<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Firefox 2 is vulnerable to ANI flaw in Security</title>
<link>http://www.dslreports.com/forum/r18108717</link>
<description></description>
<language>en</language>
<pubDate>Sat, 05 Dec 2009 00:59:06 EDT</pubDate>
<lastBuildDate>Sat, 05 Dec 2009 00:59:06 EDT</lastBuildDate>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18115475</link>
<description><![CDATA[<A HREF="/useremail/u/879997"><b>dadkins</b></A> : #1 SMALL picture even when clicked on... cannot read text.<br><br>#2 No problems here in IE 7 after patch. <br><SMALL>--<br>Think outside the Fox... <A HREF="http://www.opera.com/">Opera</A></SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18115475?c=1147685&ret=L2ZvcnVtL3IxODEwODcxNy54bWw%3D"><IMG class="apic" BORDER=0 TITLE="228973 bytes" WIDTH=600 HEIGHT=375 SRC="/r0/download/1147685.thumb600~801f02996350b1510755fca5b8dc9b3a/ANI.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18115475</guid>
<pubDate>Wed, 04 Apr 2007 12:12:58 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18114954</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : <div class="bquote"><SMALL>said by  DownTheShore <A HREF="/useremail/u/906825"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><div class="bquote"><SMALL>said by  jcbsinger <A HREF="/useremail/u/1450688"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Could anyone here please explain me that what is ANI flaw, I am kinda new to this area :(<br> </DIV>It's a vulnerability in the portion of the computer code that allows you to run animated cursors, if I'm understanding it correctly.  Nefarious people can use certain browsers/websites to access that coding on your machine and divert it to their own purposes.<br><br>You may or may not be vulnerable to it, and your anti-virus program may stop it automatically, but just to be sure, Windows Update has a patch for the problem.<br> </DIV>&raquo;<A HREF="/forum/remark,18114422">Mozilla Firefox Insecure Element Stealth Injection Vulnerabi</A><br><SMALL>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> Missing Kids &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18114954</guid>
<pubDate>Wed, 04 Apr 2007 10:29:35 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18114913</link>
<description><![CDATA[<A HREF="/useremail/u/906825"><b>DownTheShore</b></A> : <div class="bquote"><SMALL>said by  jcbsinger <A HREF="/useremail/u/1450688"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Could anyone here please explain me that what is ANI flaw, I am kinda new to this area :(<br> </DIV>It's a vulnerability in the portion of the computer code that allows you to run animated cursors, if I'm understanding it correctly.  Nefarious people can use certain browsers/websites to access that coding on your machine and divert it to their own purposes.<br><br>You may or may not be vulnerable to it, and your anti-virus program may stop it automatically, but just to be sure, Windows Update has a patch for the problem.<br><SMALL>--<br><I>Life is simply one damned thing after another.</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18114913</guid>
<pubDate>Wed, 04 Apr 2007 10:18:07 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18114462</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : <div class="bquote"><SMALL>said by  Mele20 <A HREF="/useremail/u/403861"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><div class="bquote"><SMALL>said by  Name Game <A HREF="/useremail/u/655093"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>And what you just described is the biggest problem with Firefox..in the IE world at least people know the differences in IE5, IE5.5, IE6, and IE7..but when it come to Firefox and people say they have a problem with it..you have no idea what version or plug in or other opensource gimmick they have with it..the whole project has little or no quality control..each version has it own particular problems and I constantly see gurus who write code for it tell users it is not our fault contact the webmaster of the site..or some other vendor.<br> </DIV>That's because you don't use it. I know what the differences are between 1.5 and 2.0 and I won't use 2.0 because of the privacy invasions in 2.0. I also know the differences between the best version of Fx (0.8) and 1.0 and 1.5 and 2.0. As for different extensions causing different problems, the user can always boot into Fx Safe Mode where the extensions and themes are disabled to see if they still have the problem.  The extensions are why we use Fx and we become quicky and strongly addicted to them and it's unthinkable to go use IE which has none of the richness of Fx...none of the vista of potential either.<br> </DIV>No.. that is because I help people with their Firefox problems..not only at DSLR but in the real world and other forums constantly running into prolems they have with it..some case just like the IE mentality where they refuse to update..but too many cases lately where it is just plain broken or won't work with another App and for Firefox 2 the latest is 2.0.0.3 and still counting. Safe Mode.. :D Firefox does not have a monopoly on that..it is a Microsoft thingie..Richness ??? like with Winamp and shoutcast ?<br><br>&raquo;<A HREF="http://www.mozilla.org/projects/firefox/roadmap.html" >www.mozilla.org/projects/firefox&middot;&middot;&middot;map.html</A><br><SMALL>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> <br>Missing Kids<br> &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18114462</guid>
<pubDate>Wed, 04 Apr 2007 08:13:44 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18114444</link>
<description><![CDATA[<A HREF="/useremail/u/332558"><b>Ryan</b></A> : <div class="bquote"><SMALL>said by  Name Game <A HREF="/useremail/u/655093"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>And what you just described is the biggest problem with Firefox..in the IE world at least people know the differences in IE5, IE5.5, IE6, and IE7..but when it come to Firefox and people say they have a problem with it..you have no idea what version or plug in or other open source gimmick they have with it..the whole project has little or no quality control..each version has it own particular problems and I constantly see gurus who write code for it tell users it is not our fault contact the webmaster of the site..or some other vendor.<br> </DIV> :</SMALL><BR><BR>PFFFF yea who uses software that can be customized or preferred by that user. Everyone should be forced into standardized computing. No choices, no customizing, and you have to pay for it too!  :uhh:]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18114444</guid>
<pubDate>Wed, 04 Apr 2007 08:03:01 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18114435</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : <div class="bquote"><SMALL>said by  Name Game <A HREF="/useremail/u/655093"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>And what you just described is the biggest problem with Firefox..in the IE world at least people know the differences in IE5, IE5.5, IE6, and IE7..but when it come to Firefox and people say they have a problem with it..you have no idea what version or plug in or other opensource gimmick they have with it..the whole project has little or no quality control..each version has it own particular problems and I constantly see gurus who write code for it tell users it is not our fault contact the webmaster of the site..or some other vendor.<br> </DIV>That's because you don't use it. I know what the differences are between 1.5 and 2.0 and I won't use 2.0 because of the privacy invasions in 2.0. I also know the differences between the best version of Fx (0.8) and 1.0 and 1.5 and 2.0. As for different extensions causing different problems, the user can always boot into Fx Safe Mode where the extensions and themes are disabled to see if they still have the problem.  The extensions are why we use Fx and we become quicky and strongly addicted to them and it's unthinkable to go use IE which has none of the richness of Fx...none of the vista of potential either.<br><SMALL>--<br>"If you want to do DRM on a PC then you need to treat the user as the enemy." Ross Anderson in "`Trusted Computing' Frequently Asked Questions"<br><br>&raquo;<A HREF="http://www.msfirefox.com/" >www.msfirefox.com/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18114435</guid>
<pubDate>Wed, 04 Apr 2007 07:56:16 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18114395</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : <div class="bquote"><SMALL>said by  swhx7 <A HREF="/useremail/u/1376598"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>javaMan is right, the browser is only a vehicle. What causes the problem here is unpatched user32.dll interpreting an animated cursor file. The file need not be named with .ani extension.<br><br>When we were discussing it before in the other thread (1 and 2 april), we observed that the most straightforward way of delivering the file, namely putting reference to it in a CSS line, did not work on Firefox. And Mozilla doc page said that Firefox could not use the ani files.<br><br>WHat we have now is a proof of concept (POC) of infection via Firefox. But they do not explain how it works and they won't until there's a Firefox patch. The two obvious possibilities are (a) certain versions of Firefox support .ani although earlier versions don't or (b) there is some means of getting Firefox to download an ani file without user permission and ask user32.dll to run it, other than the CSS way.<br><br><div class="bquote"><SMALL>said by  Boricua65 <A HREF="/useremail/u/571743"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</SMALL><br><br>I don't use animated cursors, so I should be okay?  I use Firefox 2.0.0.3 as the main browser and IE 6 when pages do not render well and for updates.  Or are they talking about the cursors installed from Windows. </DIV>The point of this whole issue is that it's not a choice. If it were something you could just turn off in Windows it would be less critical. The problem is malicious websites (or frames, emails etc.) can make the system try to run the supposed animated cursor (really a malware) without asking. We don't know how it works thru Firefox yet.<br><br><div class="bquote"><SMALL>said by  jcbsinger <A HREF="/useremail/u/1450688"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</SMALL><br><br>Could anyone here please explain me that what is ANI flaw, I am kinda new to this area :(<br> </DIV>.ani files are a type of file that normally makes an animated cursor, but a malicious version of it can take over your computer, if you haven't installed the fix.<br><br>Simple answer for all Windows users now, install the patch. You will already have it if you use Automatic Updates. If you use Microsoft Update site and haven't gone there since about midday Tuesday 3rd April, do it now. If you download manually, go to: &raquo;<A HREF="http://www.microsoft.com/technet/security/Bulletin/MS07-017.mspx" >www.microsoft.com/technet/securi&middot;&middot;&middot;017.mspx</A><br> </DIV>And what you just described is the biggest problem with Firefox..in the IE world at least people know the differences in IE5, IE5.5, IE6, and IE7..but when it come to Firefox and people say they have a problem with it..you have no idea what version or plug in or other opensource gimmick they have with it..the whole project has little or no quality control..each version has it own particular problems and I constantly see gurus who write code for it tell users it is not our fault contact the webmaster of the site..or some other vendor.<br><SMALL>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> Missing Kids &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18114395</guid>
