Technical advice

User picture

New Firefox exploit from NET Framework SP

In case everyone hasn't read it yet; http://isc.sans.org/diary.html?storyid=7381
The newest patch from Microsoft's patch Tuesday, (MS09-054) installs a vulnerable plug-in in Firefox.

So just go to Firefox's add-ons, click plugins, then chose disable for the Windows Presentation Foundation plugin.

To get rid of the plugin (Unless I understood this wrong.) go to %SYSTEMDRIVE%\Windows\Microsoft.NET\Framework\v3.5\
and delete the folder named Windows Presentation Foundation.

User picture

oooh

Vista and lower, is what this advisory is for.

I am in Windows 7 (release), and I do not see the plugin in Firefox. :)

~DragonMaster Jay, malware researcher,
Admin, helpmyos.com

User picture

what about IE?

what about IE?

User picture

Here

Are the institutions to determine if you are affected, and how to fix the vulnerability in IE. http://securitygarden.blogspot.com/2009/10/ms09-05...

Hope that helps demonluo. :)

User picture

oh no...

Not security garden...

~DragonMaster Jay, malware researcher,
Admin, helpmyos.com

User picture

Why?

Why?

User picture

uhh..

See my comment: http://www.mywot.com/en/scorecard/securitygarden.b...

~DragonMaster Jay, malware researcher,
Admin, helpmyos.com

User picture

thanks for the links good

thanks for the links good info but r this site owner really deframe/mean to other since jpvip seem to know the site owner...

User picture

Thank you for the warning; I

Thank you for the warning; I have deleted the add-on. Hopefully the Mozilla staff will blacklist this soon.

User picture

What is WPF..?

What is this "Windows Presentation Foundation" supposed to do?

I suppose it has some kind of functionality,
but who needs it and who don't..?

User picture

...

WPF is a GUI rendering program for Windows-based programs.

@demonluo
Security Garden is owned by an MS-MVP Corrine. I have read some nasty reports she spills out. I have no idea why she gets so rash, but I guess that is her passion.

~DragonMaster Jay, malware researcher,
Admin, helpmyos.com

User picture

Firefox just blacklisted it,

Firefox just blacklisted it, along with the Microsoft .NET plugin.

User picture

lol

Good. I guess it was bad enough.

~DragonMaster Jay, malware researcher,
Admin, helpmyos.com

User picture

Yay

Firefox! Too bad I already got rid of it. :P

© WOT Services patent pending