That's so we know not to m3sS w1Th t3h b35T!Originally Posted by SassiAsura
That's so we know not to m3sS w1Th t3h b35T!Originally Posted by SassiAsura
Is it possible to be infected even if you don't use lolIE?
If you dont know the answer to that then I have to wonder why you think IE is so "lol"?
I'm just making sure![]()
YES it IS possible to get infected even if you AREN'T using IE.....
Just update your realplayer or uninstall it.
Also it's a good idea to get prompted for ActiveX scripts.
Pretty sure this has all been beaten to death though.![]()
looks to me like the code bails if it doesn't report a version of IE. makes sense as it draws from activex controls which obviously (and blissfully) do not operate under firefox.Originally Posted by PrincessMinnet
btw, is that executable code of some kind in that stringtable at the start? i thought it was nothing more than obfuscation at first (a very ugly way of trying to slip past a heuristic detection) but after looking into the exploit itself, the method it exploits only accepts caps/lower letters and numbers and only the last 6 entries of the stringtable appear to otherwise be used so i'm wondering if that may be the actual malicious code. yeah. i'm an amateur at this stuff at best, i'm aware. usually i just know enough to say something that sounds remotely smart but look stupid after someone who knows more shows up.
The malicious iframe may be gone, but the note on FFXI Atlas does not indicate that they have eliminated the vulnerability that was used to insert it in the first place.
How long until the official POL site gets done in? I'd like to see SE try to deal with the damage that would cause.
(on a random note, I feel like a dumbass for having NoScript installed but had IFRAMEs allowed)
why would that be bad? i mean who visits the PoL site except at patch time?Originally Posted by Kaisha
What if they were actually timing one for patch time?Originally Posted by Spekkio
If there's 5000 some infected FFXI players that have an outdated RealPlayer installed, pretty sure there's still a lot more.
I'm also guilty for visiting the POL site each day, waiting on them to start the bloody teaser announcement for the next content update.
Originally Posted by evilpaul
considering that it's a realplayer exploit, no, you can't be affected by it. still, you never know when their next attack will use something more commonly distributed (i won't even begin to list the juicy targets *cough*quicktime*cough*) so firefox+noscript=goodness.Originally Posted by ferigor
look forward to this in march ;3Originally Posted by Kaisha
AV video coming 2009
fixdOriginally Posted by LinktheDeme
How does one get this NoScript plugin for firefox?
http://www.google.com/search?rls=en&q=noscript+firefoxOriginally Posted by Rehn
https://addons.mozilla.org/en-US/firefox/addon/722Originally Posted by Rehn
Get used to having to whitelist your usual trusted sites for the first while before it becomes handy.
(that combined with Ad-Block+ & Filterset.G are godly for killing off ads)
[EDIT] Damnit, beat by Buttson.
(didn't even get that 'someone posted while you were typing' re-direct either)
By default iframes are allowed in no script after you install it. You have go to the options check the box to forbid iframes.
Stop using MSIE >_>.