Kolejna luka we wszystkich wersjach Internet Explorera
- Dodano: 4 lutego 2010
- Wprowadził: hcsl.pl
- Komentarze: 104
Microsoft potwierdził istnienie kolejnej luki w zabezpieczeniach Internet Explorera, o której szczegółach dowiedzieliśmy się we wtorek podczas konferencji Black Hat DC, i opublikował w tej sprawie poradnik zabezpieczeń.
Usterka pozwala odpowiednio spreparowanym witrynom na uzyskiwanie dostępu do systemu plików na komputerze użytkownika. Wystarczy tylko, że napastnik będzie znał konkretną ścieżkę i nazwę pliku, co w przypadku standardowych instalacji nie jest trudne do ustalenia.
Problem dotyczy Internet Explorera w wersji od 5.01 aż do 8 na wszystkich obsługiwanych platformach Windows. Przed udanym atakiem ochroni nas jednak w Internet Explorerze 7 i 8 (w systemie Windows 7, Vista i Server 2003/2008) aktywowany tryb chroniony (Protected Mode), co jest zresztą ustawieniem standardowym. Użytkownicy Windows XP Home również nie są zagrożeni, ponieważ w systemie tym nie ma możliwości dostępu do administracyjnego udziału C$, który jest niezbędny do wykonania ataku.
Przyczyną problemu jest błędne działanie ustawień strefy bezpieczeństwa w Internet Explorerze w przypadku przetwarzania informacji o ścieżce podanych w formacie UNC (ang. Uniform Naming Convention), takich jak: file://127.0.0.1/C$/…/index.dat. Powoduje to, że kod JavaScript ze strefy internetowej w pewnych okolicznościach może uzyskać dostęp do lokalnie zapisanych plików, pomimo że model stref nie pozwala na takie działania. Do obejścia zabezpieczeń wykorzystywany jest błąd w ustalaniu typów MIME lokalnych plików, a także niedoskonałości w przetwarzaniu znaczników OBJECT.
Microsoft pracuje już nad rozwiązaniem problemu, jednak jak twierdzi sam odkrywca luki Jorge Luis Alvarez Medina z Core Security Technologies, opracowanie łaty nie będzie wcale łatwe. Wynika to z faktu, że atak wykorzystuje w praktyce kilka niezależnych od siebie błędów obecnych w przeglądarce firmy Microsoft.
Do czasu opracowania aktualizacji Microsoft przygotował tymczasowe narzędzie naprawcze, dzięki któremu Internet Explorer przestaje obsługiwać adresy w postaci file://.
Materiał pochodzi z serwisu HARD CORE SECURITY LAB.
Więcej informacji: http://www.microsoft.com/technet/securit...80088.mspx
Znalazłeś literówkę? Zgłoś ją używając formularza!
Jeśli uważasz, że ten nius jest nieobiektywny, przedstawia nieprawdziwe wydarzenie, jest spamem lub nie spełnia standardów serwisu, napisz raport.
Niusy na podobny temat:
Komentarze są prywatnymi opiniami dodających je osób. Prosimy o zachowanie kultury wypowiedzi. Komentarze obraźliwe oraz obniżające poziom serwisu będą usuwane. Więcej w regulaminie komentowania.
104 komentarzy
Wszystkie autorskie niusy w serwisie publikowane są na licencji Creative Commons Uznanie autorstwa 2.5 Polska.


Jak dla mnie MS wyraźnie nie przykłada się do jakości kodu w ich przeglądarce i co najdziwniejsze ta sytuacja trwa już długi czas .
Nie lepiej było by upublicznić kod IE ?
Pewnie! Wtedy wysyp znanych bledow bylby tak ogromny, ze MS podjalby (nota bene sluszna) decyzne o porzuceniu projektu w pizdu.
Dla mnie bomba!
jeśli założymy, co nie jest prawdą, że znajdowanie nowych błędów bezpieczeństwa polega na pracy z kodem źródłowym, a nie z binarką.
Chyba lepiej byłoby porzucić wreszcie ten projekt. Czas przyznać się do totalnej porażki i zachować choć resztki honoru.
Zaraz… to microsoft… zapomniałem, że oni nie mają honoru…
Czy kazdy błąd w IE to musi być news? Firefox ma tyle samo jeśli nie więcej błędów – o co chodzi ludzie :/
U góry, lekko po prawej stronie masz do dyspozycji taki ogromny magiczny guzik opisany jako "Dodaj niusa".
Zamiast samemu napisać coś ciekawego to usiłujecie rozkazywać innym o czym mają pisać – o co chodzi ludzie :/
o to, że hoduje się fanbojstwo na tym serwisie
Fanbojstwo hoduje się na każdym serwisie, bo fanboj jest bardzo łatwy w hodowli.
@Najek: O ile dobrze pamiętam, to serwis ten w linii prostej wywodzi się z LinuxNews więc zamiast dziwić się, że nie ukrywa się tutaj błędów w IE, to zapomnij o tym serwisie i zacznij czytywać newsletter Microsoftu – wszyscy na tym zyskamy ;P
Akurat czytam co mi pozwala być w miarę obiektywnym.
nie dodaje – bo newsy o błedach w firefoxie nie są ciekawe. Tak jak w kernelu linuxa, gnome, kde i tak dalej.
Szkoda. Na prawdę chętnie poczytałbym co nieco o błędach w oprogramowaniu, którym posługuję się na co dzień. Nawet jeśli miałyby być delikatnie subiektywne
Nie, nie każdy. Ale cieszę się, gdy dowiaduję się o poważnym błedzie w takim wielkim projekcie. To samo tyczy się kazdej innej przeglądarki, wykryjesz powazny błąd w Firefoksie, to go nam przedstaw, też chętnie przeczytam.
PS Tylko uprasza się, o nie podawanie błędów w wersji "minefield", PKS.
Widzisz… Gdyby miał tyle samo (jeśli nie więcej jak zaznaczasz) błędów – to pewnie było by tyle samo (jeśli nie więcej) newsów o tych błędach
. A że nie ma – wnioski wysnuj sobie sam.
Nie wszyscy olewają bezpieczeństwo użytkownika. Jeśli pojawi się błąd w Firefoksie, to na szczęście stosunkowo szybko jest łatany – i nikt nie udaje, że go nie ma.
Firefox nie ma "tyle samo" błędów a o rząd wielkości mniej
http://osnews.pl/microsoft-zalatal-jedna-dziure-i…
"Czy kazdy błąd w IE to musi być news? Firefox ma tyle samo jeśli nie więcej błędów – o co chodzi ludzie :/"
Dlaczego niby "każdy"?
Nawet MS nie poublikuje wszystkiego nt. błędów w IE.
A takie istotne informacje jak te np. blokady adresów "file://" akurat są bardzo ważne, bo jest to funcjonalność czesto wykorzystywna.
I jak zwykle zalecam rozstanie się z erystką, gdyż w dzisiejszych czasach odwoływanie się do technik manipulacyjnych jest zwyczajnie żałosne i w sposób oczywisty widoczne praktycznie dla każdego.
Jeśli w ostatnim czasie pojawił się błąd pozwalający w alternatywnych do IE przeglądarkach nie tylko na przeglądanie Internetu, ale również na przeglądanie w kierunku Internet->system użytkownika, to założę się, że wszyscy równie chętnie o tym poczytają…
Jak twierdzi M$ IE jest (pseudo)standardem w biznesie i nie wywala się grubej kapusty na zmianę podstawy oprogramowania bez powodu. No co wy ludzie, ewangelistów z Redmond nie słuchacie, czytacie… ;P
To sie robi troche żałosne….. IE nie nadaje się do użytku, tyle poważnych luk w dość krótkim czasie które pozwalają na dostęp do plików użytkownika, rozumiem złość zwolenników IE ale FF,Opera itd. takich spektakularnych luk nie ma, a jeśli się zdarzy to łata jest nakładana w porównaniu do M$ w ekspresowym tempie, radze przestać używać IE 5/6/7/8 bo stracicie nerwy
Przecież IE używają jeszcze albo totalnie nieświadomi zwykli użytkownicy, albo idioci i fanboje microsoftu.
