Press CTRL-D to bookmark us
Welcome Guest Login / Register / Members
Search in  
Top Submit newsSubscribe
Communication | Computer Crime | Digital Audio, Video, Photo | General News | Hardware | Internet | Mobile | PDA | Security | Software | Vulnerability |


Previous articleBack to news listNext article
 

 Sponsored links

Want to become one of our authors and see your work published on ALLSeek.iNFO ?
 
 Microsoft Internet Explorer Trusted Domain Default Settings Facilitate Silent Installation of Executables
Categorie: Vulnerability
Posted: 2003-12-29 by ReCall
Views: 470
Source: Click here
 
Current Rating: Not rated
Poor Best
 Details
Description: An exploit method was reported in Microsoft Internet Explorer, illustrating IE's weak default settings for the 'Trusted Site' security zone. A remote user can create HTML that will cause an arbitrary executable to be silently downloaded to and installed on a target user's system.

http-equiv reported that a remote user can create HTML that, when loaded by a target user, will trigger the flaw and install arbitrary code to the target user's system, potentially in an arbitrary security domain.

With the assistance of a cross-site scripting flaw in a web site designated as a 'trusted site' domain, a remote user can display HTML containing a '' tag to install an executable file within an arbitrary security zone [if a web site in the security zone suffers from cross-site scripting flaws]. If the site is in the 'Internet' zone, the target user may be prompted for installation, but if the site is in the 'trusted site' domain, the target user will not be prompted, according to the report.

The executable will reportedly be installed in the Temporary Internet File directory associated with a trusted zone.

Impact: A remote user can cause arbitrary binaries to be silently downloaded and installed on the target
user's system.

Solution: No solution was available at the time of this entry.
 
Syndication
Permalink Email this

The URI to TrackBack this entry is:
http://allseek.info/news/trackback.php?id=624

User comments (post your comments here)

Only registerd members can post comments and articles
 

Previous articleBack to news listNext article
 



InterJOB.su

SpyLOG Page Rank Checker
LAST QUERIES