<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" media="screen" href="/styles/xslt/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:c9="http://channel9.msdn.com">
<channel>
	<title>Channel 9 Forums - Coffeehouse - Crashes with animated cursors. What the hell?</title>
	<atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/Forums/rss"></atom:link>
	<image>
		<url>http://mschnlnine.vo.llnwd.net/d1/Dev/App_Themes/C9/images/feedimage.png</url>
		<title>Channel 9 Forums - Coffeehouse - Crashes with animated cursors. What the hell?</title>
		<link>http://channel9.msdn.com/Forums</link>
	</image>
	<description>Channel 9 keeps you up to date with the latest news and behind the scenes info from Microsoft that developers love to keep up with. From LINQ to SilverLight – Watch videos and hear about all the cool technologies coming and the people behind them.</description>
	<link>http://channel9.msdn.com/Forums</link>
	<language>en</language>
	<pubDate>Sun, 26 May 2013 00:36:42 GMT</pubDate>
	<lastBuildDate>Sun, 26 May 2013 00:36:42 GMT</lastBuildDate>
	<generator>Rev9</generator>
	<c9:totalResults>10</c9:totalResults>
	<c9:pageCount>-10</c9:pageCount>
	<c9:pageSize>-1</c9:pageSize>
	<item>
		<title>Coffeehouse - Crashes with animated cursors. What the hell?</title>
		<description><![CDATA[<p><div align="center"><font size="3"><a href="http://www.avertlabs.com/research/blog/?p=233">Don't drag&amp;drop an animated cursor over me, I could stop responding!</a></font><br>
</div></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/253605#253605</link>
		<pubDate>Fri, 30 Mar 2007 08:33:23 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/253605#253605</guid>
		<dc:creator>YearOfTheLinuxDesktop</dc:creator>
		<slash:comments>10</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/YearOfTheLinuxDesktop/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Crashes with animated cursors. What the hell?</title>
		<description><![CDATA[<p><blockquote>
<div>YearOfTheLinuxDesktop wrote:</div>
<div>&#65279;
<div><a href="http://www.avertlabs.com/research/blog/?p=233">Don't drag&amp;drop an animated cursor over me, I could stop responding!</a><br>
</div>
</div>
</blockquote>
<br>
<br>
Well that is quite simply .... unbelievable.<br>
<br>
So a drive-by click managed to crash Vista? <br>
<br>
So what happened to all that stuff about a vulnerability not propogating down through the layers?
<br>
<br>
Unbelievable, but I think I already said that.<br>
<br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/66cbf1b4422d43638c299dec006b86a0#66cbf1b4422d43638c299dec006b86a0</link>
		<pubDate>Fri, 30 Mar 2007 10:30:36 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/66cbf1b4422d43638c299dec006b86a0#66cbf1b4422d43638c299dec006b86a0</guid>
		<dc:creator>Ray6</dc:creator>
		<slash:comments>10</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Ray6/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Crashes with animated cursors. What the hell?</title>
		<description><![CDATA[<p>I have to say I'm puzzled by a) how they managed to get it to crash like that (assuming all default settings and considering MS quotes below) b) why the email html preview is affected but IE7 in protected mode is not? (why doesn't protected mode apply to
 email viewing, it's still html?)<br>
<br>
Couple select quotes from <a href="http://www.microsoft.com/technet/security/advisory/935423.mspx">
http://www.microsoft.com/technet/security/advisory/935423.mspx</a><br>
<br>
<br>
&quot;Customers who are using Internet Explorer 7 on Windows Vista are protected from currently known web based attacks due to Internet Explorer 7.0 protected mode&quot;<br>
<br>
This one is weird:<br>
<br>
&quot;By default, Outlook 2007 uses Microsoft Word to display e-mail messages which protects customers from the HTML e-mail preview and attack vector&quot;<br>
<br>
So now viewing stuff in Word protects in this case? One would figure that Word would have more features and thus bugs.<br>
<br>
<br>
&quot;Reading e-mail in plain text on Outlook Express does not mitigate attempts to exploit this vulnerability&quot;<br>
<br>
Ouch. This one is surprising. I'd like to ask, how the hel* does the cursor get past that automatically or is there some user action still required?<br>
