Expeditions: Samurai veut révolutionner le RPG tactique avec une aventure entièrement jouable en coop
¥ÝÝÝÛÛÚØÕÐÏÌɇ†‰ˆˆ„ƒƒ‚€`@ ! # ca prends les caraxctères UNICODE mainte ce site ? ?
alerte ke j´ai eu perso ded bill ! !!
Erreur! Nom du fichier non spécifié.
TechNet Home > Security > BulletinsErreur! Référence de lien hypertexte non valide.
Microsoft Security Bulletin MS02-047 Print
Cumulative Patch for Internet Explorer (Q323759)
Originally posted: August 22, 2002
Summary
Who should read this bulletin: Customers using Microsoft® Internet Explorer
Impact of vulnerability: Six new vulnerabilities, the most serious of which could enable an attacker to execute commands on a user’s system.
Maximum Severity Rating: Critical
Recommendation: Customers should install the patch immediately.
Affected Software:
Microsoft Internet Explorer 5.01
Microsoft Internet Explorer 5.5
Microsoft Internet Explorer 6.0
Technical details
Technical description:
This is a cumulative patch that includes the functionality of all previously released patches for IE 5.01, 5.5 and 6.0. In addition, it eliminates the following six newly discovered vulnerabilities:
A buffer overrun vulnerability affecting the Gopher protocol handler. This vulnerability was originally discussed in Microsoft Security Bulletin MS02-027, which provided workaround instructions while the patch provided here was being completed.
A buffer overrun vulnerability affecting an ActiveX control used to display specially formatted text. The control contains a buffer overrun vulnerability that could enable an attacker to run code on a user’s system in the context of the user.
A vulnerability involving how Internet Explorer handles an HTML directive that displays XML data. By design, the directive should only allow XML data from the web site itself to be displayed. However, it does not correctly check for the case where a referenced XML data source is in fact redirected to a data source in a different domain. This flaw could enable an attacker’s web page to open an XML-based files residing a remote system within a browser window that the site could read, thereby enabling the attacker to read contents from websites that users had access to but the attacker was not able to navigate to.
A vulnerability involving how Internet Explorer represents the origin of a file in the File Download Dialogue box. This flaw could enable an attacker to misrepresent the source of a file offered for download in an attempt to fool users into accepting a file download from an untrusted source believing it to be coming from a trusted source.
A Cross Domain verification vulnerability that occurs because of improper domain checking in conjunction with the Object tag. As a result, the vulnerability could enable a malicious web site operator to access data across different domains, for example one in a web site’s domain and the other on the user’s local file system and then pass information from the latter to the former. This could enable the web site operator to read, but not change, any file on the user’s local computer that could be viewed n a browser window. In addition, this can also enable an attacker to invoke, but not pass parameters to, an executable on the local system, much like the "Local Executable Invocation via Object tag" vulnerability discussed in MS02-015.
A newly reported variant of the "Cross-Site Scripting in Local HTML Resource" vulnerability originally discussed in Microsoft Security Bulletin MS02-023. Like the original vulnerability, this variant could enable an attacker to create a web page that, when opened, would run in the Local Computer zone, allowing it to run with fewer restrictions than it would in the Internet Zone.
In addition, the patch sets the Kill Bit on the MSN Chat ActiveX control discussed in Microsoft Security Bulletin MS02-022 as well as the TSAC ActiveX control discussed in Microsoft Security Bulletin MS02-046. This has been done to ensure that vulnerable controls cannot be introduced onto users’ systems. Customers who use the MSN Chat control should ensure that they have applied the updated version of the control discussed in MS02-022 and customers who use the TSAC control should ensure that they have applied the updated version of the control discussed in MS02-046 .
Mitigating factors:
Buffer Overrun in Gopher Protocol Handler:
The vulnerability would provide the attacker with user’s own privileges on the system. Customers who run with fewer than full privileges on the system would therefore be at lower risk.
Buffer Overrun in Legacy Text Formatting ActiveX Control:
The vulnerable ActiveX control is not installed by default as part of a current version of IE. Upon learning of the vulnerability, Microsoft removed the download from its site to minimize the likelihood that users would have the control on their systems.
The vulnerability would provide the attacker with the user’s own privileges on the system. Customers who run with fewer than full privileges on the system would therefore be at lower risk.
Customers who use Outlook Express 6.0 or Outlook 2002 (or Outlook 98 or 2000 in conjunction with the Outlook Email Security Update) would by default by protected against email-borne attacks via this vulnerability unless they specifically clicked a link within the email message.
2
The following table indicates which of the currently supported versions of Internet Explorer are affected by the vulnerabilities.
Versions of IE prior to 5.01 Service Pack 2 are no longer eligible for hotfix support. IE 5.01 SP2 is supported only on Windows® 2000.
IE 5.01 SP2 IE 5.5 SP1 IE 5.5 SP2 IE 6.0
Buffer Overrun in Gopher Protocol Handler (CAN-2002-0646) Yes Yes Yes Yes
Buffer Overrun in Legacy Text Formatting ActiveX Control (CAN-2002-0647) Yes Yes Yes Yes
XML File Reading via Redirect (CAN-2002-0648) Yes Yes Yes Yes
File Origin Spoofing (CAN-2002-0722): Yes Yes Yes Yes
Cross Domain Verification in Object Tag (CAN-2002-0723) No Yes Yes Yes
Variant of Cross-Site Scripting in Local HTML Resource (CAN-2002-0691) Yes Yes Yes No
Frequently asked questions
What vulnerabilities are eliminated by this patch?
