BulletProof Nerds Gaming Community
May 24, 2012, 04:46:03 AM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: TO POST ON THE FORUMS YOU MUST REGISTER ON THE BPN HOMEPAGE, ONCE YOU ARE LOGGED IN THERE, IT AUTOMATICALLY LOGS YOU INTO THE FORUMS AS WELL.  IF YOU STILL CAN'T POST THEN LOG OUT OF THE WEBSITE AND LOG BACK IN, THEN COME BACK TO THE FORUMS.
 
   Home   Help BPN HOMEPAGE Search Login Register  
Pages: 1   Go Down
  Print  
Author Topic: Beware Windows XP's F1 Help Bug  (Read 621 times)
0 Members and 1 Guest are viewing this topic.
Schlup
Master Admin
1000 POSTS CLUB!!!
*
*

BPN Props: 1226
Offline Offline

Posts: 6664



WWW Awards
« on: March 01, 2010, 08:03:33 PM »

SEC Security Research has disclosed and Microsoft has confirmed a vulnerability in Internet Explorer versions 6, 7 and 8 that could allow remote code execution. Only Windows XP is vulnerable.

According the the advisory from iSEC, the attacker needs to elicit some cooperation from the user: The attack pops up a Windows messagebox (a simple dialog box with a button) loaded with VBScript. If the user presses F1, IE will load an attacker-supplied .HLP file with winhlp32.exe. iSEC also notes a stack overflow vulnerability in winhlp32 that they could use.

Microsoft's description of the issue basically supports all the claims by iSEC and adds some more facts.

This is only an issue on XP because afterwards Microsoft recognized that .HLP files are an endless fount of vulnerabilities. HLP files are now among what Microsoft calls "unsafe file types." Windows Server 2003 could be affected, but not in the default Enhanced Security Configuration for web browsing.

So far the vulnerability seems impressive as far as it goes, but there's actually less here than it seems. As iSEC notes themselves, winhlp32 on XP is compiled with the /GS switch, which should stop conventional stack overflows. Perhaps there are other types of vulnerabilities in winhlp32 which could be employed in this case, but the bottom line is that this isn't the most serious IE problem out there.

Full Story:  http://www.pcmag.com/article2/0,2817,2360810,00.asp

CoCoCountyKiller
Guest
« Reply #1 on: March 02, 2010, 10:14:39 AM »

looks like it is time to upgrade to a better OS

co.co.
Schlup
Master Admin
1000 POSTS CLUB!!!
*
*

BPN Props: 1226
Offline Offline

Posts: 6664



WWW Awards
« Reply #2 on: March 02, 2010, 01:13:11 PM »

Yeah, I think this is a ploy to get people to start upgrading.  It really is time...if you still have XP, you have what is considered a very old PC now...or OS for that matter.  It (XP) also stops getting supported completely in a few months.

CoCoCountyKiller
Guest
« Reply #3 on: March 03, 2010, 10:19:06 AM »

"old"

ouch

co.co.
JamesBong
Newbie Poster
*

BPN Props: 0
Offline Offline

Posts: 34



Awards
« Reply #4 on: March 25, 2010, 10:08:13 PM »

Time for me to do last re-formatting Sad.I have XP Pro and at least once a year I do backup and do a fresh install takes me days Sad .

Play Hard or Go Home.
Schlup
Master Admin
1000 POSTS CLUB!!!
*
*

BPN Props: 1226
Offline Offline

Posts: 6664



WWW Awards
« Reply #5 on: March 26, 2010, 02:01:34 AM »

Don't forget to export your TS3 identity and save it...

Pages: 1   Go Up
  Print  
 
Jump to:  


Powered by SMF 1.1.16 | SMF © 2011, Simple Machines Page created in 0.29 seconds with 22 queries.