Account Options

  1. Sign in
The old Google Groups will be going away soon, but your browser is incompatible with the new version.
Google Groups Home
« Groups Home
Outlook Express exploit
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  3 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Eric  
View profile  
 More options Oct 8 2000, 3:00 am
Newsgroups: comp.unix.shell
From: Eric <liber...@twcny.rr.com>
Date: 2000/10/08
Subject: Outlook Express exploit

Dear Bill Gates: Do you actually believe that we think this was
accidental? HANG, you
communist ba$tard!!! (For those of you who think Bill Gates is "the good
guy,"
I suggest you learn the NetBIOS exploit on Windows 95/98. Accidental MY
ASS!!!!

  ASSESSMENT 00-049

  Microsoft E-mail and Script Vulnerabilities
  Issued at 8:00 p.m. EDT, 07/19/2000

  Microsoft Corp. has released an advisory on a component shared by
Outlook and Outlook Express
  which contains an unchecked buffer in email headers. In addition, the
System Administration,
  Networking & Security Institute (SANS) has issued an advisory on HTML
and IE Script
  Vulnerabilities. The SANS advisory covers two separate issues
concerning vulnerabilities in
  Active X controls.

                           Malformed E-mail Header Vulnerability
                          See Microsoft Security Advisory MS00-043
         http://www.microsoft.com/technet/security/bulletin/MS00-043
Posted July 18, 2000

  This vulnerability could allow unwanted code (e.g. a virus or trojan
horse) to become executed
  on your computer without opening any email attachments. A component
shared by Outlook and
  Outlook Express contains an unchecked buffer in the functionality that
parses e-mail headers
  when downloading mail via either pop3 or IMAP4. By sending an e-mail
that overruns the buffer, a
  malicious user could cause either of two effects to occur when the
mail was downloaded from the
  server by an affects e-mail client: If the affected field were filled
with random data, the
  e-mail could be made to crash, or if the affected field were filled
with carefully-crafted data,
  the e-mail client could be made to run code of the malicious user's
choice.

                 Internet Explorer Script & Office HTML Script
Vulnerabilities
                       See SANS Flash Advisory: Dangerous Windows Flaw
            http://www.sans.org/newlook/resources/win_flaw.html Posted
July 17, 2000

  Internet Explorer (IE) Script

  This vulnerability could allow ActiveX controls to be loaded on your
computer even if you have
  disabled Active Scripting. Internet Explorer allows the use of an
object tag to load an ActiveX
  control. The data property of the object tag is the ActiveX control to
be loaded. An ActiveX
  control is normally an executable, however, Microsoft Office documents
are also ActiveX
  controls. In a default installation, ActiveX controls load silently,
without prompting the user,
  thus automatically executing the exploit. Internet Explorer can be
configured to prompt the user
  to load ActiveX controls. The problem occurs in the sequence of
execution, whereby the IE
  actually opens the Access database before it asks the user to open it.

  Office HTML Script

  Excel 2000 and PowerPoint 97 and 2000 can be scripted from inside
Internet Explorer to save a
  file to an arbitrary location on the user's hard drive as long as the
user has access to that
  location. This would enable an attacker to save files to locations
such as the Startup folder.
  This vulnerability is not exploitable if Active Scripting and/or
Running ActiveX controls is
  disabled. Therefore, it is considerably less dangerous than the Access
problem. The root cause
  of this problem is that Excel and PowerPoint are marked as safe for
scripting. The patch by
  Microsoft Corp. eliminates this by marking them unsafe for scripting.
Microsoft Corp. has made
  this fix available at http://officeupdate.microsoft.com.

  As always, users are advised to maintain awareness of new
vulnerabilities that are reported by
  security entities from CERT/CC, SANS Institute, Microsoft Corp. and
other cognizant
  organizations.

  Please report any illegal or malicious activities to your local FBI
office or the NIPC, and to
  your military or civilian computer incident response group, as
appropriate.


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Andreas Kähäri  
View profile  
 More options Oct 9 2000, 3:00 am
Newsgroups: comp.unix.shell
From: Andreas Kähäri <andk...@emailme.net.REMOVE>
Date: 2000/10/09
Subject: Re: Outlook Express exploit
In article <39E0868C.1368D...@twcny.rr.com>,

Eric  <liber...@twcny.rr.com> wrote:

>Dear Bill Gates: Do you actually believe that we think this was
>accidental? HANG, you
>communist ba$tard!!!

I would be very thankful if you could explain why exactly Mr. Bill
Gates deserves to be called a communist, and since I'm quite
interested in the foundations of economical ideas (such as capitalism
and marxism), I am also interested in hearing your definition of a
"communist bastard" and how it relates to corporate management in
Northen America today. (Do this by e-mail since it is completely off
topic in most news groups.)

Also, please note that this forum is a Unix forum and although
Internet Explorer *has* been ported to the Solaris platform I feel
that your sudden explosion here was a little bit uncalled for.

If you require further assistance with IE, please refer to the
appropriate Microsoft forum.

/A

--
Andreas Kähäri,
Uppsala University, Sweden.
=============================={ "free", as in "software" --> www.gnu.org


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Andreas Kähäri  
View profile  
 More options Oct 9 2000, 3:00 am
Newsgroups: comp.unix.shell
From: Andreas Kähäri <andk...@emailme.net.REMOVE>
Date: 2000/10/09
Subject: Re: Outlook Express exploit
In article <39e1b...@merganser.its.uu.se>,
Andreas Kähäri  <andk...@emailme.net.REMOVE> wrote:

Sorry, my fault. The OP wrote about Outlook, not about IE.
It's off topic anyway, so it doesn't really matter I guess.

/A

--
Andreas Kähäri,
Uppsala University, Sweden.
=============================={ "free", as in "software" --> www.gnu.org


 
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »