Received: from SpoolDir by JASPIS (Mercury 1.48); 6 Mar 02 18:16:28 +0100 Return-path: Received: from cache-ov.ha-vel.cz (10.0.1.254) by spsch-ostrava.cz (Mercury 1.48) with ESMTP; 6 Mar 02 18:16:13 +0100 Received: from interval.cz (www.interval.cz [62.168.63.140]) by cache-ov.ha-vel.cz (8.11.6/8.11.6) with ESMTP id g26HEO621906; Wed, 6 Mar 2002 18:14:24 +0100 Received: from smtp1.vol.cz [195.250.128.73] by interval.cz with ESMTP (SMTPD32-7.05) id AF958800C0; Wed, 06 Mar 2002 18:19:17 +0100 Received: from karel (datela-1-3-3.dialup.vol.cz [212.20.97.149]) by smtp1.vol.cz (8.11.6/8.11.3) with SMTP id g26HDn059053 for ; Wed, 6 Mar 2002 18:13:49 +0100 (CET) (envelope-from ero.conf@atlas.cz) Message-ID: <001601c1c532$483edac0$956114d4@karel> From: "Erik WEBR" To: Subject: =?iso-8859-1?Q?OT:_Fw:_V_IE_je_dals=ED_nepr=EDjemn=E1_d=EDra_jako_hrom?= Date: Wed, 6 Mar 2002 01:43:50 +0100 MIME-Version: 1.0 boundary="----=_NextPart_000_017C_01C1C4B0.5DA3F940" X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 5.50.4133.2400 X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4133.2400 Precedence: bulk Sender: help-owner@interval.cz Reply-To: help@interval.cz Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable X-MIME-Autoconverted: from 8bit to quoted-printable by cache-ov.ha-vel.cz id g26HEO621906 preposilam... ----- Original Message ----- From: "tune.up" To: Sent: Tuesday, March 05, 2002 10:52 PM Subject: V IE je dals¡ nepr¡jemn  d¡ra jako hrom > V IE je dals¡ nepr¡jemn  d¡ra jako hrom Petr > > > Dnes, 5. brezna 2002, 09:11 Bezpecnost, Software > Pokud jste si mysleli, ze vypnut¡m ActiveX, vesker˜ch skriptovac¡ch > moznost¡ atd znemozn¡te napaden¡ vaseho Internet Exploreru, jste na omylu. > Byla totiz objevena chyba, kter  si i s t¡mto dovede poradit a velmi > jednoduch˜m kusem HTML k¢du spust¡ jak˜koliv program na vasem disku, za > predpokladu, ze zn  n zev spustiteln‚ho souboru. Postizeny jsou > pravdepodobne vsechny verze od IE 4. Probl‚m je detailne i s uk zkov˜m k¢dem > pops n v GreyMagic Security Advisory GM#001-IE. > > Tuto chybu lze (i kdyz obt¡zne a nepr¡jemne) zablokovat. Stac¡ si > spustit Editor registru (regedit.exe) a ve vetvi > "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet > Settings\Zones\0" ulozit do polozky "1004" hodnotu "3" (DWORD). Pak uz stac¡ > jen reboot. A pro jistotu je jeste vhodn‚ vl‚zt na v˜se zm¡nenou str nku a > ozkouset si dole odkaz Simple, ci Advanced. > > Update: V˜se zm¡nen˜ kl¡c v registrech je pouze u Windows NT, 2000 a > asi i XP. U Windows 9x mus¡te zmenu prov‚st v: > "HKEY_CURRENT_USER\Software\Microsoft\Windows\Internet Settings\Zones\0" > (chyb¡ tam to CurrentVersion). Ozkouset si to pak mus¡te tak, ze kliknete na > odkaz Advanced a tam si vloz¡te cestu na nejak˜ spustiteln˜ soubor na vasem > disku. > > > --- Nekter‚ soubory nebylo mozn‚ zkontrolovat Zkontrolov no antivirov˜m syst‚mem AVG (http://www.grisoft.cz). Verze: 6.0.324 / Virov  b ze: 181 - datum vyd n¡: 14.2.2002