<br>
<br>
</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/88d5bad6fb9c48d885339dec006b86ce#88d5bad6fb9c48d885339dec006b86ce</link>
		<pubDate>Fri, 30 Mar 2007 17:04:57 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/88d5bad6fb9c48d885339dec006b86ce#88d5bad6fb9c48d885339dec006b86ce</guid>
		<dc:creator>androidi</dc:creator>
		<slash:comments>10</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/androidi/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Crashes with animated cursors. What the hell?</title>
		<description><![CDATA[<p>I hope c9 doesnt start using animated cursors.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/72d13aa8cad541f9a13c9dec006b86f6#72d13aa8cad541f9a13c9dec006b86f6</link>
		<pubDate>Fri, 30 Mar 2007 17:08:26 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/72d13aa8cad541f9a13c9dec006b86f6#72d13aa8cad541f9a13c9dec006b86f6</guid>
		<dc:creator>harumscarum</dc:creator>
		<slash:comments>10</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/harumscarum/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Crashes with animated cursors. What the hell?</title>
		<description><![CDATA[<p><blockquote>
<div>androidi wrote:</div>
<div>&#65279;
<p>I have to say I'm puzzled by a) how they managed to get it to crash like that (assuming all default settings and considering MS quotes below) b) why the email html preview is affected but IE7 in protected mode is not? (why doesn't protected mode apply to
 email viewing, it's still html?)<br>
<br>
Couple select quotes from <a href="http://www.microsoft.com/technet/security/advisory/935423.mspx">
http://www.microsoft.com/technet/security/advisory/935423.mspx</a><br>
<br>
<br>
&quot;Customers who are using Internet Explorer 7 on Windows Vista are protected from currently known web based attacks due to Internet Explorer 7.0 protected mode&quot;<br>
<br>
This one is weird:<br>
<br>
&quot;By default, Outlook 2007 uses Microsoft Word to display e-mail messages which protects customers from the HTML e-mail preview and attack vector&quot;<br>
<br>
So now viewing stuff in Word protects in this case? One would figure that Word would have more features and thus bugs.<br>
<br>
<br>
&quot;Reading e-mail in plain text on Outlook Express does not mitigate attempts to exploit this vulnerability&quot;<br>
<br>
Ouch. This one is surprising. I'd like to ask, how the hel* does the cursor get past that automatically or is there some user action still required?<br>
<br>
<br>
</p>
</div>
</blockquote>
<br>
<br>
It sounds like the bug works like this:<br>
<br>
Animated cursors (*.ani) show a preview of the cursor as the icon in Windows Explorer.&nbsp; So, when a malformed animated cursor is placed on the desktop (and probably any other folder), it causes Explorer to stop responding while it attempts to draw the animated
 cursor as the icon for the file.<br>
<br>
There's no way this attack could be automated (unless your email client lets files automatically be downloaded to the desktop).&nbsp; The cursor file could only end up on&nbsp;the desktop (triggering this bug) if the user decided to download the file, which could be
 an email&nbsp;attachment or a file downloaded from the web.&nbsp; If it's in an email attachment, it doesn't matter whether you're using HTML mail or not, you can still download the attachment.<br>
<br>
It all boils down to not downloading files from untrusted sources--&nbsp; if you follow that rule, you're fine.<br>
<br>
[edit] It appears that this can also be exploited when an HTML page includes a malformed cursor file as well...&nbsp; that's why IE7 isn't affected in Protected Mode.&nbsp; Word's HTML viewing prevents this bug from being exploited because it's
<strong>not</strong> a full featured HTML viewer--&nbsp; it can't use an animated cursor included in a webpage.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/9f4f0d8f38c942f3b1829dec006b872b#9f4f0d8f38c942f3b1829dec006b872b</link>
		<pubDate>Fri, 30 Mar 2007 17:52:18 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/9f4f0d8f38c942f3b1829dec006b872b#9f4f0d8f38c942f3b1829dec006b872b</guid>
		<dc:creator>JonathonW</dc:creator>
		<slash:comments>10</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/CannotResolveSymbol/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Crashes with animated cursors. What the hell?</title>
