stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


Nasty new IE vulnerability







Nasty new IE vulnerability

Nasty new IE vulnerability 12/09/2003 02:34 PM

Most people reading are probably aware of the common trick whereby spammers and other assorted ne'er-do-wells publish URLs with usernames that look like hostnames to fool people in to trusting a malicious site - for example, http://www.microsoft.com&session%123123123@simon.incutio.com . This trick is frequently used by spammers to steal people's PayPal accounts, by tricking them in to "resetting" their password at a site owned by the spammer but disguised as PayPal.com.

Today's new Internet Explorer vulnerability makes the problem a hundred times worse. By including an 0x01 character after the @ symbol in the fake URL, IE can be tricked in to not displaying the rest of the URL at all. Don't expect a patch for a while either; the guy who discovered the bug released it to BugTraq on the same day he notified the vendor.




This is a GrokNews Entry: (what is grok?)





Similar Items

Nasty new IE vulnerability

Grok Headline matches for Nasty new IE vulnerability

Nasty LKM


Nasty LKM 08/08/2004 07:03 AM
Check it out !

A Nasty Fix For Apple


A Nasty Fix For Apple 12/11/2003 12:30 AM
It didn't have to be this way. Properly trained support reps would have headed this problem off long before it blossomed into a subversive online antiadvertising campaign. And a better customer-support system in general could be a huge selling point for Apple, as users encounter increasing complexity in pulling together the various pieces of the digital lifestyle. By Alex Salkever (BusinessWeek via MyAppleMenu)

Nasty telemarketers


Nasty telemarketers 06/05/2005 11:31 PM
Every so often we get a call from 888 858 9823. Sometime in the mid-nineties the phone number was the fax number of some small company here in Los Angeles, so when it just said "click [silence]" I thought it was a confused fax machine. Over the last weeks it's become more frequent. Every few days or so, maybe more. Grrh. Today I tried waiting a little to see if it was a telemarketer, but nothing happened. I tried looking...

Nasty new IE hole


Nasty new IE hole 12/09/2003 06:09 PM
A new MS Internet Explorer vulnerability is discovered. Most digerati already know about the spammer and lamer trick to publish URLs that look like legitimate hostnames to fool people in to trusting a malicious site. This trick is frequently used by spammers to steal people's PayPal accounts, by tricking them in to "resetting" their password at a site owned by the spammer but disguised as PayPal.com. Today's new IE vulnerability is significantly worse. By including an 0x01 character after the @ symbol in the fake URL, IE can be tricked in to not displaying the rest of the URL at all. Don't expect a patch right way, the guy who found the hole released it to BugTraq on the same day he notified Microsoft. (via Simon Willison)

Nasty AT&T Surprise


Nasty AT&T Surprise 07/02/2004 09:53 AM
AT&T Wireless hit me with an unpleasant surprise this month — a $268.68 cell phone bill, compliments of roaming and...

A Nasty Fix for Apple


A Nasty Fix for Apple 12/11/2003 02:27 PM
Business Week Dec 11 2003 1:37PM ET

PDA Viruses Could Get Nasty


PDA Viruses Could Get Nasty 07/29/2004 11:58 PM
Viruses that target handhelds can be even more dangerous than their cousins that attack PCs, spawning self-replicating programs that hide easily, a security researcher told an audience of security professionals at the Black Hat Briefings conference here this week.

The first virus aimed at Pocket PC handhelds, revealed last week, could be far worse if it were modified slightly to carry a harmful payload, said Seth Fogie, a vice president of Airscanner, which develops security software for the Window Mobile platform.

The benign WinCE4.Duts.A (or just "Dust") virus was created as a demonstration of threats against personal digital assistants. However, Fogie noted, such programs could spread stealthily, logging keystrokes on the Pocket PC's "soft keyboard," and sending data stored on handhelds across the Internet.

View: Complete Article
News source: PCWorld

Read full story...

It's Jackson if You're Nasty


It's Jackson if You're Nasty 02/10/2004 02:45 AM

I watched the game, but wasn't impressed by the commercials and tuned out the half-time show about half-way through... then I read about this:

Stupid CBS... Bad idea... Bad execution...


