Newsgroups: comp.infosystems.www.authoring.html
Date: Fri, 25 Jan 2008 16:17:15 -0800 (PST)
Local: Fri, Jan 25 2008 7:17 pm
Subject: Re: </noscript> Issue
On Jan 25, 6:13 pm, Ed Jay <ed...@aes-intl.com> wrote:
> aoksi...@gmail.com scribed: Ed Jay, > >On Jan 25, 4:22 pm, Ed Jay <ed...@aes-intl.com> wrote: > >> >Ed Jay wrote: > >> >> aoksi...@gmail.com scribed: > >> >>> Ed Jay <ed...@aes-intl.com> wrote: > >> >>> For the people who accept new info here is one link to a direct > >> >> New info? LMAO! The thread is about an infected WEB SITE, not a User's > >> >I just read the stopbadware thread listed above, and it sure looks to me > >> That's not quite how I read it. I'd have said that errant js on hacked web > >Please read this > >http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=JS%5F... > >and this > >http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=JS%5F... > >It more clearly states the issue. > Thanks, but I'm not sure I understand. The citation says, and I paraphrase > >This malicious JavaScript is hosted on a Web site and runs when a user accesses the said Web site. > Yup > >This malicious JavaScript accesses the following URL to download files: > Yup > >It takes advantage of the following software vulnerabilities: > ActiveX exploits... I understand the security issues with ActiveX > >Upon successful exploit, the system is redirected to the following Web site to download a malicious file > OK > >It saves the downloaded files.. > OK > >It then executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system. > To my knowledge, the only way that js can execute a local file is either > I conclude that js isn't the problem, but poor browser design and those > >One significant reason for disabling JavaScript when browsing the > is true only if the user's system is already compromised. The past few posts and any future posts are not intended for you. Best Wishes, Daniel You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
| ||||||||||||||