Vulnerability Development mailing list archives

Re: Unscrupulous websites installing apps


From: MortalCry () aol com
Date: Thu, 13 Sep 2001 17:22:55 EDT

I have seen this a couple of times when using internet explorer 5.5.  Ill 
goto a site, and there will nothing there, then like 5 minutes later zone 
alarm will tell me about some strange program trying to connect to the 
internet.  Ill check to see if i can find out where the application came 
from, using properties -> Versions tab.  Sometimes it shows the same address 
that i had just been to.  Didn't really think about it as being a vuln. 
untill now.  Someone could use the 'bug' to download a trojan on every 
internet exporer based computer that connects to their site.  The user 
wouldnt even know what was going on.  Maby its the default security setting?  
Lack of security setting?


Current thread: