Hello All,
MS Security Essentials recently flagged this twice on my laptop. Curious if this exploit falls soley under the realm of AV software or is something NoScript could eventually stop?
Thanks
Win 7 Home Premium, FFox 3.6.3, NoScript 1.9.9.81, plus additional stuff
Exploit:HTML/IframeRef.gen
Exploit:HTML/IframeRef.gen
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
- Giorgio Maone
- Site Admin
- Posts: 9524
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: Exploit:HTML/IframeRef.gen
From http://www.microsoft.com/security/porta ... ameRef.gen :
Since exploitation in 99.9% of the cases involves running JavaScript or active plugin content, NoScript will block this class of attacks even if the antivirus fails at blocking it at the proxy level because the serving site is too "new" to be listed in the blacklist.
This means that this is a generic signature for IFrames whose src attribute matches a blacklist of known malicious web sites serving payloads which exploit browser or plugin vulnerabilities.Microsoft wrote: Exploit:HTML/IframeRef.gen is generic detection for specially formed IFrame tags that point to remote Web sites containing malicious content, for example malicious Javascript containing an exploit for a specific vulnerability.
Since exploitation in 99.9% of the cases involves running JavaScript or active plugin content, NoScript will block this class of attacks even if the antivirus fails at blocking it at the proxy level because the serving site is too "new" to be listed in the blacklist.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
Re: Exploit:HTML/IframeRef.gen
Should forbid IFRAME option be enabled in Noscript to prevent this Exploit, or will it be prevented by default?
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
-
- Ambassador
- Posts: 1586
- Joined: Fri Mar 20, 2009 4:47 am
- Location: Colorado, USA
Re: Exploit:HTML/IframeRef.gen
Not necessary. JavaScript and active plugin content are blocked by default.eradic8 wrote:Should forbid IFRAME option be enabled in Noscript to prevent this Exploit, or will it be prevented by default?
Giorgio Maone wrote:Since exploitation in 99.9% of the cases involves running JavaScript or active plugin content, NoScript will block this class of attacks...
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.4) Gecko/20100527 Firefox/3.6.4