MSIE 5.5/6 Q312461 patch disclose patch information

From: KOJIMA Hajime (kjmat_private)
Date: Sun Nov 18 2001 - 18:57:15 PST

  • Next message: 18C3 Crew: "CfP: 18th annual Chaos Communication Congress, Berlin, Germany"

      If you apply Q312461 (MS01-055) patch to your IE 5.5 SP2 / 6, 
      your IE shows patch information into HTTP_USER_AGENT as:
    
      IE 6:
        Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; Q312461)
      IE 5.5 SP2:
        Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0; T312461)
    
      You can find vulnerable IE 5.5/6 very easily...
    
    What's this?
    ------------
    
      It's registry entry, at:
    
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform
    
    Tested
    ------
    
    * Windows 2000 SP2 (japanese) + IE 5.5 SP2 (japanese) + Q312461 (japanese)
    * Windows 2000 SP2 (japanese) + IE 6 (japanese) + Q312461 (japanese)
    
    1st reported by
    ---------------
    
      SUZUKI, Kazuhiro
      http://memo.st.ryukoku.ac.jp/archive/200111.month/1890.html
      (caution: this URL is written in Japanese)
    
    ----
    KOJIMA Hajime - Ryukoku University, Seta, Ootsu, Shiga, 520-2194 Japan
    [Office] kjmat_private, http://www.st.ryukoku.ac.jp/~kjm/
    



    This archive was generated by hypermail 2b30 : Mon Nov 19 2001 - 12:28:39 PST