<pubDate>Wed, 04 Apr 2007 07:38:55 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18114295</link>
<description><![CDATA[<A HREF="/useremail/u/1376598"><b>swhx7</b></A> : javaMan is right, the browser is only a vehicle. What causes the problem here is unpatched user32.dll interpreting an animated cursor file. The file need not be named with .ani extension.<br><br>When we were discussing it before in the other thread (1 and 2 april), we observed that the most straightforward way of delivering the file, namely putting reference to it in a CSS line, did not work on Firefox. And Mozilla doc page said that Firefox could not use the ani files.<br><br>WHat we have now is a proof of concept (POC) of infection via Firefox. But they do not explain how it works and they won't until there's a Firefox patch. The two obvious possibilities are (a) certain versions of Firefox support .ani although earlier versions don't or (b) there is some means of getting Firefox to download an ani file without user permission and ask user32.dll to run it, other than the CSS way.<br><br><div class="bquote"><SMALL>said by  Boricua65 <A HREF="/useremail/u/571743"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I don't use animated cursors, so I should be okay?  I use Firefox 2.0.0.3 as the main browser and IE 6 when pages do not render well and for updates.  Or are they talking about the cursors installed from Windows. </DIV>The point of this whole issue is that it's not a choice. If it were something you could just turn off in Windows it would be less critical. The problem is malicious websites (or frames, emails etc.) can make the system try to run the supposed animated cursor (really a malware) without asking. We don't know how it works thru Firefox yet.<br><br><div class="bquote"><SMALL>said by  jcbsinger <A HREF="/useremail/u/1450688"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Could anyone here please explain me that what is ANI flaw, I am kinda new to this area :(<br> </DIV>.ani files are a type of file that normally makes an animated cursor, but a malicious version of it can take over your computer, if you haven't installed the fix.<br><br>Simple answer for all Windows users now, install the patch. You will already have it if you use Automatic Updates. If you use Microsoft Update site and haven't gone there since about midday Tuesday 3rd April, do it now. If you download manually, go to: &raquo;<A HREF="http://www.microsoft.com/technet/security/Bulletin/MS07-017.mspx" >www.microsoft.com/technet/securi&middot;&middot;&middot;017.mspx</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18114295</guid>
<pubDate>Wed, 04 Apr 2007 06:47:29 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18114222</link>
<description><![CDATA[<A HREF="/useremail/u/1450688"><b>jcbsinger</b></A> : Could anyone here please explain me that what is ANI flaw, I am kinda new to this area :(<br><SMALL>--<br>Guide on Mp4<br>&raquo;<A HREF="http://www.mp4-converter.net" >www.mp4-converter.net</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18114222</guid>
<pubDate>Wed, 04 Apr 2007 05:23:23 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18113887</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : Naw..just 'lock down' the browser and many threads at this forum to explain the settings to do so. limited user is now set at default for any who hav winxp sp2..and Vista has its own version of the same..no need for theird party stuff..their are setting in your browser to do just that and even IE6 has popup blocker protection that does more than some users realize..but its all there if one looks and sets it up<br><br>&raquo;<A HREF="http://www.microsoft.com/windowsxp/sp2/ieoeoverview.mspx" >www.microsoft.com/windowsxp/sp2/&middot;&middot;&middot;iew.mspx</A><br><SMALL>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> Missing Kids &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18113887</guid>
<pubDate>Wed, 04 Apr 2007 01:04:49 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18113683</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : <div class="bquote"><SMALL>said by  Name Game <A HREF="/useremail/u/655093"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>well rich..what you just posted made no sense..when it came to your words on the browser end of the deal..</DIV><BR> Why? Sure, browsers have certain security built in. Up until recently, both Opera and FireFox users have laughed at IE users, but now, FF has experienced many vulnerabilities, and O is perhaps not far behind, once malware writers focus on it. No line of code is immune from being exploited.<br><br>With that in mind, I would never depend on my browser to be immune from some unknown exploit, and so, I advocate that we should  have protection in back of the browser for the "in case" scenario.<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>but it certainly is true one needs to stop a vector or a payload if it was cause damage..but your supposition would then be to stop everything until you make sure no one is going to throw mama from the train. :D<HR></BLOCKQUOTE><BR> My supposition is to stop *any* executable from being installed  by remote code execution, aka, drive-by download. <br><br>Many ways to do that: DEP, SRP, Limited User, 3rd-party execution protection -- all White List solutions.<br><BR><br><br>regards,<br><br>-rich<BR><br>______________________________________________<br><SMALL>"Talking About Security Can Lead To Anxiety, Panic, And Dread... <br>Or Cool Assessments, Common Sense And Practical Planning..."<br>  <BLOCKQUOTE>   --Bruce Schneier</SMALL></BLOCKQUOTE><br><br> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18113683</guid>
