-
Istanbul Expert
MS: Hold Everything! Don't Press F1 if you use WinXP
Not really a computer question, but something that seems pretty important 3/3/10:
Microsoft told Windows XP users today not to press the F1 key when prompted by a Web site, as part of its reaction to an unpatched vulnerability that hackers could exploit to hijack PCs running Internet Explorer (IE).
In a security advisory issued late Monday, Microsoft confirmed the unpatched bug in VBScript that Polish researcher Maurycy Prodeus had revealed Friday, offered more information on the flaw and provided some advice on how to protect PCs until a patch shipped.
"The vulnerability exists in the way that VBScript interacts with Windows Help files when using Internet Explorer," read the advisory. "If a malicious Web site displayed a specially crafted dialog box and a user pressed the F1 key, arbitrary code could be executed in the security context of the currently logged-on user."
Last week, Prodeus called the bug a "logic flaw," and said attackers could exploit it by feeding users malicious code disguised as a Windows help file -- such files have a ".hlp" extension -- then convincing them to press the F1 key when a pop-up appeared. He rated the vulnerability as "medium" because of the required user interaction.
More Here
“The basic tool for the manipulation of reality is the manipulation of words. If you can control the meaning of words, you can control the people who must use the words."
--Philip K. Dick
-
Anti-Winlink Warlord
Re: MS: Hold Everything! Don't Press F1 if you use WinXP
F1 help? Real men never ask for direction when cruising the web.
Or anywhere else, for that matter.
Real men move along...nothing to see here. :rofl: :rofl:
"Bacon, Beans and Limousines"
"Actually, it's a Democratic Republic; Democratic comes first".
Please don't confuse my personality with my attitude. My personality is obviously me, But my attitude depends largely upon you.
-
"Island Bartender"
Re: MS: Hold Everything! Don't Press F1 if you use WinXP
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules