Re: Spyware and Adware affect every internet user
- From: Sebastian Gottschalk <seppi@xxxxxxxxx>
- Date: Fri, 05 May 2006 23:03:53 +0200
Fuzzy Logic wrote:
This is one.I was referring to the flaws that are getting 'exploited all day long'.<http://technet2.microsoft.com/WindowsServer/en/Library/22fffeb1-66a3-4You're wrong, these flaws are getting exploited all day long. ThisReferences?
has actually gone so far that Microsoft declared some of them to be
features.
d5c -bc12-def57c3354fa1033.mspx>
Which is?
Running executable through mismatching MIME times.
Microsoft never fixed the defective handling, but instead added some
common type-combination to a blacklist. On Windows Server 2003 this was
even turned into a Group Policy, yet it still isn't an empty whitelist
and certain combinations can lead to execute f.e. HTA files (which has
actually been reported and fixed some weeks ago).
Wrong, as for some (even critical) vulnerabilities there are no such
things like safe configuration or workaround.
So you say. It's certainly not been my experience.
I gave you a list with some exploits. Show me a configuration that
prevents all of them.
BTW, you think misusing IE as a webbrowser is a credible state?
Huh? If IE isn't a web browser I'm not sure what it is?
It is a Rich Platform Client for COM/ActiveX Applications.
It may not be a web browser that YOU approve of but it's
still a web browser none the less.
I've pointed you to documentation about design problems that clearly
show that IE was never intended to be used in a hostile environment.
And well, it renders HTML pretty poorly, doesn't even do the SGML
parsing correctly (which disqualifies it as a webbrowser totally) and
even Telnet performs better on HTTP Digest Authentication (which is
totally laughable for something claiming to be a webbrowser).
.
- Follow-Ups:
- Re: Spyware and Adware affect every internet user
- From: Fuzzy Logic
- Re: Spyware and Adware affect every internet user
- References:
- Re: Spyware and Adware affect every internet user
- From: Fuzzy Logic
- Re: Spyware and Adware affect every internet user
- From: Sebastian Gottschalk
- Re: Spyware and Adware affect every internet user
- From: Fuzzy Logic
- Re: Spyware and Adware affect every internet user
- From: Sebastian Gottschalk
- Re: Spyware and Adware affect every internet user
- From: Fuzzy Logic
- Re: Spyware and Adware affect every internet user
- From: Sebastian Gottschalk
- Re: Spyware and Adware affect every internet user
- From: Fuzzy Logic
- Re: Spyware and Adware affect every internet user
- From: Sebastian Gottschalk
- Re: Spyware and Adware affect every internet user
- From: Fuzzy Logic
- Re: Spyware and Adware affect every internet user
- From: Sebastian Gottschalk
- Re: Spyware and Adware affect every internet user
- From: Fuzzy Logic
- Re: Spyware and Adware affect every internet user
- From: Sebastian Gottschalk
- Re: Spyware and Adware affect every internet user
- From: Fuzzy Logic
- Re: Spyware and Adware affect every internet user
- From: Sebastian Gottschalk
- Re: Spyware and Adware affect every internet user
- From: Fuzzy Logic
- Re: Spyware and Adware affect every internet user
- Prev by Date: Re: Spyware and Adware affect every internet user
- Next by Date: Re: Spyware and Adware affect every internet user
- Previous by thread: Re: Spyware and Adware affect every internet user
- Next by thread: Re: Spyware and Adware affect every internet user
- Index(es):