<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sister CISA CISSP &#187; Heads Up</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/cisa-cissp/tag/heads-up/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/cisa-cissp</link>
	<description></description>
	<lastBuildDate>Tue, 19 Oct 2010 17:25:29 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>I.E. Help Files and F1 Function Key = Vulnerability</title>
		<link>http://itknowledgeexchange.techtarget.com/cisa-cissp/ie-help-files-and-f1-function-key-vulnerability/</link>
		<comments>http://itknowledgeexchange.techtarget.com/cisa-cissp/ie-help-files-and-f1-function-key-vulnerability/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 18:18:11 +0000</pubDate>
		<dc:creator>Arian Eigen Heald</dc:creator>
				<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Heads Up]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[programming]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/cisa-cissp/?p=982</guid>
		<description><![CDATA[A new alert came out from Microsoft on March 1st. When a user is online with Internet Explorer, they have to press the F1 function key when a pop-up is displayed. Not that users commonly use this key in IE, but some may do so when invited to by malware masquerading as a help file. [...]]]></description>
				<content:encoded><![CDATA[<p>A new alert came out <a href="http://www.microsoft.com/technet/security/advisory/981169.mspx">from Microsoft</a> on March 1st. </p>
<p>When a user is online with Internet Explorer, they have to press the F1 function key when a pop-up is displayed. Not that users commonly use this key in IE, but some may do so when invited to by malware masquerading as a help file.</p>
<p>Microsoft is not being very specific, probably because they don&#8217;t have a patch yet.</p>
<p>According to the <a href="http://isec.pl/vulnerabilities/isec-0027-msgbox-helpfile-ie.txt">firm that discovered the vulnerability, </a>&#8220;It is possible to invoke winhlp32.exe from Internet Explorer 8,7,6 using VBScript.&#8221;</p>
<p>The newer Microsoft OSes are not affected by this &#8220;feature,&#8221; but if you are using Microsoft Windows 2000, Windows XP, and Windows Server 2003, it&#8217;s worthwhile alerting your users. </p>
<p>In terms of IE version, all are vulnerable, so you can guess that it is more specific to the OS than the IE version.</p>
<p>Of course, if your users are not running their machines with administrator rights, you&#8217;re in much better shape.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/cisa-cissp/ie-help-files-and-f1-function-key-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
