Feeling Dangerously Brave?
Results 1 to 9 of 9

Thread: Feeling Dangerously Brave?

  1. #1
    Join Date
    Jul 2002
    Location
    Collingwood, Ontario, Canada
    Posts
    1,104

    Feeling Dangerously Brave?

    A friend went to a site that ran the JS.Exception Exploit on his machine. Its mostly annoying (webpage changes when he moves the mouse, errors in Windows Explorer). In researching it, I found many refences to Internet Explorer, but he uses Netscape.

    Turns out he has never done a Windows Update. He is doing that now, and I think that the Critical/Security Update that would have saved him was November 12, 1999. (Deals with Javascript)But would that haved saved him if he uses Netscape?

    He insists on using V4.76 and I have found where he can download that version from Netscape's site. Would the "current" V4.76 be any more secure than his two year old one?

    If anyone is feeling dangerously brave, and if a Moderator agrees, I'll post the URL.

    Last edited by Leurgy; August 13th, 2002 at 12:39 PM.
    ** **
    We use our powers for good, not evil

    ** **
    Logic is a systematic method of coming to the wrong
    conclusion with confidence.

  2. #2
    Join Date
    Jul 1998
    Location
    Toronto
    Posts
    26,543
    That website is for the makers of Lockdown Millenium, formerly Lockdown 2000. They have been harshly criticized by a lot of knowledgable web security/privacy experts for not only creating a substandard product and using fear tactics to try and get unknowing users to buy their software but also for generating spurious lawsuites against some of those critics.

    http://www.nwinternet.com/~pchelp/bo/LDthreat.htm
    _____________________
    cat lovers click here

  3. #3
    Join Date
    Jul 2002
    Location
    Collingwood, Ontario, Canada
    Posts
    1,104
    Thanks Fink:

    I ran the test with AVG running, and got an alert "Could be infected VBS/GMW". It then wanted me to shutdown my anti-virus. I'm not THAT stupid. I read the page you sent, and am removing that link.

    Thanks again, I guess thats why we come here.
    ** **
    We use our powers for good, not evil

    ** **
    Logic is a systematic method of coming to the wrong
    conclusion with confidence.

  4. #4
    Join Date
    Oct 2001
    Location
    Tennessee
    Posts
    922
    The page you get after clicking on the link on Little's page shows me that Lockdown is the most unprofessional "business" I've seen yet in the time I've been on the Net. Why would I spend a dime with them? And what would I get if I used their phone support? Sounds from a nursery?

    From a quick glance it would seem Little has more reason for a lawsuit, considering there's a whole web page of bed wetting dedicated to him.


    http://lockdowncorp.com/pchelp/

    Uh, make that at least 2 pages of bedwetting.

    http://lockdowncorp.com/pchelp/paris.html



    Very unprofessional business practices.....
    Last edited by JoJo Gunn; August 13th, 2002 at 03:20 PM.

  5. #5
    Join Date
    Jul 2002
    Location
    Collingwood, Ontario, Canada
    Posts
    1,104
    So, it seems that these two people (Paris and Little) are not getting along. Oh well.

    Any answers to my questions?
    ** **
    We use our powers for good, not evil

    ** **
    Logic is a systematic method of coming to the wrong
    conclusion with confidence.

  6. #6
    Join Date
    Oct 2001
    Location
    Tennessee
    Posts
    922
    I'm confused. Did you post a link to that script and later remove it? I'm only able to go by fink's response here. Is that script attributed to Lockdown? If so, my comments apply.

    Now, what site did your friend go to?
    Last edited by JoJo Gunn; August 13th, 2002 at 06:41 PM.

  7. #7
    Join Date
    Jul 2002
    Location
    Collingwood, Ontario, Canada
    Posts
    1,104
    I removed the link for the lockdown browser security test, based on what I read, and what I experienced.

    The site my friend went to was:

    http://www.nessie.co.uk/
    ** **
    We use our powers for good, not evil

    ** **
    Logic is a systematic method of coming to the wrong
    conclusion with confidence.

  8. #8
    Join Date
    Feb 2001
    Location
    Adelaide, South Australia
    Posts
    6,447
    The patches on Windows Update only apply to IE, not Netscape. Historically though, Netscape has suffered from far fewer of that sort of exploit than IE, and in this case it appears that JS.Exception is an IE-only flaw.

    There's no point downloading 4.76 again. Netscape sometimes release a major security fix as a new minor version without actually telling anyone it's a security fix, but to my knowledge they've never tried to silently re-release a version.

  9. #9
    Join Date
    Jul 2002
    Location
    Collingwood, Ontario, Canada
    Posts
    1,104
    Spoke to my friend again and he is suddenly being flooded with spam, co-incident to the JS.Exploit(?). The wierd thing about it is that the spam he is receiving does not have his email address, in other words, he is receiving spam with other peoples email addresses.

    Could the Exploit have caused this? If so, how? Any ideas about how to correct this?
    ** **
    We use our powers for good, not evil

    ** **
    Logic is a systematic method of coming to the wrong
    conclusion with confidence.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •