RE: [Full-Disclosure] How big is the danger of IE?

From: Eric Paynter (eric_at_arcticbears.com)
Date: 07/08/04

  • Next message: Barry Fitzgerald: "Re: [Full-Disclosure] shell:windows command question"
    To: full-disclosure@lists.netsys.com
    Date: Thu, 8 Jul 2004 07:56:19 -0700 (PDT)
    
    

    On Thu, July 8, 2004 4:51 am, Sapheriel said:
    > well, i read about a hacker scenario once that utilizes IE vulnerabilities
    > by exploiting the interests of employees. basically, you lure an employee
    > to a website you prepared that exploits some bug in IE to install a trojan
    > on that pc, thus bypassing firewall and other security precautions.

    Don't forget that the "website" you lure the person too can also be an
    email, or anything else with embedded HTML - one of those chain-mail power
    point things - almost anything.

    -Eric

    --
    arctic bears - affordable email and name services @yourdomain.com
    http://www.arcticbears.com
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Barry Fitzgerald: "Re: [Full-Disclosure] shell:windows command question"

    Relevant Pages

    • Re: Scheduling Employees
      ... Have a look at this website, you should be able to find something you can ... of hours that all employees will be scheduled throughout the day. ... scheduling 2 departments and have fiddled around with excel until it has ... A template url would be excellent. ...
      (microsoft.public.excel.misc)
    • Re: OT:IE7 Public Beta
      ... Thats external users; its a small company in terms of employees and internal ... The website that was taken from is ... > So it varies according to target audience. ...
      (uk.games.video.xbox)
    • Re: domain name issue
      ... the employees try to go to our website the system looks internally for it ... Just create a Host Record in the DNS Zone. ...
      (microsoft.public.windows.server.networking)
    • Re: Ferrite question
      ... I do not know how to make a website to place the pictures ... In our continuing effort to conform to political correctness, ... insist that all employees call a spade a shovel. ...
      (sci.electronics.design)
    • Re: Saturday Railtour
      ... timings on their website. ... figured the lure of 2 tours in one morning may motivate me to get up ...
      (uk.railway)