Re: Encrypted javascript on probable virus page



"Virus Guy" wrote:

Not sure what this is all about. I only get this behavior with IE6.
It doesn't do this (display message) with firefox or an old version of
Netscape.

I believe ActiveX is only supported by MSIE.

This is probably attempting to exploit a known IE (IE6?) bug - anyone
know which one?

Several; most or all of which should be now patched. You're taking a
big risk following these kind of links with IE, or even any other
standard browser. You should use wget or some other utility to fetch
the raw unrendered page.

Are there any on-line javascript de-obfuscators?

The unscrambling routine is in the script so you can do it yourself.

[fncarp.com]

Well - you get the idea. A different IP every time you look it up

It's a fast-flux botnet. The domain has a TTL (time to live) of zero
seconds, the name servers somewhat longer of two days. All the IP
addresses (hosts and name servers) point to compromised machines on
various networks.


.



Relevant Pages

  • [NEWS] Netscape ?wp-html-rend Denial of Service Attack
    ... Remote attackers can easily perform a denial of service attack on Netscape ... Enterprise servers running with Windows NT. ... Netscape Enterprise has a selection of ?wp-* (Web publishing) commands ...
    (Securiteam)
  • Windows Server 2008, TS Web Access: Problems with ActiveX
    ... I am running a TS Web Access with TS Gateway as a front-end for my back-end Windows Server 2008 terminal servers. ... The Terminal Services ActiveX Client control is not available. ... Before you can access remote programs and connect to remote desktops through TS Web Access, you must install and enable this ActiveX control. ...
    (microsoft.public.windows.terminal_services)
  • Re: maximum length for $_GET
    ... It's Microsofts own limitation on MSIE, you can find it on their site. ... MS seems to be the lowest of the bunch (UA's, servers). ... Possibly there are UA's with an even lower limitation, ... file upload by GET is something to run away from immediately. ...
    (alt.php)
  • Re: maximum length for $_GET
    ... It's Microsofts own limitation on MSIE, you can find it on their site. ... MS seems to be the lowest of the bunch (UA's, servers). ... Possibly there are UA's with an even lower limitation, ... file upload by GET is something to run away from immediately. ...
    (alt.php)
  • Re: Whats your computers name? [OT]
    ... > netscape, had apache going, at least locally (I think I ... part time job - thunder, ... servers at work: tealc and will be two more, ...
    (comp.os.linux.networking)