<pubDate>Wed, 04 Apr 2007 00:09:56 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18113648</link>
<description><![CDATA[<A HREF="/useremail/u/1346679"><b>AB</b></A> : <div class="bquote"><SMALL>said by  La Luna <A HREF="/useremail/u/429050"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I don't care anymore. I'm patched.  :D <br><br>I think I lost track of the tennis game not long after this:<br><br><div class="bquote"><SMALL>said by  AB <A HREF="/useremail/u/1346679"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Aha! Javascript is most definitely heavily involved. Thank you very much, Cudni!</DIV>&raquo;<A HREF="/forum/remark,18090953">Re: Chinese servers host malicious cursor attacks</A><br><br> :D</DIV>That was early on in the thread, and just referenced what was printed in the 'Security Focus' article. It became apparent later that javascript was not the culprit on this one.<br>Meaning that was an incorrect statement on my part.  ;)<br><br>Glad to hear you're patched up without issues, Luna!  :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18113648</guid>
<pubDate>Wed, 04 Apr 2007 00:01:29 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18113590</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : well rich..what you just posted made no sense..when it came to your words on the browser end of the deal..but it certainly is true one needs to stop a vector or a payload if it was cause damage..but your supposition would then be to stop everything until you make sure no one is going to throw mama from the train. :D<br><SMALL>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> Missing Kids &raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18113590</guid>
<pubDate>Tue, 03 Apr 2007 23:48:13 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18113561</link>
<description><![CDATA[<A HREF="/useremail/u/429050"><b>La Luna</b></A> : <div class="bquote"><SMALL>said by  AB <A HREF="/useremail/u/1346679"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>I think it was brought out in the other thread that javascript was *not* involved, beyond the browser re-direction nature of sending you to a page hosting the exploit, regardless of how it was presented in the 'Security Focus' article.<br>A CSS code trojan/worm, was what I got from it.<br>But there definitely seems to be a lot more confusion about what's up with this one than is ordinarily the case.<br><div class="bquote">Why start a new thread? It just makes it more confusing and harder to keep up with.</DIV>So many threads, so little time . . . .  ;)  :)<br> </DIV>I don't care anymore. I'm patched.  :D <br><br>I think I lost track of the tennis game not long after this:<br><br><div class="bquote"><SMALL>said by  AB <A HREF="/useremail/u/1346679"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Aha! Javascript is most definitely heavily involved. Thank you very much, Cudni!</DIV>&raquo;<A HREF="/forum/remark,18090953">Re: Chinese servers host malicious cursor attacks</A><br><br> :D<br><SMALL>--<br>~~Don't wanna' fight in a holy war...World war III when are you coming for me? Been kicking up sparks, we set the flames free...the windows are locked now so what'll it be? A house on fire or a rising sea?...~~<br><br></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18113561</guid>
<pubDate>Tue, 03 Apr 2007 23:41:53 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18113498</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : <div class="bquote"><SMALL>said by  Boricua65 <A HREF="/useremail/u/571743"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I don't use animated cursors, so I should be okay? </DIV><BR>Note that it is the code of an animated cursor file, and not an animated cursor itself which does the work. The file has to be embedded in a web page or email.  Also, file extensions other than *.ani are used. The one I tested was a .jpg file with the .ani code inside. <br><br><div class="bquote"><SMALL>said by  javaMan <A HREF="/useremail/u/658856"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR> What is worrisome is there are a variety of technologies that could possibly be used.</DIV><div class="bquote"><SMALL>said by somebodynew5 :</SMALL><BR><BR>These proof of concept pages often only test a limited subset of all possible attack vectors.</DIV><BR>Again, Kevin's and my points in the AV thread: if you depend on trying to cover all bases of exploit carriers (.ani, .wmf, etc) you will always be in "emergency mode" but if you are set up to catch the payload, well, the *,ani file can sit cached all day but won't do anything.<br><br><div class="bquote"><SMALL>said by  planet <A HREF="/useremail/u/510041"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Would this exploit be less destructive to a machine running in a limited user account? </DIV><BR>Of course!  fatdcuk <A HREF="/useremail/u/1162456"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> pointed out to me the irony of the video, in that that DEP had to be turned off in order for the exploit to run. It's reminiscent of the firewall leaktests: you have to disable your security to let the test executable run to prove you are vulnerable.<br><br><div class="bquote"><SMALL>said by  Name Game <A HREF="/useremail/u/655093"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Love those bloggers  :D<br><br>&raquo;<A HREF="http://blogs.zdnet.com/Ou/?p=461&tag=nl.e589" >blogs.zdnet.com/Ou/?p=461&tag=nl.e589</A></DIV><BR>Well, they get paid to stir up discussion. But some relevant conclusions can be made from such articles. The browser is on the front line,and should not be depended upon for ones total security. One should always have protection behind the browser for the unexpected. <br><br>So what if on day-Zero you encounter the .ani exploit on a web page and it gets by the your browser. Doesn't everyone here have something in place that would block the executable payload? I certainly hope so! <br><br>Then, you don't have to be in "emergency mode" and can calmly await the official patch (now released).<br><BR><br><br>regards,<br><br>-rich<BR><br>______________________________________________<br><SMALL>"Talking About Security Can Lead To Anxiety, Panic, And Dread... <br>Or Cool Assessments, Common Sense And Practical Planning..."<br>  <BLOCKQUOTE>   --Bruce Schneier</SMALL></BLOCKQUOTE>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18113498</guid>
<pubDate>Tue, 03 Apr 2007 23:29:38 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18112866</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : Love those bloggers  :D<br><br>&raquo;<A HREF="http://blogs.zdnet.com/Ou/?p=461&tag=nl.e589" >blogs.zdnet.com/Ou/?p=461&tag=nl.e589</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18112866</guid>
<pubDate>Tue, 03 Apr 2007 21:25:11 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18112522</link>
<description><![CDATA[<A HREF="/useremail/u/819609"><b>Grail Knight</b></A> : I figured as much but better safe then sorry.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18112522</guid>
<pubDate>Tue, 03 Apr 2007 20:19:07 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18112417</link>
<description><![CDATA[<A HREF="/useremail/u/658856"><b>javaMan</b></A> : <div class="bquote"><SMALL>said by  Grail Knight <A HREF="/useremail/u/819609"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>The patch was released today by MS in case you have not checked for updates.  :)<br> </DIV>Yeah, thanks.  I checked right after posting that message and installed it. ;)<br><SMALL>--<br>Woe unto them that call evil good, and good evil; that put darkness for light, and light for darkness. . . Isa. 5:20</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18112417</guid>
<pubDate>Tue, 03 Apr 2007 20:04:39 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18112352</link>
<description><![CDATA[<A HREF="/useremail/u/819609"><b>Grail Knight</b></A> : The patch was released today by MS in case you have not checked for updates.  :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18112352</guid>
<pubDate>Tue, 03 Apr 2007 19:53:50 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18111646</link>
<description><![CDATA[<A HREF="/useremail/u/658856"><b>javaMan</b></A> : I'm somewhat perplexed and worried by this term "browser vulnerability"  This is an OS vulnerability; web based technologies employed by the browser are simply the vehicle used for transport.  As such there is no browser test that will demonstrate either invulnerability or vulnerability.  As somebodynew5 noted there are only tests that will indicate whether a particular technology used by the browser is usable for the delivery.  What is worrisome is there are a variety of technologies that could possibly be used.  It seems prudent to me then that one should not place too much confidence in these "browser vulnerability" tests.  Invulnerability will only be attained when MS provides the patch which, according to reports, is coming soon.<br><SMALL>--<br>Woe unto them that call evil good, and good evil; that put darkness for light, and light for darkness. . . Isa. 5:20</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18111646</guid>
<pubDate>Tue, 03 Apr 2007 17:28:13 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18111401</link>
<description><![CDATA[<A HREF="/useremail/u/1089628"><b>fishmaster</b></A> : Well FF did not appear vulnerable until I click the IE tab. Opera is not vulnerable either. However after installing the update I still got this in IE7...see pic...makes a dude wonder?? aye?<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18111401?c=1147384&ret=L2ZvcnVtL3IxODEwODcxNy54bWw%3D"><IMG TITLE="112084 bytes" BORDER=0 WIDTH=600 HEIGHT=338 SRC="/r0/download/1147384~2b760a7a14e12a8fd8b4b71bbf9ccd17/Ani%20Alert2.jpg"></A><br>after patch ani alert</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18111401</guid>
<pubDate>Tue, 03 Apr 2007 16:28:24 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18110637</link>
<description><![CDATA[<A HREF="/useremail/u/1346679"><b>AB</b></A> : <div class="bquote"><SMALL>said by somebodynew5 :</SMALL><BR><BR>I think the biggest problem with these Proof of Concept test pages is people think that just because they pass one particular test that says their system is safe they think they are safe.<br><br>These proof of concept pages often only test a limited subset of all possible attack vectors. . . .<br><br>. . In this case the exploit can be triggered by some CSS code to load a ANI cursor file, So with some tweaks I am sure it is quite possible to cause Firefox to attempt to load a ANI file into windows.</DIV>I don't doubt this for a moment.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18110637</guid>
<pubDate>Tue, 03 Apr 2007 13:49:44 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18110622</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : Just an FYI folks.. there is a patch available at windows update... even as I type...<br><SMALL>--<br>da Cajun  Darn I hate Malware</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18110622</guid>
<pubDate>Tue, 03 Apr 2007 13:46:56 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18110583</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I think the biggest problem with these Proof of Concept test pages is people think that just because they pass one particular test that says their system is safe they think they are safe.<br><br>These proof of concept pages often only test a limited subset of all possible attack vectors. So while one proof of concept page may only trigger the exploit under IE there may also be attack vectors available under Firefox that are simply not exploited by the particular POC test page. A simple change to the exploit code may be able to attack using other browsers or avenues of exploit.<br><br>Much like all pages do not render the same under all browser many core operating system exploits require some minor code changes to target other browsers.<br><br>So any time the flaw is located in the underlying operating system just using a different browser may not close all available attack vectors. It all depends on the actual exploit. In this case the exploit can be triggered by some CSS code to load a ANI cursor file, So with some tweaks I am sure it is quite possible to cause Firefox to attempt to load a ANI file into windows.<br> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18110583</guid>
<pubDate>Tue, 03 Apr 2007 13:41:18 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18110478</link>
<description><![CDATA[<A HREF="/useremail/u/1021645"><b>antiphishing</b></A> : <div class="bquote"><SMALL>said by  matunga <A HREF="/useremail/u/847301"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>This is a short flash video of exploiting the ANI vulnerability on Windows Vista. The exploit works against both Internet Explorer 7 and Mozilla Firefox 2.0:<br><br>&raquo;<A HREF="http://determina.blogspot.com/2007/04/exploiting-vista-with-ani.html" >determina.blogspot.com/2007/04/e&middot;&middot;&middot;ani.html</A><br> </DIV>&raquo;<A HREF="http://www.us-cert.gov/cas/techalerts/TA07-089A.html" >www.us-cert.gov/cas/techalerts/T&middot;&middot;&middot;89A.html</A><br><SMALL>--<br><B><br>Specializing in "takes downs" of phishing and advance fee scams<br>Send your Phishing/Advance fee scams to: <A HREF="mailto:phish@antihotmail.com">phish@antihotmail.com</A> <br>&raquo;<A HREF="/profile/1021645">/profile/1021645</A><br></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18110478</guid>
<pubDate>Tue, 03 Apr 2007 13:18:04 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18110424</link>
<description><![CDATA[<A HREF="/useremail/u/1346679"><b>AB</b></A> : <div class="bquote"><SMALL>said by  planet <A HREF="/useremail/u/510041"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Would this exploit be less destructive to a machine running in a limited user account?</DIV>I hold myself out as no big security expert, but I think that's the case pretty much regardless of the nature of the exploit, isn't it?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18110424</guid>
<pubDate>Tue, 03 Apr 2007 13:06:57 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18110406</link>
<description><![CDATA[<A HREF="/useremail/u/510041"><b>planet</b></A> : Would this exploit be less destructive to a machine running in a limited user account?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18110406</guid>
<pubDate>Tue, 03 Apr 2007 13:03:38 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18110319</link>
<description><![CDATA[<A HREF="/useremail/u/1346679"><b>AB</b></A> : <div class="bquote"><SMALL>said by  La Luna <A HREF="/useremail/u/429050"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I thought we already established in the other thread about this that js <B>IS</B> involved, and that there is conflicting info on which browsers may or may not be affected?<br><br>&raquo;<A HREF="/forum/remark,18085278">Microsoft Security Advisory (935423) Vulnerability in Window</A><br><br>&raquo;<A HREF="http://www.securityfocus.com/brief/473" >www.securityfocus.com/brief/473</A></DIV>I think it was brought out in the other thread that javascript was *not* involved, beyond the browser re-direction nature of sending you to a page hosting the exploit, regardless of how it was presented in the 'Security Focus' article.<br>A CSS code trojan/worm, was what I got from it.<br>But there definitely seems to be a lot more confusion about what's up with this one than is ordinarily the case.<br><div class="bquote">Why start a new thread? It just makes it more confusing and harder to keep up with.</DIV>So many threads, so little time . . . .  ;)  :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18110319</guid>
<pubDate>Tue, 03 Apr 2007 12:45:41 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18110246</link>
<description><![CDATA[<A HREF="/useremail/u/429050"><b>La Luna</b></A> : I thought we already established in the other thread about this that js <B>IS</B> involved, and that there is conflicting info on which browsers may or may not be affected?<br><br>&raquo;<A HREF="/forum/remark,18085278">Microsoft Security Advisory (935423) Vulnerability in Window</A><br><br>&raquo;<A HREF="http://www.securityfocus.com/brief/473" >www.securityfocus.com/brief/473</A><br><br>Why start a new thread? It just makes it more confusing and harder to keep up with. <br><SMALL>--<br>~~Don't wanna' fight in a holy war...World war III when are you coming for me? Been kicking up sparks, we set the flames free...the windows are locked now so what'll it be? A house on fire or a rising sea?...~~<br><br></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18110246</guid>
<pubDate>Tue, 03 Apr 2007 12:33:53 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18110219</link>
<description><![CDATA[<A HREF="/useremail/u/1346679"><b>AB</b></A> : <div class="bquote"><SMALL>said by  Cudni <A HREF="/useremail/u/917630"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>the poc listed below did not crash  FF (on either XP or  W2K)<br><br>&raquo;<A HREF="http://zert.isotf.org/tests/testani.htm" >zert.isotf.org/tests/testani.htm</A><br><br>It closed IE7 but not IE6</DIV>The screenshot is what I get with Firefox 2.0.0.3 at that link.<br><br>I notice they call it an "ie exploit". Just poor characterization on their part?<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18110219?c=1147307&ret=L2ZvcnVtL3IxODEwODcxNy54bWw%3D"><IMG TITLE="30908 bytes" BORDER=0 WIDTH=490 HEIGHT=128 SRC="/r0/download/1147307~49219f4b6ebad8853b0aee66a24146b1/SS-ani.png"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18110219</guid>
