GangsterBB.NET


Funko Pop! Movies: The Godfather
The Godfather PART II - NEW!

Who's Online Now
1 registered members (joepuzzles234), 980 guests, and 13 spiders.
Key: Admin, Global Mod, Mod
Shout Box
Site Links
>Help Page
>More Smilies
>GBB on Facebook
>Job Saver

>Godfather Website
>Scarface Website
>Mario Puzo Website
NEW!
Active Member Birthdays
No birthdays today
Newest Members
COresearcher, Batman, demonte41, JoeySarcs, legacyaustraliaKG
10381 Registered Users
Top Posters(All Time)
Irishman12 72,704
DE NIRO 45,099
J Geoff 31,330
Hollander 29,754
pizzaboy 23,296
SC 22,902
Turnbull 19,694
Mignon 19,066
Don Cardi 18,238
Sicilian Babe 17,300
plawrence 15,058
Forum Statistics
Forums21
Topics43,336
Posts1,085,984
Members10,381
Most Online1,182
4 minutes ago
Previous Thread
Next Thread
New Reply
Print Thread
GBB Drive-by Download? #600387
04/21/11 10:59 AM
04/21/11 10:59 AM
Joined: Nov 2002
Posts: 12,543
Gateshead, UK
Capo de La Cosa Nostra Offline OP
Capo de La Cosa Nostra  Offline OP

Joined: Nov 2002
Posts: 12,543
Gateshead, UK
Norton just picked up a Drive-by Download on this site is giving me a caution sign whenever I'm on here.

"A drive-by download is computer code that takes advantage of a software bug in a Web browser to make it do something that the attacker wants—such as run malicious code, crash the browser, or read data from the computer. Software bugs that are open to browser attacks are also known as vulnerabilities."

The threat name is

"MSIE ADODB.Stream Object File Installation Weakness"

This is how the rest of my Norton page reads:

Severity: High
This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.
Description
This signature detects attempts to exploit a remote code execution vulnerability using the RDS.DataSpace Objects.
Additional Information
Microsoft Data Access Components (MDAC) provide components for database access, including functionality for querying local and remote databases of various formats.

The MDAC RDS.Dataspace ActiveX control is prone to a remote code execution vulnerability. This issue exists because the control fails to behave securely when it is hosted on a web page. Sufficient restrictions are not placed on the control to prevent it from performing privileged actions when hosted remotely.

An attacker could exploit this issue to install programs, view, modify, or delete data, or create new user accounts on the computer.
Affected

* Hitachi DA Broker for ODBC 01-00, 01-02
* Hitachi DBPARTNER ODBC 01-00, 01-03, 01-06, 01-11
* Hitachi DBPARTNER2 Client 01-05, 01-12
* Hitachi HITSENSER5 01-00, 01-10, 02-80
* Microsoft MDAC 2.5 SP3, 2.7, 2.7 SP1, 2.8

Response
Workaround:
Microsoft has described various workarounds to help prevent exploitation. Please see the referenced security bulletin for more information.

Solution:
Windows 95/98/ME users should obtain fixes from the Windows Update website.

Fixes are available:

Microsoft MDAC 2.8.0 SP1:
Microsoft Patch Security Update for Windows XP (KB911562)
Microsoft Patch Security Update for Microsoft Data Access Components 2.8 Service Pack 1 (KB911562)


Microsoft MDAC 2.8.0 SP2:
Microsoft Patch Security Update for Windows XP x64 Edition (KB911562)
Microsoft Patch Security Update for Windows Server 2003 (KB911562)
Microsoft Patch Security Update for Windows Server 2003 for Itanium-based Systems (KB911562)
Microsoft Patch Security Update for Windows Server x64 Edition (KB911562)


Microsoft MDAC 2.5 SP3:
Microsoft Patch Security Update for Microsoft Data Access Components 2.5 Service Pack 3 (KB911562) - English


Microsoft MDAC 2.7 SP1:
Microsoft Patch Security Update for Windows XP (KB911562)
Microsoft Patch Security Update for Microsoft Data Access Components 2.7 Service Pack 1 (KB911562)


Microsoft MDAC 2.8 :
Microsoft Patch Security Update for Windows Server 2003 (KB911562)
Microsoft Patch Security Update for Windows Server 2003 for Itanium-based Systems (KB911562)
Microsoft Patch Security Update for Microsoft Data Access Components 2.8 (KB911562)

Additional References

* CVE-2006-0003
* CVE-2006-3510
* Vulnerability in the MDAC Function Could Allow Remote Code Execution
* Microsoft Security Bulletin MS06-014
* SecurityFocus BID: 10514
* SecurityFocus BID: 17462
* SecurityFocus BID: 18900


...dot com bold typeface rhetoric.
You go clickety click and get your head split.
'The hell you look like on a message board
Discussing whether or not the Brother is hardcore?
Reply Quote
Re: GBB Drive-by Download? [Re: Capo de La Cosa Nostra] #600389
04/21/11 11:01 AM
04/21/11 11:01 AM
Joined: Jul 2001
Posts: 22,902
New York
SC Offline
Consigliere
SC  Offline
Consigliere

Joined: Jul 2001
Posts: 22,902
New York
I made Geoff aware of this yesterday. I haven't heard back from him yet.

Thanks for posting this, Mick.


.
Reply Quote
Re: GBB Drive-by Download? [Re: Capo de La Cosa Nostra] #600396
04/21/11 11:56 AM
04/21/11 11:56 AM
Joined: Jul 2001
Posts: 31,330
New Jersey, USA
J Geoff Offline
The Don
J Geoff  Offline
The Don

Joined: Jul 2001
Posts: 31,330
New Jersey, USA

I have no idea how that'd be possible -- I'm not getting any warnings myself -- but I'll look into it, thanks...



I studied Italian for 2 semesters. Not once was a "C" pronounced as a "G", and never was a trailing "I" ignored! And I'm from Jersey! tongue lol

Whaddaya want me to do? Whack a guy? Off a guy? Whack off a guy? --Peter Griffin

My DVDs | Facebook | Godfather Filming Locations
Reply Quote
Re: GBB Drive-by Download? [Re: Capo de La Cosa Nostra] #600402
04/21/11 12:48 PM
04/21/11 12:48 PM
Joined: Feb 2003
Posts: 15,030
Texas
O
olivant Offline
olivant  Offline
O

Joined: Feb 2003
Posts: 15,030
Texas
I posted a few weeks ago that Avast gives me a malicious warning whenever I bring up this site. Maybe it's because of this.


"Generosity. That was my first mistake."
"Experience must be our only guide; reason may mislead us."
"Instagram is Twitter for people who can't read."
Reply Quote
Re: GBB Drive-by Download? [Re: Capo de La Cosa Nostra] #600436
04/21/11 04:49 PM
04/21/11 04:49 PM
Joined: Jul 2001
Posts: 31,330
New Jersey, USA
J Geoff Offline
The Don
J Geoff  Offline
The Don

Joined: Jul 2001
Posts: 31,330
New Jersey, USA

I don't see any reason for it confused



I studied Italian for 2 semesters. Not once was a "C" pronounced as a "G", and never was a trailing "I" ignored! And I'm from Jersey! tongue lol

Whaddaya want me to do? Whack a guy? Off a guy? Whack off a guy? --Peter Griffin

My DVDs | Facebook | Godfather Filming Locations
Reply Quote
Re: GBB Drive-by Download? [Re: J Geoff] #600441
04/21/11 05:00 PM
04/21/11 05:00 PM
Joined: Jul 2001
Posts: 22,902
New York
SC Offline
Consigliere
SC  Offline
Consigliere

Joined: Jul 2001
Posts: 22,902
New York
Do you use Norton??

I do, and that "warning" is still showing up on my pc. This and the main site are affected.(the Trilogy site)


.
Reply Quote
Re: GBB Drive-by Download? [Re: Capo de La Cosa Nostra] #600501
04/22/11 12:35 AM
04/22/11 12:35 AM
Joined: Jul 2001
Posts: 31,330
New Jersey, USA
J Geoff Offline
The Don
J Geoff  Offline
The Don

Joined: Jul 2001
Posts: 31,330
New Jersey, USA

No, I don't use Norton -- I HATE Norton and how it notoriously slows down every computer it infects -- but you're right, there were 2 files hacked into the GF site that didn't belong there. I didn't notice any on the BB, but I now will check again....



I studied Italian for 2 semesters. Not once was a "C" pronounced as a "G", and never was a trailing "I" ignored! And I'm from Jersey! tongue lol

Whaddaya want me to do? Whack a guy? Off a guy? Whack off a guy? --Peter Griffin

My DVDs | Facebook | Godfather Filming Locations
Reply Quote
Quick Reply

Options HTML is disabled
UBBCode is enabled


Moderated by  Don Cardi, J Geoff, SC, Turnbull 

Powered by UBB.threads™