Więc twoje rady są jak groch o ścianę…
Nikt, do kogo może przemówić logika i fakty, nie używa już IE.
…chyba że musi, bo "takie są korporacyjne/firmowe standardy".
mby7930, dlaczego zalecasz, by szczerydobolu miał się rozstać z erystką? Może on kocha swoją erystkę, więc w imię czego stajesz na drodze ich uczuciu? Już nie wspomnę, że "zalecenia" w sprawach sercowych to możesz sobie schować do kieszeni…
Udostępnianie kodu IE , oraz jego naprawianie to troche jakchęc odrestaurowania starego auta typu garbus etc gdzie może być problem z czesciami,wiele zmarnowanych godzin by na koniec stwierdzić ze i tak nie bedzie z niego wyscigowy bolid czy bezpieczna limuzyna. Poprostu nawet zachowując sie jak totalny ,,kovalsky'' stwierdzam ze to mało rozwojowa przeglądarka (oprucz cukierkowych ikonek).
Great almanac you’ve procure
I’m impressed, I have to say. Seriously hardly ever do I encounter a blog that may be both equally educative and entertaining, and allow me to let you know, you may have hit the nail about the head. Your assumed is outstanding; the problem is a thing that not sufficient individuals are speaking intelligently about. I’m rather blissful that I stumbled throughout this in my look for a person thing referring to this
I came to this page by searching yahoo. I have found it quite interesting. thanx for providing this. I will have to visit here again!
What I couldnt give to learn how you got your design to be so amazing! I mean it. Besides the site just being fantastic, this page is too sweet! Its not too flashy. It doesnt do too much with colours and things and the videos you use are perfect for this topic! Really, fantastic blog.
I don’t normally comment on blogs.. But nice post! I just bookmarked your site
Nevertheless, it is all carried out with tongues rooted solidly in cheeks, and everybody has nothing but love for his or her friendly neighborhood scapegoat. In reality, he is not just a pushover. He is simply that extraordinary variety of person solid enough to take all of that fine natured ribbing for what it really is.
Thanks! I was a little confused on the topic. Great post.
Hey, Thanks for the info!
Hello, glad i found your site. It helped me to understand the topic a bit better.
thank you for such a fantastic site. Where else could anyone get that kind of info written in such a perfect way? I have a presentation that I am presently working on, and I have been on the watch out for such info.
Yeah i agree.
I have to say this post was certainly informative and contains useful content for enthusiastic visitors. I will definitely bookmark this website for future reference and further viewing. thank a bunch for sharing this with us!
It’s quite hard to find a good site. And I think I am lucky enough to have come here. The posts are doing great and full of good insights. I would be glad to keep on coming back here to check for updates!
Thanks for sharing the info. I located the information very useful. That’s a fantastic post you posted. I will come back to scan some more.
I enjoyed reading your pleasant blog. I see you offer priceless info. stumbled into this site by chance but I’m sure glad I clicked on that link. You definitely answered all the questions I’ve been dying to answer for some time now. Will definitely come back for more of this.
Well, I am so excited that I have located your post because I have been searching for some info on this for almost three hours! You’ve helped me a lot indeed and by scaning this article I have located many new and useful info about this subject!
I came to this page by searching yahoo. I have found it quite interesting. cheers for providing this. I will have to visit here again!
This is a great site post. thank you very much for the wonderful insight and we really appreciate the time you took to write this. cheers again.
The difference between the right word and the almost right word is more than just a fine line! it’s like the difference between a lightning bug and the lightning!
