IE drag and drop vulnerability (MS04-38 drag and drop vulnerability)

xiaoxiao2021-03-06  69

A very harmful IE vulnerability; the implementation process is like this, there is still a small area on the web page, this area is automatically followed by mouse movement, when the user uses the mouse to drag the scroll bar of the web page, a hidden Picture (or other executable, such as Troja) is also dragged at the same time, as long as a mouse button is loosen, this hidden picture or other executable file is saved in the startup item of the Start menu. The vulnerability uses in detail in the 10th issue of the hacking line, mainly using the three vulnerabilities of IE to achieve the purpose. If you install SP2, click the Custom Level button in the "Security" tab of "Internet Options", disable "binary and scripting behavior" in the "ActiveX Controls and Plugins" in the pop-up dialog, this can Effectively prevent this vulnerability.

转载请注明原文地址:https://www.9cbs.com/read-92271.html

New Post(0)