Jump to content
SAU Community

Recommended Posts

Another one here for a whole lot of characters appearing when clicking on an image.

Also noticed when i first logged in today this site wanted to install an Active X control, some Microsoft Data something or other. I didnt install it as i didnt see a notice to say that it was okay to run on the bulletin board.

Some of the fonts are showing up larger than they usually do aswell

Are these related?

I still can't upload images into private messages.

I browse, double click and the image name appears but when I ckick on add attachment it goes to a blank page rather than show the attachment in the pm.

Anyone else have this problem or have I picked up a virus or something?

i stil cant upload, and now i cant even login to msn.. that dsb.exe must have infected my pc, and now i feel like taking SAU to court.. :\

lol, if you read the conditions when you join the site there is a bit in there about SAU not being liable for such actions as you should have adequate protection.

lol, if you read the conditions when you join the site there is a bit in there about SAU not being liable for such actions as you should have adequate protection.

im just mucking around, relax.. but i suggest u get someone to fix this crap.. the exploit is still there..

We realise there is an issue.

Its a lot harder to fix something than you realise because there are limited people with access.

And the people with access are busy, they have thier own personal lives as SAU Admins/Mods are unpaid...

If your own PC is correctly protected then you wont have an issue.

Please be patient. Constantly posting about the fact it isnt fixed, simply is not going to help the issue especially when your not even a donor :D

For the exploit to work it *needs* Microsoft XML Core Services to be installed. Microsoft XML Core Services are not installed by default on Windows XP, but there seems to be a lot of packages using it, Visual Studio appears to be one common one. You can check in the Add or Remove Programs applet if you have it installed.

> The exploit works in both IE6 and IE7, which makes sense since it's exploiting a vulnerability in an ActiveX object, not in the browser itself. When executed the exploit creates an MSXML 4.0 ActiveX object (88d969c5-f192-11d4-a65f-0040963251e5). It then uses multiple setRequestHeader() method calls to execute shellcode which is included with the exploit. Once executed the shellcode (of course) first downloads the first stage downloader. At the moment it's a file called tester.dat:

16ac9982d177a47a20c4717183493e95 tester.dat

This downloader then downloads subsequent files (yet to be analysed). It looks like some AV vendors are beggining to detect the exploit. At this moment it is being detected by McAfee as Exploit-XMLCoreSrvcs and Symantec as Bloodhound.Exploit.96*. Microsoft also detects it as Exploit:HTML/Xmlreq.A. The best protection, is to prevent the XMLHTTP 4.0 ActiveX Control from running in Internet Explorer, as stated in Microsoft's advisory: http://www.microsoft.com/technet/security/...ory/927892.mspx ."

* http://www.symantec.com/security_response/...-110611-5730-99

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


  • Similar Content

  • Latest Posts

    • But seriously, can we ask for the results of the "tip a bottle of metho into a nearly empty tank" experiment?
    • Hang on. Let me get this straight. The desire is to have coilovers, BC in particular, to be MORE comfortable on Sydney roads than stock suspension? Well, that's obviously not right. BCs have crude damping design at the very best, and typically hard spring rates. BC stands for Billy Cart. And then, the desire is to put in some shitty old worn out stockers, to get it blue slipped and then put the BCs back in? And then.....what? Not worry about getting pulled up by the Plod? Because you seem to have raised a worry about paying for engineering (which actually does solve all your legality problems) and still getting pulled up.... but the only problem there is that if/when that happens you have to show your paperwork at the inspection station. Whereas, if you just swap in borrowed shitty old stockers to get it slipped now, and then you get defected in the future, you have to go find more shitty old stockers then too. You course of action looks like this set of options: Buy brand new stock type dampers, and springs. probably cost a bit more than $1k all up, but will last for the remaining life of the car. Put them in, pass inspection, drive on them forever more. Hell, they could even be really nice Bilsteins and Kings or other lower&stiffer springs if you wanted. Get the car engineered as is. ~$1k. Buy new Shockworks coilvers (or MCA) and also pay for engineering. You're spending a lot more here. But these will be the best things that you could drive around on.
    • Might be worthwhile hitting up Facebook's groups, I know most of them contain terrible people and scammers - however you might be able to find someone that's in Sydney with factory suspension you could purchase and/or hire. Just do not send any form of money anywhere, in person cash only.
    • Thanks @Duncan Ride height is fine. I think it's almost stock tbh. Happy to share a pic. I don't actually have a regular mechanic as haven't lived in Sydney too long. Could you or anyone recommend any shops in Sydney?
×
×
  • Create New...