Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

Don't Press F1 - Internet Explorer Exploit Discovered

  • 03-03-2010 7:57pm
    #1
    Registered Users, Registered Users 2 Posts: 86,729 ✭✭✭✭


    http://consumerist.com/2010/03/dont-press-the-f1-key.html

    Until Microsoft issues a hotfix, do not use your F1 Key.

    Windows: pressing the F1 key might make your computer go boom. A security exploit deployed by certain malicious websites hides in the Windows help files and could get launched if you press the F1 button. It will only happen, if the following is true:
    1. You're using Windows 2000, XP, or 2003
    2. You're visiting a website using Internet Explorer
    3. Website opens HTML help
    4. Website runs a vbscript in said HTML help window that causes a message box prompt
    5. You press F1 rather than clicking a button (like OK, cancel, etc) or closing the dialog

    Microsoft wrote:
    Microsoft is investigating new public reports of a vulnerability in VBScript that is exposed on supported versions of Microsoft Windows 2000, Windows XP, and Windows Server 2003 through the use of Internet Explorer. Our investigation has shown that the vulnerability cannot be exploited on Windows 7, Windows Server 2008 R2, Windows Vista, or Windows Server 2008. The main impact of the vulnerability is remote code execution. We are not aware of attacks that try to use the reported vulnerabilities or of customer impact at this time.
    The vulnerability exists in the way that VBScript interacts with Windows Help files when using Internet Explorer. If a malicious Web site displayed a specially crafted dialog box and a user pressed the F1 key, arbitrary code could be executed in the security context of the currently logged-on user. On systems running Windows Server 2003, Internet Explorer Enhanced Security Configuration is enabled by default, which helps to mitigate against this issue.
    We are actively working with partners in our Microsoft Active Protections Program (MAPP) to provide information that they can use to provide broader protections to customers.
    Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.
    Microsoft is concerned that this new report of a vulnerability was not responsibly disclosed, potentially putting computer users at risk. We continue to encourage responsible disclosure of vulnerabilities. We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests. This practice helps to ensure that customers receive comprehensive, high-quality updates for security vulnerabilities without exposure to malicious attackers while the update is being developed.


Comments

  • Moderators, Education Moderators, Motoring & Transport Moderators Posts: 7,396 Mod ✭✭✭✭**Timbuk2**


    I just pressed F1.

    How hardcore am I!?

    Wait until my mother hears!


  • Closed Accounts Posts: 2,347 ✭✭✭Closed ac


    Oo, what does this button do?


  • Registered Users, Registered Users 2 Posts: 8,659 ✭✭✭CrazyRabbit


    I pressed F1 in work earlier this morning. I'm still waiting for someone to come to my PC to help me.


  • Moderators, Regional East Moderators Posts: 23,239 Mod ✭✭✭✭GLaDOS


    Well in fairness you deserve it if you're using internet explorer

    Cake, and grief counseling, will be available at the conclusion of the test



  • Closed Accounts Posts: 7,645 ✭✭✭Daemos


    Don't press F1 you say?

    *presses F1*


  • Advertisement
  • Closed Accounts Posts: 36,634 ✭✭✭✭Ruu_Old


    <insert snotty comment from Linux user towards Windows user>


  • Closed Accounts Posts: 8,399 ✭✭✭Bonito




  • Registered Users, Registered Users 2 Posts: 17,190 ✭✭✭✭IvySlayer


    Ahhhh Windows 7. Got to love it. :D

    I can press F1 all dayyyy.


  • Registered Users, Registered Users 2 Posts: 442 ✭✭smiley girl


    When I read 'I don't press F1' I got an overpowering urge to press it! So I did! I've Windows Vista though!


  • Posts: 3,518 ✭✭✭ [Deleted User]


    "King to E5"
    "Me to F1 = You ****ed"


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 154 ✭✭AllYourBass


    So THAT'S where I put my the self destruct button.


  • Registered Users, Registered Users 2 Posts: 2,221 ✭✭✭BluesBerry


    Pfft *sniggers at windows users* Macs for the win :pac::pac::pac::pac:


  • Moderators, Education Moderators, Motoring & Transport Moderators Posts: 7,396 Mod ✭✭✭✭**Timbuk2**


    Well at least it's not a useful key, like Scroll Lock.


  • Closed Accounts Posts: 22,559 ✭✭✭✭AnonoBoy


    I don't watch race driving of any sort so I'm pretty sure I'm safe.


  • Closed Accounts Posts: 11,220 ✭✭✭✭m5ex9oqjawdg2i


    Overheal wrote: »
    2. You're visiting a website using Internet Explorer

    This is where most people go wrong. ;)


  • Registered Users, Registered Users 2 Posts: 81,219 ✭✭✭✭biko


    "Internet EXPLODER" :D
    Changed title Overheal from "Windows Exploit Discovered" to "Internet Explorer Exploit Discovered", to clarify it only is a risk under certain conditions.


Advertisement