TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

New Metasploit 0-day exploit for IE 7, 8 & 9 on Windows XP, Vista, and 7

138 点作者 turnersr超过 12 年前

9 条评论

dguido超过 12 年前
This title is a bit misleading. This exploit will not be able to fully exploit anyone running on Vista or Windows 7, since Internet Explorer renderers run in low integrity processes on those operating systems (essentially, they are sandboxed). No one has released a second exploit that would escalate privileges outside of this sandbox.<p>If you are running IE on Windows XP and you've taken no other steps to protect yourself (like running EMET, SandboxIE, or another mitigation), then it's your own damn fault that you got owned. On the other hand, take a look at how many exploits for IE that Rapid7/Metasploit has that support Windows 7: 0.
评论 #4538757 未加载
givan超过 12 年前
Computers can get compromised <i>simply by visiting a malicious website</i> Since <i>Microsoft has not released a patch for this vulnerability yet</i>, Internet users are strongly advised to switch to other browsers.<p>The long release cycle of internet explorer is a very big problem for ie users, unfortunately most of them don't even now what a browser is.
评论 #4533665 未加载
评论 #4534394 未加载
评论 #4534766 未加载
dj_axl超过 12 年前
More explanation here: <a href="http://www.ehackingnews.com/2012/09/new-zero-day-ie-exploit-metasploit-module.html" rel="nofollow">http://www.ehackingnews.com/2012/09/new-zero-day-ie-exploit-...</a>
recursive超过 12 年前
Could someone who understands them explain the screenshots to me like I was 5? I'm familiar with ruby, internet explorer, and virtual machines, but I can not make any sense of these images.
评论 #4534067 未加载
dkroy超过 12 年前
Resistance is futile. It is time to assimilate, download chrome.
jneal超过 12 年前
Can't say I'm ever surprised when exploits like this pop up, but it's definitely valuable to know. I don't use IE nor manage users on IE so I know I'm fine, but those of you out there using it or managing users that use it should probably take this as an opportunity to re-educate users on security best practices including email attachments and visiting unfamiliar websites.<p>Also important to note that some websites you may be familiar with could become compromised and attack-code added within iFrames is very common, so it's best to just not use IE at all until a patch is released.
Zenst超过 12 年前
www.google.com/chrome dont leave 127.0.0.1 without it.<p>I find packaging up 0-day's into point-click downloads for metaspliot and the likes akin to giving a small child a loaded gun, but thats me I guess. Will only encourage the digital-vandals (media calls them hackers, bless).
评论 #4535180 未加载
RutZap超过 12 年前
I sure hope this exploit gets a lot of attention, in this way most people will understand the importance of upgrading their browser and thus... we, web developers, will not have to support crappy browsers (IE7 I'm looking at you!) :D
propercoil超过 12 年前
wow this is so big it makes my head spin.. most def the new ms08-067
评论 #4534771 未加载