[Full-Disclosure] SUPER SPOOF DELUXE : Take Two

http-equiv_at_excite.com
Date: 06/29/04

  • Next message: full-disclosure_at_nym.hush.com: "RE: [Full-Disclosure] SSH vs. TLS"
    To: <full-disclosure@lists.netsys.com>
    Date: Tue, 29 Jun 2004 18:51:13 -0000
    
    

    >Here's a quick and dirty demo injecting malware.com into
    >windowsupdate.microsoft.com :)

    >http://www.malware.com/targutted.html

    Thomas Kessler was kind enough to inform that this is not new,
    but in fact on old "issue" with Internet Explorer which by all
    accounts was supposed to be "patched" back in 1998[?]:

    Microsoft Security Program: Microsoft Security Bulletin (MS98-
    020) Patch Available for 'Frame Spoof' Vulnerability

    http://www.microsoft.com/technet/security/bulletin/ms98-020.mspx

    Quite clearly this contraption known as Internet Explorer is
    just broken. It's oozing pus from every pore at this stage.

    If indeed the issues are the exact same.

    You'd better wipe hands of it anyway.

    We give up.

    -- 
    http://www.malware.com
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: full-disclosure_at_nym.hush.com: "RE: [Full-Disclosure] SSH vs. TLS"

    Relevant Pages

    • SUPER SPOOF DELUXE Re: [Full-Disclosure] Microsoft and Security
      ... >Here's a quick and dirty demo injecting malware.com into ... Thomas Kessler was kind enough to inform that this is not new, ... Microsoft Security Program: Microsoft Security Bulletin (MS98- ... Quite clearly this contraption known as Internet Explorer is ...
      (NT-Bugtraq)
    • SUPER SPOOF DELUXE Re: [Full-Disclosure] Microsoft and Security
      ... Thomas Kessler was kind enough to inform that this is not new, ... accounts was supposed to be "patched" back in 1998: ... Microsoft Security Program: Microsoft Security Bulletin (MS98- ... Quite clearly this contraption known as Internet Explorer is ...
      (Full-Disclosure)
    • SUPER SPOOF DELUXE Re: [Full-Disclosure] Microsoft and Security
      ... Thomas Kessler was kind enough to inform that this is not new, ... accounts was supposed to be "patched" back in 1998: ... Microsoft Security Program: Microsoft Security Bulletin (MS98- ... Quite clearly this contraption known as Internet Explorer is ...
      (Bugtraq)
    • Re: OE Hyperlinks do not work
      ... opens up. ... I decided to check the other to user accounts and opened up ... Scroll down to URL:HyperText Transfer Protocol and select it. ... the proper associations for Internet Explorer. ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
    • Re: Microsoft Security Bulletin MS03-040 - 828750
      ... Pardon me, but do you have ANY idea how foolish your post is? ... > Title: Cumulative Patch for Internet Explorer Execution > Date: October 3, ... > The Microsoft Security Response Center has released Microsoft Security> Bulletin MS03-040 ...
      (microsoft.public.security)