<pubDate>Tue, 03 Apr 2007 12:29:15 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18110179</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : <div class="bquote"><SMALL>said by  matunga <A HREF="/useremail/u/847301"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>... Firefox 2.0.0.3 is affected with or without NoScript.<br>The only browser not at risk is Internet Explorer 7 under Windows Vista because the Protected Mode (enabled by default)<br> </DIV>ANI patch not applied, WINXP home w/current patches, user has admin rights.<br><SMALL>--<br>The society which scorns excellence in plumbing as a humble activity and tolerates shoddiness in philosophy because it is an exalted activity will have neither good plumbing nor good philosophy: neither its pipes or its theories will hold water.<br></SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18110179?c=1147306&ret=L2ZvcnVtL3IxODEwODcxNy54bWw%3D"><IMG class="apic" BORDER=0 TITLE="114729 bytes" WIDTH=600 HEIGHT=469 SRC="/r0/download/1147306.thumb600~d78ac7c56d9362244c972285bf74cf0b/ScnCap001 Apr. 03 12.17.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18110179</guid>
<pubDate>Tue, 03 Apr 2007 12:21:14 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18110178</link>
<description><![CDATA[<A HREF="/useremail/u/571743"><b>Boricua65</b></A> : I don't use animated cursors, so I should be okay?  I use Firefox 2.0.0.3 as the main browser and IE 6 when pages do not render well and for updates.  Or are they talking about the cursors installed from Windows.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18110178</guid>
<pubDate>Tue, 03 Apr 2007 12:21:01 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18110119</link>
<description><![CDATA[<A HREF="/useremail/u/465492"><b>Jrb2</b></A> : Hi Cudni,<br><br>IMON (NOD32) immediately jumps up with a warning (see screenie) when clicking on that link.<br>Then I see: "you do not appear to be vulnerable to the ie ani cursor exploit" (etc etc).<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18110119?c=1147299&ret=L2ZvcnVtL3IxODEwODcxNy54bWw%3D"><IMG TITLE="13671 bytes" BORDER=0 WIDTH=467 HEIGHT=228 SRC="/r0/download/1147299~f96d41152c4f68c9e5d3dfc9eacf4326/NOD32_2007_04_03_1.gif"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18110119</guid>
<pubDate>Tue, 03 Apr 2007 12:10:28 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18110098</link>
<description><![CDATA[<A HREF="/useremail/u/825862"><b>MeDuZa</b></A> : <div class="bquote"><SMALL>said by  matunga <A HREF="/useremail/u/847301"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>The only browser not at risk is Internet Explorer 7 under Windows Vista because the Protected Mode (enabled by default)</DIV>No crash here. I'm getting the below message with both browsers Opera and K-Meleon on w2k. <br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>you do not appear to be vulnerable to the ie ani cursor exploit<br>for more information about the exploit and the patch visit: <A HREF="http://zert.isotf.org/">zert</A><HR></BLOCKQUOTE><br><br>Is there any other test site to check?<br><SMALL>--<br>Reality corrupted. Reboot universe? (Y/N)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18110098</guid>
<pubDate>Tue, 03 Apr 2007 12:05:07 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18110076</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : Hmm... with hardware DEP on... It didn't crash ff or cause IE7 to close... <br><SMALL>--<br>da Cajun  Darn I hate Malware</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18110076</guid>
<pubDate>Tue, 03 Apr 2007 12:00:59 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18109992</link>
<description><![CDATA[<A HREF="/useremail/u/917630"><b>Cudni</b></A> : the poc listed below did not crash  FF (on either XP or  W2K)<br><br>&raquo;<A HREF="http://zert.isotf.org/tests/testani.htm" >zert.isotf.org/tests/testani.htm</A><br><br>It closed IE7 but not IE6<br><br>Cudni]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18109992</guid>
<pubDate>Tue, 03 Apr 2007 11:42:18 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18109711</link>
<description><![CDATA[<A HREF="/useremail/u/847301"><b>matunga</b></A> : <div class="bquote"><SMALL>said by  angussf <A HREF="/useremail/u/560047"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>      :</SMALL><BR><BR>I went to a site which purports to test your browser and my Firefox 2.0.0.3 with NoScript was not vulnerable.  IE6 with scripting disabled is also not vulnerable.<br> </DIV>Sorry, but javascript is not involved in this flaw, so Firefox 2.0.0.3 is affected with or without NoScript.<br>The only browser not at risk is Internet Explorer 7 under Windows Vista because the Protected Mode (enabled by default)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18109711</guid>
<pubDate>Tue, 03 Apr 2007 10:48:17 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18109489</link>
<description><![CDATA[<A HREF="/useremail/u/560047"><b>angussf</b></A> : I went to a site which purports to test your browser and my Firefox 2.0.0.3 with NoScript was not vulnerable.  IE6 with scripting disabled is also not vulnerable.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18109489</guid>