I came to this page by searching yahoo. I have located it quite interesting. thank you for providing this. I will have to visit here again!
This is my first time i visit here. I found so many interesting stuff in your site especially its discussion. From the tons of comments on your articles, I guess I am not the only one having all the enjoyment here! keep up the good work.
I came to this page by searching yahoo. I have found it quite interesting. thank you for providing this. I will have to visit here again!
Hello I am so delighted I found your website, I really found you by mistake, while I was watching on google for something else, Anyways I am here now and would just like to say cheers for a tremendous post and a all round entertaining site. Please do keep up the great work.
Thanks for the suggestions you are revealing on this website. Another thing I’d like to say is that often getting hold of some copies of your credit rating in order to check accuracy of each and every detail is the first motion you have to carry out in fixing credit. You are looking to clean up your credit reports from dangerous details problems that ruin your credit score.
Your post will be rather good, and I’m sure some will find it interesting because it’s about a topic that’s as widely discussed as others. Some may even find it useful.cheers so much for your post.
I have to say this post was certainly informative and contains useful content for enthusiastic visitors. I will definitely bookmark this blog for future reference and further viewing. thank a bunch for sharing this with us!
This is a great blog post. cheers very much for the wonderful insight and we really appreciate the time you took to write this. cheers again.
cheers for taking the time to discuss this, I feel strongly about it and love learning more on this topic. If possible, as you gain expertise, could you mind updating your blog with more information? as it is extremely helpful for me.
perfect account you occupy
A very informationrmative article and lots of really honest and forthright comments made! This certainly got me thinking about this issue, thank all.
Please keep on posting such quality articles as this is a rare thing to find these days. I am always searching online for articles that can help me. watching forward to another great blog. Good luck to the author! all the best!
cheers for such a brilliant blog. Where else could anyone get that kind of info written in such a perfect way? I have a presentation that I am presently working on, and I have been on the look out for such info.
Very pleasant site, I just came to know of it yesterday evening. Bookmarked this and also feel upon it. Thanks a lot,You had some pleasant ideas in the post, I enjoyed scaning it.
A friend of mine advised this site. And yes. it has some useful pieces of info and I enjoyed reading it. Therefore i could love to drop you a quick note to express my nice one. Take care
cheers for taking the time to discuss this, I feel strongly about it and love learning more on this topic. If possible, as you gain expertise, could you mind updating your blog with more information? as it is extremely useful for me.
This has to be one of my favorite posts! And on top of thats its also very helpful topic for newbies. nice one a lot for the info!
I like to spend my free time by scaning various internet recourses. Today I came across your site and I located it is as one of the best free resources available! Well done! Keep on this quality!
Wow! This blog looks exactly like my old one! It’s on a entirely different topic but it has pretty much the same page layout and design. Superb choice of colors!
Very cool, some valid points! I appreciate you making this article available, the rest of the blog is also well done. I hope you have a wonderful day.
While I tend to agree with the post I sincerely believe that car insurance has become too complex for the average car insurance policy holder. Just like any important purchase however you must perform due diligence and research the insurance companies before you buy.
Very effectively written information. Will probably be helpful to anyone who usess it, including myself. Sustain the great work – for certain i’ll take a look at extra posts.
I believe that avoiding packaged foods may be the first step to be able to lose weight. They will often taste good, but highly processed foods include very little vitamins and minerals, making you consume more to have enough strength to get through the day. If you are constantly eating these foods, switching to whole grain products and other complex carbohydrates will assist you to have more power while taking in less. Interesting blog post.
I am looking forward to diggin more of your quality articles.
You made some great points here. I’ve done a lot of searching on the topic and think many people will agree with your article. Thanks, Preserve Slides
Thanks for the blog loaded with numerous information.
Good blog post. Things i would like to make contributions about is that laptop memory has to be purchased should your computer still cannot cope with that which you do along with it. One can mount two RAM memory boards of 1GB each, as an example, but not one of 1GB and one having 2GB. One should always check the manufacturer’s documentation for one’s PC to be certain what type of memory is required.
