New vuln affects ALL browsers
09-12-2004, 14:01
|
#16
|
Trollsplatter
Join Date: Jun 2003
Location: North of Watford
Services: Humane elimination of all common Internet pests
Posts: 38,083
|
Re: New vuln affects ALL browsers
Does it perhaps depend on you having the Secunia site open in a different window/tab while you click the graphic on the bank site?
|
|
|
09-12-2004, 14:08
|
#17
|
Guest
|
Re: New vuln affects ALL browsers
OK I did it again, and it came up with the pop-up. These computers at college have the flaw
|
|
|
09-12-2004, 14:28
|
#18
|
Inactive
Join Date: Apr 2004
Location: Minas Tirith, Gondor
Age: 60
Posts: 3,458
|
Re: New vuln affects ALL browsers
IE6 on XPSP1 (patched until this months IE patch) with Google popup-blocker is vulnerable.
FF (with Tabbrowser Extensions and standard popup-blocker) is safe. Even tried opening Secunia site and Citibank in separate windows rather than tabs.
Will check the standard SP2 version of IE6 this evening.
Bottom line is - you need to visit a 'malicious' website and then a legit website (via link from malicious site?), that the malicious site knows about, using the same browser and legit website then has to open a pop-up window.
|
|
|
09-12-2004, 14:47
|
#19
|
Inactive
Join Date: Jun 2003
Location: Los Angeles, CA
Age: 46
Posts: 6,343
|
Re: New vuln affects ALL browsers
If you are using a Mozilla variant, you can make sure the page is really coming from where it says it is by doing this:
1) Type "about:config" into the location bar.
2) Look for "dom.disable_window_open_feature.location".
3) Set to "true".
|
|
|
09-12-2004, 14:49
|
#20
|
Trollsplatter
Join Date: Jun 2003
Location: North of Watford
Services: Humane elimination of all common Internet pests
Posts: 38,083
|
Re: New vuln affects ALL browsers
Quote:
Originally Posted by Richard M
If you are using a Mozilla variant, you can make sure the page is really coming from where it says it is by doing this:
1) Type "about:config" into the location bar.
2) Look for "dom.disable_window_open_feature.location".
3) Set to "true".
|
would that count as a 'patch' or does it restrict the functionality of the browser?
|
|
|
09-12-2004, 14:52
|
#21
|
Inactive
Join Date: Jun 2003
Location: Los Angeles, CA
Age: 46
Posts: 6,343
|
Re: New vuln affects ALL browsers
It does this, it's a kinda workaround thing:
|
|
|
09-12-2004, 16:36
|
#22
|
Oh Lanky Lanky.
Join Date: Jun 2003
Location: Shaw, Oldham, Lancashire.
Services: 2 TV 360 boxes. 500mb BB, Phone line.
Posts: 8,040
|
Re: New vuln affects ALL browsers
All clear,XP.. IE 6 SP2. tried it 5 or 6 times, no problems.
|
|
|
09-12-2004, 17:00
|
#23
|
[NTHW] pc clan
Join Date: Jun 2003
Location: Tonbridge
Age: 57
Services: Amazon Prime Video & Netflix. Deregistered from my TV licence.
Posts: 21,960
|
Re: New vuln affects ALL browsers
adshield protects me from this......
|
|
|
09-12-2004, 17:20
|
#24
|
Permanently Banned
Join Date: Jun 2003
Location: norton , teesside
Age: 57
Posts: 10,571
|
Re: New vuln affects ALL browsers
seems fine here
|
|
|
09-12-2004, 18:43
|
#25
|
Inactive
Join Date: Jun 2003
Services: Virgin Media
Posts: 9,163
|
Re: New vuln affects ALL browsers
Using FF with the pop-up blocker turned on it didn't work, but I turned it off and worked
EDIT: Just tried it with IE6. Google toolbar didn't stop it, but when I turned the pop-up stopper in IE6, it stopped the secunia thing, but it let the correct pop-up appear.
|
|
|
09-12-2004, 19:54
|
#26
|
The Invisible Woman
Cable Forum Team
Join Date: Jun 2003
Location: between Portsmouth and Southampton.
Age: 72
Services: VM XL TV,50 MB VM BB,VM landline, Tivo
Posts: 40,339
|
Re: New vuln affects ALL browsers
How odd!! I did the second link with PoUpCop disabled and got the correct citibank site pop up.Then I refreshed the secunia site and got the other popup.
Anyway I keep my popup blocker going all the time so I'm not really worried.
__________________
Hell is empty and all the devils are here. Shakespeare..
|
|
|
09-12-2004, 21:20
|
#27
|
Guest
Location: Sale, Cheshire
Services: 10MB Broadband, DTV, Telephone
Posts: n/a
|
Re: New vuln affects ALL browsers
Affects me (IE 6 SP2 version). Reading the 'blurb', as Chris T says above, it does depend on the Secunia site still being open in a separate window.
|
|
|
09-12-2004, 21:22
|
#28
|
Guest
Location: Sale, Cheshire
Services: 10MB Broadband, DTV, Telephone
Posts: n/a
|
Re: New vuln affects ALL browsers
...and in response to Incog., the SP2 version of IE 6 includes a pop-up bloker, which didn't help in this instance.
|
|
|
09-12-2004, 21:42
|
#29
|
Inactive
Join Date: Apr 2004
Location: Minas Tirith, Gondor
Age: 60
Posts: 3,458
|
Re: New vuln affects ALL browsers
Hmm..
With IE6 SP2 (built-in pop-up blocker) I am vuln. The Secunia info appears as a popup from citibank. But going back to the Secunia window, IE tells me it's blocked a pop-up from the Secunia site!!
Just as well I've hidden IE on home system - wife and kids can use the safe (from this) FF
|
|
|
09-12-2004, 22:09
|
#30
|
Guest
|
Re: New vuln affects ALL browsers
Windows 2000 IE6 SP4 is vulnerable.
|
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +1. The time now is 16:37.
|