Windows XP users: Don't press F1

来源: stillthere 2010-03-04 08:35:05 [] [博客] [旧帖] [给我悄悄话] 本文已被阅读: 次 (2947 bytes)


By Christopher Null

If you're browsing the web today and see a notice that you should press the F1 key (the traditional button used to get "help" in any application), don't do it.

Microsoft is warning of a brand new exploit that can cause computers running Windows XP and using the Internet Explorer web browser to become infected with malware at the push of a button: Specifically, the F1 button.

The flaw is part of the way Visual Basic and Windows Help are implemented within IE, the upshot being that a clever hacker can code a dialog box that will allow the running of any code the hacker wants. Traditionally this means installing any kind of malware or virus on the victim's PC that a hacker desires.

The good news is that this exploit isn't extremely dangerous because it does require user interaction to install itself. Unlike some recent exploits, merely visiting an infected website won't cause harm to your computer: You actually have to "push a button" to be affected.

The bad news is that the F1 button has always been seen as harmless, more so than simply clicking "OK" on the average prompt you might see. When dismissed, the prompt can also be coded to pop up repeatedly, so getting rid of it might not be simple.

Microsoft is advising users that, until a patch can be written and released, users are advised not to press the F1 key while web browsing. No matter how many pop-ups and alerts a user receives, as long as F1 is not pressed this attack will not succeed.

Microsoft has not announced a timeline for the fix, but its next patch release is due on March 9. Hang tight, but don't ask for "help."


http://ca.tech.yahoo.com/blogs/the_working_guy/rss/article/4373



请阅读更多我的博客文章>>>
  • 刘希凡:敬畏自然,崇拜自然,游戏自然
  • 鼓浪屿游记
  • 虎年骑车虎虎生威
  • Future Earth 2025
  • 李富玉:自行车界的姚明
  • 请您先登陆,再发跟帖!

    发现Adblock插件

    如要继续浏览
    请支持本站 请务必在本站关闭/移除任何Adblock

    关闭Adblock后 请点击

    请参考如何关闭Adblock/Adblock plus

    安装Adblock plus用户请点击浏览器图标
    选择“Disable on www.wenxuecity.com”

    安装Adblock用户请点击图标
    选择“don't run on pages on this domain”