As a whole, the best word to describe this movie would be unique- although the „super-human” concept has been used over and over again in the creative circuit, this story puts a new twist and spin on this idea that sparks a retrospective glance of the drug-fueled cultural revolution of the 60s- the idea that there is some kind of drug out there that unlocks your true potential.
Good blog! I really love how it is simple on my eyes and the data are well written. I am wondering how I might be notified whenever a new post has been made. I have subscribed to your RSS which must do the trick! Have a great day!
For example either the Homebrew Channel, a freeware Nintendo homebrew games application loader. This is developed to provide users a way of running software to the Wii console unofficially. Since the architecture of the Wii is dependant on the Nintendo GameCube equipment, most of the homebrew development tools used for the Nintendo GameCube will also be used for Wii growth.
Terrific transient and that blog post reduced the problem a lot. Give you thanks My husband and i attempting to find a person’s information….
The site rocks !. Since i consistently encountered something totally new & assorted the following. We appreciate your which often personal data.
The main one being that it feels like there is entirely too much going on in the film.
Thanks bro
Hey – good blog, simply looking around some blogs, seems a reasonably nice platform You Are using. I’m at the moment using Drupal for a couple of of my websites but looking to change considered one of them over to a platform very much the identical to yours as a trial run. Anything particularly you’ll advocate about it?
I generally don’t leave blog comments but your writing forced me to, amazing work.
Cool
Amazing brief and that piece of content taught me to be a large amount. Express gratitude As i trying to find ones information….
Exceptional small and this also piece solved the problem a great deal. Express gratitude My husband and i struggling to find your entire information….
Great blog! Is your theme custom made or did you download it from somewhere? A theme like yours with a few simple adjustements would really make my blog shine. Please let me know where you got your design. Kudoscoach outlet
Howdy! I just wish to give an enormous thumbs up for the nice data you’ve here on this post. I will likely be coming back to your blog for extra soon.
Good to know
Effective
Pretty good post. I just stumbled upon your blog and also wanted to say that I have really loved reading your blog posts.
You have some helpful ideas! Maybe I should consider doing this by myself.
Great post, I think website owners should learn a lot from this weblog its rattling user genial.
That is since I use a lot of to not be left behind.
Thanks bro
hey all, I used to be just checkin’ out this weblog and I actually admire the premise of the article, and don’t have anything to do, so if anybody want to to have an engrossing convo about it, please contact me on AIM, my identify is heather smith
What an enjoyable (and may I say insightful) read! You may not know it, but this post of yours gave me so many realizations. I wonder if it occurs to you and other people, too, but there are times when I get wonderful ideas from things that don’t have anything to do at all with what’s in my mind. On a different note, I read a lot of blogs, it’s what I do before I head off to the gym, and I can’t believe some of the trash that some people are putting out, like a magic bullet for this, and a so-called-secret for that. Like in the topic of body-building, I’ve read quite a number of blogs that talk about products that make building muscles almost instantaneous! Imagine, bodybuilding without breaking a sweat?! Come on! At the very least you need to have a workout program which you will actually follow! Now I’m ranting, sorry. I’ll look around your blog some more before heading to another one.
What’s the purpose of this particular post should you don’t mind myself asking?
You have some helpful ideas! Maybe I should consider doing this by myself.
I know this isn’t exactly on topic, but i have a website online using the same program as properly and i get troubles with my comments displaying. is there a setting i am lacking? it’s attainable you could assist me out? thanx.
Pretty! This was a really wonderful post. Thank you for your provided information.
The next time I read a blog, I hope that it doesnt disappoint me as much as this one. I mean, I know it was my choice to read, but I actually thought youd have something interesting to say. All I hear is a bunch of whining about something that you could fix if you werent too busy looking for attention.