<pubDate>Tue, 03 Apr 2007 10:07:35 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18108834</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : <div class="bquote"><SMALL>said by  jansson_mark <A HREF="/useremail/u/444625"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Im still having a bit trouble believing all this. <br><br>Well, for starters I dont understand how the heck is Firefox connected to animated cursors of Windows in the first place. I just dont get it. Second, I havent SEEN and TRYED OUT any POC on my Firefox 2.0.0.3.<br> </DIV>It is getting more complicated than that..and depends on how you have the security set on IE or any other browser..<br>I can set IE6 up and it will not be hit..also same with IE7.<br><br>But I do understand your point.<br><br>Vulnerability Details<br>(Credit to Joe Stewart, SecureWorks)<br><br>The newly discovered zero-day vulnerability in the parsing of animated cursors is very similar to the one previously discovered by eEye that was patched by Microsoft in MS05-002. Basically an "anih" chunk in an animated cursor RIFF file is read into a stack buffer of a fixed size (36 bytes) but the actual memory copy operation uses the length field provided inside the "anih" chunk&#151;giving an attacker an easy route to overflow the stack and gain control of the execution of the process. <br><br>With the MS05-002 patch, Microsoft added a check for the length of the chunk before copying it to the buffer. However, they neglected to audit the rest of the code for any other instances of the vulnerable copy routine. As it turns out, if there are two "anih" chunks in the file, the second chunk will be handled by a separate piece of code which Microsoft did not fix. This is what the authors of the zero-day discovered. <br><br>Although eEye has released a third-party patch that will prevent the latest exploit from working, it doesn't fix the flawed copy routine. It simply requires that any cursors loaded must reside within the Windows directory (typically C:&#8260;WINDOWS&#8260; or C:&#8260;WINNT&#8260;). This approach should successfully mitigate most "drive-by's," code execution scenarios, but it might also break third-party applications that use animated cursors within their own program directories. <br><br>For this reason, ZERT is releasing a patch which addresses the core of the vulnerability, by ensuring that no more than 36 bytes of an "anih" chunk will be copied to the stack buffer, thus eliminating all potential exploit paths while maintaining compatibility with well-formatted animated cursor files. <br><br>&raquo;<A HREF="http://zert.isotf.org/advisories/zert-2007-01.htm" >zert.isotf.org/advisories/zert-2007-01.htm</A><br><br>Compromised sites using ANI exploit code<br>&raquo;<A HREF="http://www.websense.com/securitylabs/blog/blog.php?BlogID=119" >www.websense.com/securitylabs/bl&middot;&middot;&middot;ogID=119</A><br>Apr 2 2007 3:15PM ~ "Websense's ThreatSeeker(tm) technology has discovered that a large set of websites have been compromised within the Asia Pacific Region and have embedded IFRAMES within them pointing to a site that is hosting the ANI exploit code. An IFRAME or "invisible frame" is an element which makes it possible to embed another HTML document inside the main document. From Wikipedia: http://en.wikipedia.org/wiki/Iframe.<br>Although we are tracking hundreds of other sites that are hosting ANI exploit files this alert pertains to one group of sites that are all connecting to the same host. Many of the sites appear to be running online blogs or message boards. Most sites have embedded IFRAME's on all pages leading to a main set of sites which are hosting the exploit code. The number of unique sites currently up and running for this one attack is greater than 50 and the number of pages is greater than 500. Assuming users connect to the sites they will be redirected to two unique locations which are hosting exploit code which in turn downloads and installs a file called "ad.exe". The file includes a generic password stealer and is not detected well by most Antivirus companies (MD5 0c9217553871d3eb5f20b553d91a098b)..."<br><br>(Screenshots available at the URL above.)<br><br>http://forums.spybot.info/showthread.php?s=ddf7a0304bcf9398c9c38d1b84cde327&t=12557&page=2<br><SMALL>--<br>Gladiator Security Forum  http://www.gladiator-antivirus.com/ Missing Kids http://www.missingkids.com/</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18108834</guid>
<pubDate>Tue, 03 Apr 2007 05:14:39 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18108766</link>
<description><![CDATA[<A HREF="/useremail/u/444625"><b>jansson_mark</b></A> : Im still having a bit trouble believing all this. <br><br>Well, for starters I dont understand how the heck is Firefox connected to animated cursors of Windows in the first place. I just dont get it. Second, I havent SEEN and TRYED OUT any POC on my Firefox 2.0.0.3.<br><SMALL>--<br>My computer security & privacy related homepage &raquo;<A HREF="http://www.markusjansson.net" >www.markusjansson.net</A> <br>Use HushTools or GnuPG/PGP to encrypt any email before sending it to me to protect our privacy.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18108766</guid>
<pubDate>Tue, 03 Apr 2007 04:15:35 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18108752</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : The exploit is more severe in Fx! And over at Mozillazine they have been pooh-pooing this entire thing. <br><br>Thanks for the link. I don't have Flash Player on my main machine but I do have it on a virtual one so I watched this there.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18108752</guid>
<pubDate>Tue, 03 Apr 2007 04:03:14 EDT</pubDate>
</item>

<item>
<title>Firefox 2 is vulnerable to ANI flaw</title>
<link>http://www.dslreports.com/forum/remark,18108717</link>
<description><![CDATA[<A HREF="/useremail/u/847301"><b>matunga</b></A> : This is a short flash video of exploiting the ANI vulnerability on Windows Vista. The exploit works against both Internet Explorer 7 and Mozilla Firefox 2.0:<br><br>&raquo;<A HREF="http://determina.blogspot.com/2007/04/exploiting-vista-with-ani.html" >determina.blogspot.com/2007/04/e&middot;&middot;&middot;ani.html</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18108717</guid>
<pubDate>Tue, 03 Apr 2007 03:35:05 EDT</pubDate>
</item>

</channel>
</rss>