HAPPY PEOPLE ARE NASTY?


HAPPY PEOPLE ARE NASTY? 06/21/2004 07:48 AM
more» .. more

nytimes.com/2004/06/20/magazine/20WWLN.html
track this site | 4 links


RIAA's Nasty Easter Egg


RIAA's Nasty Easter Egg 04/11/2004 05:03 PM

Nasty 0.5 (Default branch)


Nasty 0.5 (Default branch) 04/05/2005 11:56 AM
Nasty is an advanced tool for recovering GPG private-key passphrases. It has multiple methods for brute-force attacking the passphrase (searching the whole space, random searches, and dictionary attacks using an external wordlist). It saves its state to a file so that it can continue from where it stopped the last time it ran.

EMC, IBM storage battle gets NASty


EMC, IBM storage battle gets NASty 04/18/2005 07:33 AM
EMC this week announced a new NAS system to its lineup, playing a tit-for-tat game with IBM in the storage market.

IBM's battle with EMC gets NASty


IBM's battle with EMC gets NASty 04/06/2005 09:15 AM
IBM and Network Appliance on Wednesday announced a strategic storage relationship aimed at expanding both companies' product lines and offering a more united front against storage giant EMC.

Nasty 0.6 (Default branch)


Nasty 0.6 (Default branch) 04/13/2005 02:11 PM
Nasty is an advanced tool for recovering GPG private-key passphrases. It has multiple methods for brute-force attacking the passphrase (searching the whole space, random searches, and dictionary attacks using an external wordlist). It saves its state to a file so that it can continue from where it stopped the last time it ran.
Changes:
Now compiles and runs with version 1.0.2 of the gpgme library. A bug that could cause random crashes has been fixed.

Scratching Nasty Blogger


Scratching Nasty Blogger 01/16/2004 01:02 PM

After reading Mark Pilgrim's latest post in which he dragged XHTML into the bad feed handling discussion and tried to instigate a fight by making it look like Tim Bray insulted others, I felt pretty upset and my opinion of Mark dropped down a few notches.  Then this morning, I found out via Dave that Mark is blocking traffic coming from Dave's blog.  That drops my opinion of Mark down to the gutter so I removed him from my blogroll.

Put me on your blacklist too, Mark, because I finally had enough of your nasty antics.  No matter how much fancy Python script you write, you'll never be able to refill those holes if you keep digging like that.


Online personals business gets nasty


Online personals business gets nasty 06/16/2004 07:33 PM
Techzonez Jun 16 2004 11:21PM GMT

IBM's battle with EMC gets NASty
(InfoWorld)


IBM's battle with EMC gets NASty
(InfoWorld)
04/06/2005 09:21 AM
InfoWorld - IBM and Network Appliance on Wednesday announced a strategic storage relationship aimed at expanding both companies' product lines and offering a more united front against storage giant EMC.

EMC, IBM storage battle gets NASty
(InfoWorld)


EMC, IBM storage battle gets NASty
(InfoWorld)
04/18/2005 07:42 AM
InfoWorld - EMC this week announced a new NAS system to its lineup, playing a tit-for-tat game with IBM in the storage market.

Paid Search Battles Get Nasty


Paid Search Battles Get Nasty 06/01/2004 04:14 AM
It seems that paid search is getting a ton of interest these days, with the two big providers being Google and Yahoo. As competitors, though, the battle is starting to get a little nastier. Yahoo recently banned Shopping.com from advertising on their site, because the ads directed users to a page that included Google ads. Eventually, the two companies worked out an agreement to include some Yahoo ads as well. The article points out that this raises some questions about how companies will deal with being blocked from advertising on certain search engines if they do business with the other. To be honest, though, this policy from Yahoo seems shortsighted. It's not as if they don't get money from Shopping.com when people click through the ads - even if they then go on to click through more Google ads. Why should Yahoo care what the person does after they've clicked through the ad - so long as the ad results are relevant? Obviously, they want more advertising dollars (and getting another deal with a company is valuable), but this seems to be a case where the company was doing more to take business away from a competitor than make business better for themselves.

nasty fixes for smbldap-tools


nasty fixes for smbldap-tools 12/07/2003 04:09 PM
A couple of things I had to do to make the cookbook smbldap-tools + howto work on my Debian system...

