July 11, 200917 yr There are 8 more KILLBIT entries included in this REG file than in the one Queue posted...Yea I saw those too, but for some reason the MSI does not add them when it installs
July 12, 200917 yr Why are there so many CLSID's?If we're dealing with just one control, why not just one CLSID kill-bit entry?Probably lots of different versions, or the control has a lot of entry points (each exposed COM interface needs a class ID).
July 28, 200917 yr Killbits are dead : http://www.hustlelabs.com/bh2009preview/Bottom line, don't use IE, or any app that embeds its runtime, for going online.
July 28, 200917 yr That is what would be considered a knee-jerk reaction. The severity of their killbit bypass isn't clear, nor is it (currently) seeing wide-spread exploitation, nor is it known if it affects 9x systems.Queue
July 28, 200917 yr Wow, yeah, I guess that's what today's out-of-band Microsoft security updates were for (to fix killbits).
July 28, 200917 yr Killbits are dead : http://www.hustlelabs.com/bh2009preview/Bottom line, don't use IE, or any app that embeds its runtime, for going online.Wow, way to jump to conclusions. Want a mat? The vulnerability is in the ATL code used when building COM components in Visual Studio (all the way back to VC6), not IE - the fix is so that IE won't load any controls that ARE vulnerable. Note that any application that loads C/C++ code built with ATL that is vulnerable, is vulnerable.
Create an account or sign in to comment