Re: U.S. Steers Consumers Away From IE

From: Zurab Davitiani (agt_at_mindless.com)
Date: 07/06/04


Date: Tue, 06 Jul 2004 07:35:14 GMT

Leythos wrote:

> As they said, it's about Java Scripting - if you have it enabled then
> you are vulnerable. The key, even with IE, is to disable all scripting
> (java or ActiveX) in your IE Internet security zone, then set your IE
> Trusted Zone to Medium security. No pop-ups, nothing, works like a
> champ.

If you are referring to the recent execCommand flaw, then the problem is
ActiveX and the way Internet Explorer specifically fails to enforce the
security boundary between different domains. Check out the CERT description
of the vulnerability: http://www.kb.cert.org/vuls/id/326412

Disabling scripting in IE will render many websites useless or cripple them
in one way or another. Check out this article:
http://www.eweek.com/article2/0,1759,1619961,00.asp

> If you get to a site that doesn't work, because you disabled scripting,
> and it's a site you really want to trust, then add the site to your IE
> Trusted Zone - make sure you keep the Trusted Zone at MEDIUM, it
> defaults to LOW.

I don't have the IE handy to test this but wouldn't adding a site to trusted
zone and allowing scripting make that site vulnerable to the same
"injection?"



Relevant Pages

  • [NT] Dotless IP Addresses Can Cause IE to Move into Intranet Zone
    ... Dotless IP Addresses Can Cause IE to Move into Intranet Zone ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The third is a new variant of a vulnerability discussed in Microsoft ...
    (Securiteam)
  • [NT] Cookie Data in IE Can Be Exposed or Altered Through Script Injection
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Many web sites use cookies as a way to store information on a user's local ... customers can protect their systems by disabling active scripting. ... are not affected by the HTML mail exploit of this vulnerability because ...
    (Securiteam)
  • [UNIX] Path Disclosure and Cross Site Scripting Vulnerability in MyABraCaDaWeb
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A security vulnerability found in this product allows full path disclosure ... and Cross Site Scripting attacks. ... A vulnerability in MyABraCaDaWeb allow attackers to determine the physical ...
    (Securiteam)
  • Re: Html injection/hacking, but what does it do? Any advice?
    ... I'm not very good on security, but from what I read, if you write scripts ... cross-site scripting, which is more serious than a bit of spam. ... someone enters a comment with the characters, ... I can't say for sure if you do have the vulnerability. ...
    (alt.html)
  • [SCSA-013] Cross Site Scripting vulnerability in testcgi.exe
    ... Security Corporation Security Advisory ... "Ceilidh is a Web-based threaded discussion engine that features ... This kind of attack known as "Cross-Site Scripting Vulnerability" is ...
    (Bugtraq)