Nasty car wreck caught on live TV.


Nasty car wreck caught on live TV. 09/17/2004 10:22 PM
A dangerous intersection in Tampa... then, disaster strikes, on live TV. [note: Windows Media, high bandwidth, graphic]

Acxiom playing nasty in Opt Out List


Acxiom playing nasty in Opt Out List 11/17/2003 05:27 PM
In what only can be described as an attempt to have there cake and eat it too, Acxiom is refusing...

Nasty Malware Fouls PCs With Porn


Nasty Malware Fouls PCs With Porn 04/30/2004 04:52 AM
An especially evil new browser hijacker is sweeping the Net, spying on users of infected machines and pummeling them with truly vile pornography. Some folks are screaming for vengeance, but the problem is finding out who unleashed the vicious code. By Michelle Delio.

DoubleClick Inc receives a nasty DOS
attack


DoubleClick Inc receives a nasty DOS
attack
07/27/2004 11:18 PM

Direct and Related Links for 'DoubleClick Inc receives a nasty DOS attack'

InfoWorld reports that DoubleClick received a virtual server beating Tuesday thanks to the efforts from a DOS Attack (Denial of Service) originating from the Internet. Reports indicate the attack took place at about 10:30 a.m. Eastern Time. The attack was quite successful at crippling their website in addition to their ad servers. DoubleClick has indicated that their staff is working out a plan of defense in case this happens again,…

Slashdot | RIAA's Nasty Easter Egg


Slashdot | RIAA's Nasty Easter Egg 04/13/2004 01:57 AM
Record labels want to raise online mp3 prices to $3 per song .. RIAA's Nasty Easter Egg .. reports

slashdot.org/articles/04/04/11/2019235.shtml
track this site | 4 links


Germans develop nasty case of IE jitters


Germans develop nasty case of IE jitters 09/13/2004 07:07 AM
Switch to Mozilla, says Office for Information Security

Notes and Tips: Nasty Firmware Trap


Notes and Tips: Nasty Firmware Trap 06/25/2004 10:24 AM
Failing to follow Apple's instructions for firmware fixes before upgrading to Mac OS X may completely disable your computer.

Porno bl0g spam turns nasty


Porno bl0g spam turns nasty 08/04/2004 08:22 AM
Smut attack via compromised military proxies

Collaborative Book Idea Gets a Nasty
Review


Collaborative Book Idea Gets a Nasty
Review
11/17/2003 07:44 PM
The work is to be a collaboration among his readers who "are encouraged to post their thoughts and reflections on what I write in this ongoing blog on Google ...

Games move into the nasty side of life


Games move into the nasty side of life 12/13/2003 05:56 AM
BBC Dec 13 2003 4:45AM ET

Drowned, Not Downed, Trees in the Amazon
Get Nasty


Drowned, Not Downed, Trees in the Amazon
Get Nasty
09/07/2004 10:39 AM
Decomposing vegetation caused by a dam in Brazil has resulted in the emission of millions of tons of greenhouse gases.

BlackBerry fuels nasty campaign brush
fire


BlackBerry fuels nasty campaign brush
fire
05/28/2004 06:14 AM
Sympatico May 28 2004 9:57AM GMT

Chicken Swimsuit Model Hides Nasty Worm


Chicken Swimsuit Model Hides Nasty Worm 02/05/2005 09:20 PM
The Bropia worm lures MSN Messenger users with promises of sexy image files, but there's a bigger danger lurking, anti-virus experts warn.

