Keyword: yetanothermblunder

Brevity: Headers | « Text »
  • Trojan exploits unpatched IE flaw

    12/01/2005 7:41:41 AM PST · by ShadowAce · 28 replies · 901+ views
    The Register ^ | 1 December 2005 | John Leyden
    The release of a Trojan that exploits an unpatched IE hole has prompted speculation that Microsoft may release an emergency out-of-cycle security patch. The Delf-DH Trojan downloader uses an Internet Explorer vulnerability to infect unprotected Windows users who stray onto maliciously constructed websites. Delf-DH downloads other malware onto infected machines changing settings in order to monitor user activity and redirect surfers onto porn sites. The attack relies on a flaw in the way IE handles requests to the window() object, highlighted by proof-of-concept code last week and now used in anger by VXers. Even fully patched Windows 2000 and Windows...