Re: Update and comments on the MS02-023 patch, holes still remain

From: Andrew Clover (and@doxdesk.com)
Date: 05/17/02


Date: Fri, 17 May 2002 09:27:37 +0000
From: Andrew Clover <and@doxdesk.com>
To: bugtraq@securityfocus.com

Thor Larholm <Thor@jubii.dk> wrote:

> The above is merely misinformation on their parts. The Restricted Sites Zone
> tries to disable scripting ( a requisite for the dialogArguments
> vulnerability ), but many vulnerabilities allow you to circumvent this
> setting

Even non-vulnerabilities allow it. For example a <meta http-equiv="refresh">
can redirect to a page not within the Restricted Sites zone, and a
<frame> or <iframe> can include content from a non-restricted site.

It is also possible to create an about:<script>...</script> URL, which
injects scripts into the Internet zone. Such URLs cannot be put in the
Restricted Sites zone using the normal IE Security tab. Microsoft have
refused to remove this undocumented behaviour.

So essentially the Restricted Sites feature offers zero security protection
by design. Users should not rely on it to enforce stricter settings than
present in the Internet Zone.

-- 
Andrew Clover
mailto:and@doxdesk.com
http://and.doxdesk.com/



Relevant Pages

  • Microsoft Security Bulletin MS02-023
    ... IE ships with several files that contain HTML on the local file ... An attacker could craft a web page ... with a URL that exploits this vulnerability and then either host ... it introduces a behavior change to the Restricted Sites zone. ...
    (microsoft.public.security)
  • Re: Microsoft Security Bulletin MS02-023
    ... > - A cross-site scripting vulnerability in a Local HTML Resource. ... An attacker could craft a web page ... it introduces a behavior change to the Restricted Sites zone. ...
    (microsoft.public.security)
  • Re: Minor IE vulnerability: about: URLs
    ... Subject: Minor IE vulnerability: about: URLs ... At 17:13 +0200 19.10.01, Clover Andrew wrote: ... >Assume all versions of IE/Win are vulnerable. ... >Restricted Sites Zone, simply by pointing at another site that is ...
    (Bugtraq)