		<description><![CDATA[<p><blockquote>
<div>CannotResolveSymbol wrote:</div>
<div>&#65279;<br>
[edit] It appears that this can also be exploited when an HTML page includes a malformed cursor file as well...&nbsp; that's why IE7 isn't affected in Protected Mode.&nbsp; Word's HTML viewing prevents this bug from being exploited because it's
<strong>not</strong> a full featured HTML viewer--&nbsp; it can't use an animated cursor included in a webpage.</div>
</blockquote>
<br>
<br>
&quot;Reading e-mail in plain text on Outlook Express does not mitigate attempts to exploit this vulnerability&quot;<br>
<br>
Assuming you're right it still doesn't explain the above quote. How come Word's HTML viewing prevents but a plain text (no html parsing) doesn't? It just doesn't make any sense assuming the bug can be exploited just by opening the mail in plain text and not
 clicking some .ani attachment or stuff.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/8416cbf375c2494b933f9dec006b8757#8416cbf375c2494b933f9dec006b8757</link>
		<pubDate>Fri, 30 Mar 2007 19:44:04 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/8416cbf375c2494b933f9dec006b8757#8416cbf375c2494b933f9dec006b8757</guid>
		<dc:creator>androidi</dc:creator>
		<slash:comments>10</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/androidi/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Crashes with animated cursors. What the hell?</title>
		<description><![CDATA[<p>an unofficial patch for this bug came out <a href="http://www.betanews.com/article/3rd_Party_Patches_Critical_Windows_Flaw/1175279785">
just today</a>.<br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/e04bf0a86ecd4181b8209dec006b8782#e04bf0a86ecd4181b8209dec006b8782</link>
		<pubDate>Fri, 30 Mar 2007 20:34:22 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/e04bf0a86ecd4181b8209dec006b8782#e04bf0a86ecd4181b8209dec006b8782</guid>
		<dc:creator>YearOfTheLinuxDesktop</dc:creator>
		<slash:comments>10</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/YearOfTheLinuxDesktop/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Crashes with animated cursors. What the hell?</title>
		<description><![CDATA[<p>if I remember the article it says that it's a malformed ani file. So the file is corrupt in the first place.<br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/361ba5a327ff4d40892c9dec006b87ab#361ba5a327ff4d40892c9dec006b87ab</link>
		<pubDate>Fri, 30 Mar 2007 21:58:30 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/361ba5a327ff4d40892c9dec006b87ab#361ba5a327ff4d40892c9dec006b87ab</guid>
		<dc:creator>Cybermagellan</dc:creator>
		<slash:comments>10</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Cybermagellan/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Crashes with animated cursors. What the hell?</title>
		<description><![CDATA[<p>Man, if you can't trust the little walking dinosaur and the drum to not crash your machine, who can you trust?<br></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/b4c593e9667742aebb279dec006b87d5#b4c593e9667742aebb279dec006b87d5</link>
		<pubDate>Fri, 30 Mar 2007 22:06:01 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/b4c593e9667742aebb279dec006b87d5#b4c593e9667742aebb279dec006b87d5</guid>
		<dc:creator>Lazycoder2</dc:creator>
		<slash:comments>10</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Lazycoder2/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - Crashes with animated cursors. What the hell?</title>
		<description><![CDATA[<p>Well, looks like the patch is <a href="http://news.com.com/Microsoft&#43;to&#43;issue&#43;cursor&#43;flaw&#43;patch&#43;early/2100-1002_3-6172364.html">
getting released early</a>.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/8ab8bf30aee44a309df09dec006b8800#8ab8bf30aee44a309df09dec006b8800</link>
		<pubDate>Mon, 02 Apr 2007 08:47:08 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/253605-Crashes-with-animated-cursors-What-the-hell/8ab8bf30aee44a309df09dec006b8800#8ab8bf30aee44a309df09dec006b8800</guid>
		<dc:creator>Bas</dc:creator>
		<slash:comments>10</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Bas/Discussions/RSS</wfw:commentRss>
	</item>
</channel>
</rss>