HTASploit

From: Larry Seltzer (larry_at_larryseltzer.com)
Date: 07/30/03

  • Next message: Chris Harrington: "Re: IAS as a RADIUS server"
    To: <focus-ms@securityfocus.com>
    Date: Tue, 29 Jul 2003 21:27:54 -0400
    
    

    An IE exploit is alleged at http://www.spywareinfo.com/articles/htasploit/ "that allows
    trojans and other malicious software to be introduced onto a machine via Internet
    Explorer despite security settings."

    I won't bother repeating all the details here, but wonder: If the exploit presumes that
    a malicious ActiveX control runs on the system and executes MSHTA.EXE from the Windows
    folder, what is the point of the HTA stuff? Once you get a malicious ActiveX control on
    the system anything's possible. Am I wrong?

    Larry Seltzer
    Editor
    Ziff Davis Security SuperSite
    http://security.ziffdavis.com/
    larryseltzer@ziffdavis.com

    ---------------------------------------------------------------------------
    Your network firewall and IDS products do not prevent Web application
    attacks - the most common form of online exploitation- resulting in Web
    defacement, data theft, sabotage and fraud.
    KaVaDo is the only company that provides a complete suite of Web
    application security products.
    Download a FREE whitepaper on "Security Policy Automation for Web
    Applications":http://www.securityfocus.com/Kavado-focus-ms
    ---------------------------------------------------------------------------


  • Next message: Chris Harrington: "Re: IAS as a RADIUS server"

    Relevant Pages

    • Re: Unable to download/run ActiveX controls
      ... Your current security settings prohibit running Active X ... Test Your ActiveX Installation ... change the security settings for this zone? ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: Big Security Permission Mistake - Please Help if You Can
      ... Reset Security Settings Back to the Defaults ... security template to be applied. ...
      (microsoft.public.windowsxp.configuration_manage)
    • Re: why microsoft choose mfc rather than wtl?
      ... One is that users need to keep their browser security settings as high as ... attacks that aren't possible in the higher security settings. ... point was that you should not dictate securiy settings to your customers ...
      (microsoft.public.vc.mfc)
    • RE: What the heck is this msblast.exe
      ... Its also worth noting that if you see 'Security Routing' in your services in ... |Your network firewall and IDS products do not prevent Web application ... |attacks - the most common form of online exploitation- resulting in Web ...
      (Focus-Microsoft)
    • RE: System Restore
      ... Security setting descriptionsComputer Configuration\Windows ... Windows XP Service Pack 2 introduces some security-enhancing changes to ... Account Policies Password Policy, Account Lockout Policy, and Kerberos Policy ... You can configure the security settings that are described in this section ...
      (microsoft.public.windowsxp.general)