1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Disable Active Scripting

Discussion in 'Windows XP' started by bobm735, 2004/08/20.

Thread Status:
Not open for further replies.
  1. 2004/08/20
    bobm735

    bobm735 Well-Known Member Thread Starter

    Joined:
    2002/11/15
    Messages:
    460
    Likes Received:
    1
    I don't understand this below. also if I should disable Active Scripting .How do I do it and what efect will it have.?
    thank you


    Description:
    http-equiv has discovered a vulnerability in Microsoft Internet Explorer, which can be exploited by malicious people to compromise a user's system.

    The vulnerability is caused due to insufficient validation of drag and drop events issued from the "Internet" zone to local resources. This can be exploited by a malicious website to e.g. plant an arbitrary executable file in a user's startup folder, which will get executed the next time Windows starts up.

    http-equiv has posted a PoC (Proof of Concept), which plants a program in the startup directory when a user drags a program masqueraded as an image.

    NOTE: Even though the PoC depends on the user performing a drag and drop event, it may potentially be rewritten to use a single click as user interaction instead.

    This vulnerability is a variant of an issue discovered by Liu Die Yu.
    SA9711

    The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP1/SP2.

    Solution:
    Disable Active Scripting or use another product.

    Provided and/or discovered by:
    http-equiv

    Other References:
    SA9711:
    http://secunia.com/advisories/9711/




    Please note: The information, which this Secunia Advisory is based upon, comes from third party unless stated otherwise.

    Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
     
  2. 2004/08/20
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389

  3. to hide this advert.

  4. 2004/08/20
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
    PeteC--Went to Arie's article since I wanted to get the PowerTweaks download. The download was a little flaky. Then, even more flaky, I clicked on the .exe file, but no additions to my IE Tools menu. Redownloaded twice, each time when I clicked on the .exe file was told "not a valid Win 32 application ". However, I now do have the "Add to Restricted/Trusted Zone" commands in IE Tools. Weird.
     
  5. 2004/08/20
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Welshjim

    Very strange - I have just downloaded again from the link in Arie's article and reinstalled - just fine. Presumably you did not see these boxes ....
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.