Nasty Language on Live TV Renews Old
Debate (TechNews.com)


Nasty Language on Live TV Renews Old
Debate (TechNews.com)
12/13/2003 06:26 PM
FCC faces obscenity controversy after Billboard Music Awards .. WASHINGTON POST: Nasty Language on Live TV Renews Old Debate .. only brought to light

washingtonpost.com/ac2/wp-dyn/A61109-2003Dec12?language=printe r
track this site | 5 links


Spammers turn nasty in battle with
antispam websites


Spammers turn nasty in battle with
antispam websites
11/06/2003 08:51 AM
Computer Weekly Nov 6 2003 8:08AM ET

Nasty Linux kernel crash exploit found


Nasty Linux kernel crash exploit found 06/14/2004 10:48 PM
Versions 2.4.x and 2.6.x of the Linux kernel running on x86 systems are vulnerable to a simple, yet nasty bit of C code that will hard lock the kernel. The kicker is that anyone with shell access can execute the code and bring down the system.

Article: Acne bug's nasty secrets
spotted| New Scientist


Article: Acne bug's nasty secrets
spotted| New Scientist
07/31/2004 10:44 AM
Acne bug’s nasty secrets discovered

newscientist.com/news/news.jsp?id=ns99996222
track this site | 3 links


Fred Dale, creator of nasty smells, dies
(Reuters)


Fred Dale, creator of nasty smells, dies
(Reuters)
05/12/2004 01:03 PM
Reuters - Fred Dale, the man who concocted foul smells such as Dead Roman Soldier's Armpit and Viking Loo for theme parks, has died, his son says.

NISCC Vulnerability Advisory 236929:
Vulnerability Issues in TCP


NISCC Vulnerability Advisory 236929:
Vulnerability Issues in TCP
04/20/2004 02:16 PM
David Ahmad (Apr 20 2004)
Grok Description matches for Nasty new IE vulnerability
GrokA matches for Nasty new IE vulnerability

Nasty new IE vulnerability

The following phrases have been identified by the grok system as matching this entry:

















Also check out:


Grok

Ipod Porn on the
Rise

Brief Abstract of
Wikipedia's
Mesothelioma Cancer
page

Get first aid
instructions in your
cell phone

IE is crap
JSPWiki gains
podcasting support

Spamcup
xsdb -- eXtremely
Simple DataBase

JImageTaglib
JasperReports
HP dangles $1
billion worth of
services deals in
front of analysts

The Mushroom House
Anti-Spam Laws Sound
Nice, But Won't Do
Much

Exercise left for
the student

Intelligent
Documents Headline
XML 2003

where is version
1.0?

Open Textbook
Project

InterSAINT
Free/Open Source
research Community

OSDN
CSR Upgrades
Bluetooth

3's 3G Video Gets A
Kick

Vodafone Launch 3G
For Laptops

DoCoMo to Launch 3
New 505iS Models

Silicon.com: Techies
and finance squaring
off over IT spending

META Group:
Strategic IT Cost
Cutting

automated via a
dedicated tool

TechRepublic:
Building and
Implementing a
Successful
Information Security
Policy

META Group: Patch
Management: Building
the Process

UN: Internet Summit
Exposes Digital
Divisions Between
Rich And Poor

Cos. Work on
Internet Phone
Service Deal

Congress Approves
Anti-Spam
Legislation

Rifts Between
Nations Loom at U.N.
Summit

Annan: Net Must
Reaffirm Media
Freedoms

US Airways Pulls
Tickets From Expedia

Reynolds: Who will
control the
Internet?

Sweetwater, CDW,
Outpost Hot Deals
updated

Four new titles from
Aspyr shipping this
month

LaCie offers
FireWire 800 PCMCIA
card

SpamSieve 2.1 adds
Apple Mail POP
support

Matt gets two offers
Review of Dell's new
20-inch LCD monitor

Eyeball cam
The Long Line
Bush Opposes Taiwan
Bid for Independence

Have a holly, jolly
Christmas....

It's just money
'Forking' Greatest
Danger of Adopting
Open Source?

AMD's Window's woes:
Linux to the rescue!

Aspyr gets ready to
ship four new games

MDKSA-2003:112 -
Updated cvs packages
fix malformed module
request
vulnerability

MDKSA-2003:113 -
Updated screen
packages fix buffer
overflow
vulnerability

Re: Dell BIOS DoS
Internet Explorer
URL parsing
vulnerability

BNCweb File
Disclosure
Vulnerability

@Mail web interface
multiple security
vulnerabilities

what is grok?