

IE phishing exploit..

Sunday, April 9th, 2006

There is ANOTHER IE vulnerability that’s come across the news in the last week. It seems that this is currently only a Proof of Concept, I’ll have to check and see if anyone’s reported seeing this in the wild…, but essentially a race condition between a Macromedia flash file and web content can allow a […]

Google
 
Web www.averyjparker.com