Exploit:HTML/IframeRef.gen

General discussion about the NoScript extension for Firefox
Post Reply
Scott(0)
Posts: 4
Joined: Fri Jun 04, 2010 8:08 pm

Exploit:HTML/IframeRef.gen

Post by Scott(0) »

Hello All,

MS Security Essentials recently flagged this twice on my laptop. Curious if this exploit falls soley under the realm of AV software or is something NoScript could eventually stop?

Thanks

Win 7 Home Premium, FFox 3.6.3, NoScript 1.9.9.81, plus additional stuff
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
User avatar
Giorgio Maone
Site Admin
Posts: 9524
Joined: Wed Mar 18, 2009 11:22 pm
Location: Palermo - Italy
Contact:

Re: Exploit:HTML/IframeRef.gen

Post by Giorgio Maone »

From http://www.microsoft.com/security/porta ... ameRef.gen :
Microsoft wrote: Exploit:HTML/IframeRef.gen is generic detection for specially formed IFrame tags that point to remote Web sites containing malicious content, for example malicious Javascript containing an exploit for a specific vulnerability.
This means that this is a generic signature for IFrames whose src attribute matches a blacklist of known malicious web sites serving payloads which exploit browser or plugin vulnerabilities.
Since exploitation in 99.9% of the cases involves running JavaScript or active plugin content, NoScript will block this class of attacks even if the antivirus fails at blocking it at the proxy level because the serving site is too "new" to be listed in the blacklist.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
eradic8
Senior Member
Posts: 67
Joined: Wed Aug 26, 2009 11:43 am

Re: Exploit:HTML/IframeRef.gen

Post by eradic8 »

Should forbid IFRAME option be enabled in Noscript to prevent this Exploit, or will it be prevented by default?
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
Alan Baxter
Ambassador
Posts: 1586
Joined: Fri Mar 20, 2009 4:47 am
Location: Colorado, USA

Re: Exploit:HTML/IframeRef.gen

Post by Alan Baxter »

eradic8 wrote:Should forbid IFRAME option be enabled in Noscript to prevent this Exploit, or will it be prevented by default?
Not necessary. JavaScript and active plugin content are blocked by default.
Giorgio Maone wrote:Since exploitation in 99.9% of the cases involves running JavaScript or active plugin content, NoScript will block this class of attacks...
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.4) Gecko/20100527 Firefox/3.6.4
Post Reply