The best known and most sought after collections of gold coins on the globe are the classic collection of United kingdom gold coins – Gold Sovereigns
I must show some appreciation to the writer just for bailing me out of such a incident. After browsing throughout the search engines and seeing solutions which are not beneficial, I figured my entire life was well over. Living without the approaches to the issues you have fixed by way of your entire short article is a crucial case, as well as ones that would have in a wrong way damaged my career if I had not noticed your blog. Your primary training and kindness in playing with a lot of things was helpful. I don’t know what I would’ve done if I had not come across such a thing like this. It’s possible to at this moment look ahead to my future. Thanks very much for your reliable and result oriented help. I won’t hesitate to refer your web sites to any individual who should receive assistance about this topic.
great tips! thanks!
I know this isn’t exactly on subject, but i have a website using the same program as nicely and i am getting troubles with my comments displaying. is there a setting i am lacking? it’s attainable you may assist me out? thanx.
SiteBuilder is ideally suited for new users unfamiliar with producing websites. The 5 step wizard packs the supremacy of home layout in a simple graphical person interface.Online success begins with a good domain name. At Domain.com, we generate it simple and economical to get the domain name you want, quick. We provide all significant Top Degree Domains (TLDs) and over 25 Region Code Top Level Domains (ccTLDs). Just about every domain name registration includes the after domain equipment:A domain name, or Web deal with, is an handle the place you can be found online. It’s how you’ll convey yourself through electronic mail or your web page and it’s which prospects feel of once making an attempt to find you.Once you register a domain name, the Internet Corporation for Assigned Names and Numbers (ICANN) demands your domain name name registrar to submit your personal reach facts to the WHOIS database. When your listing seems in that online directory, it is publicly obtainable to anyone who chooses to check domain namess employing the WHOIS look tool.Domains contains search for new domain name hosting, domain names registration, domain registrar switch, domain locking, private domain registration, …Buy a domain name hosting and website hosting for much less than GoDaddy, Connect Solutions, Register.com or OrderYourName.com. Your source for all things domain names related.Domain name registration for personal or company use, switch or sign-up your domain name for low cost domain namess registrations.Buy premium domain name, register a domain name name or uncover available web domains for sale at OrderYourName, your supply for top quality domains and hosting.Sign-up a domain name and transfer domains. Dependable web hosting and VPS. Powerful internet site, weblog, and ecommerce tools. 10 many years, thousands and thousands of prospects.It forum discusses basic domain issues, like: domains as a brand, domain values, negotiating domain sales, domain inventory management.A domain name is an identification tag that defines a realm of administrative autonomy, power, or management in the Internet. Domain names are also critica for web hostingDomain registrations – web domain registration for your web site is quick and easy to at Register.com. Check accessibility with our search domains tool.Buy a domain name and site hosting for less than GoDaddy, Network Remedies, OrderYourname.com or Register.com. Your source for all things domain name related.A big wide variety of domain name extensions (generic & country-code TLDs). Full DNS/Whois management, ID protection, EPP transfer key, lck/unlock status, etc.Discover how to control your domain reach data and registration. Realize domainlocking and Personal domain name Registration.Register a domain, search for available domains, renew and transfer domains, and choose from a wide variety of domain extensions.Sign-up a domain name search for available domains, renew and transfer domains, and choose from a broad variety of domain extensions.Domains provides web hosting, transfer domains, domain lookup, domnain names, and allows you to buy domain names.OrderYourname.com domain name offers web hosting, switch domains, domain lookup, domnain namess, and enables you to buy domains.Get free domain name registration with a revealed World-wide-web site internet hosting prepare with OrderYourName.com domain names registration services.
This one is an inspiration personally to uncover out rather more related to this subject. I need to confess your knowledge extended my sentiments in addition to I am going to right now take your feed to stay up to date on every coming blog posts you may probably create. You might be worthy of thanks for a job completely accomplished!
This is really the rather helpful see for my situation, Have got to mention will probably be One out of the very best writers My partner and i by chance watched.Thanks for writing this instructive short article.