This is a cumulative patch that incorporates the functionality of all previously released patches for Internet Explorer. In addition, the patch eliminates six newly reported vulnerabilities:
A vulnerability originally discussed in Microsoft Security Bulletin MS02-027, that could enable an attacker to take any action on another system that the system’s legitimate user could take.
A vulnerability that could enable an attacker to run code on a user’s system in the context of the user
A vulnerability that could, under certain conditions, enable an attacker to read certain types of data files on another user’s system
A vulnerability that could enable an attacker to misrepresent the origin of a file offered for download.
A vulnerability that could enable a malicious web site operator to read, but not change, any file on the user’s local computer that could be viewed n a browser window. In addition, the vulnerability enable an attacker to invoke, but not pass parameters to, an executable on the local system.
A new variant of a vulnerability originally discussed in Microsoft Security Bulletin MS02-023, that could allow an attacker to cause script to be run in the Local Computer Zone.
Does the patch include any other changes?
Yes. The patch ensures that a component that was the subject of Microsoft Security Bulletin MS02-022 cannot be used as well as ensuring that the TSAC control that was the subject of Microsoft Security Bulletin MS02-046 cannot be used. This has been done to prevent either component from being reintroduced onto users’ systems. The components at issue here is associated with MSN Chat and TSAC; customers who use MSN Chat and have not already installed the patch provided in MS02-022 should do so before installing this patch and customers who use TSAC and have not already installed the patch provided in MS02-046 should do so before installing this patch.
Buffer Overrun in Gopher Protocol Handler (CAN-2002-0646):
What’s the scope of first vulnerability?
This vulnerability was originally announced via Microsoft Security Bulletin MS02-027. As discussed in the bulletin, the vulnerability could enable an attacker to take any action on a user’s system that the user himself could take. Examples of actions the attacker could take include loading and running programs, sending data from the user’s system to a web site, reformatting the hard drive, and so forth. It could be possible to exploit the vulnerability through either of two vectors: by hosting a specially constructed web page on a web site, or by sending such a web page to another user as an HTML mail.
When the vulnerability was originally announced, Microsoft offered a workaround that customers could use to protect their systems. A complete fix is now available, and is included in this patch.
Is the description of the vulnerability provided in Microsoft Security Bulletin MS02-027 still accurate?
Yes. The information in Microsoft Security Bulletin MS02-027 still represents a complete description of the vulnerability and the risk it poses.
How does the patch eliminate the vulnerability?
The patch eliminates the vulnerability by instituting proper buffer handling within the Gopher protocol handler. It also disables the use of the Gopher protocol by default.
Why does the patch disable Gopher?
Very few customers use Gopher today. Customers who do use Gopher can easily enable it, but for the majority of users the most appropriate default condition is to have the protocol disabled.
I do use Gopher. How do I re-enable support after installing the patch? First, if you followed the workaround instructions in Microsoft Security Bulletin MS02-027, you’ll need to undo those changes. Microsoft Knowledge Base article Q326185 provides instructions for doing this.
Next, you’ll need to set the following registry key to enable Gopher via the patch:
on a peté le 800!!!!!
How could an attacker exploit this vulnerability?
The attacker would need to construct a web page that opens an XML file that purportedly resides on the server, then redirect the putative XML file to a location on the remote system. The attack could then proceed via either of two vectors. In the first, the attacker could host the web page on a web site. In the second, the attacker could only send a link to the web page in mail In either case, when the web page opened, Internet Explorer would open the file on the user’s system, within a browser window that would lie within the web site’s domain. The page could then read the data and send it to the web site.
How would the attacker know where an XML file resided on the remote system?
In most cases, the attacker wouldn’t know this information. He or she would need to either know or guess significant information about the location of the XML file on the user’s system.
Could the attacker change the data on the user’s system?
No. The vulnerability would only enable the attacker to read data – not change, add, or delete it.
Would certain email clients be at less risk than others from the mail-borne attack vector?
Yes. As in the case above, customers using Outlook Express 6.0 or Outlook 2002, or those using Outlook 98 or 2000 in conjunction with the Outlook Email Security Update, would be at much less risk. In all of these cases, HTML mail is opened by default in the Restricted Sites Zone, and this would prevent the vulnerability from being exploited.
How does the patch eliminate the vulnerability?
The patch changes the feature that contains the vulnerability, and causes it to refuse to open any XML data that has been redirected outside of the web site.
File Origin Spoofing (CAN-2002-0722):
What’s the scope of fourth vulnerability?
This vulnerability can cause the wrong origin to appear in a File Download dialogue box. An attacker could exploit this vulnerability in an attempt to fool a user into downloading a file from an untrusted source, believing it originates at a trusted source.
The vulnerability does not provide a means for the attacker to change the behavior of the file downloads. Specifically, the user would still have to accept the download. However, because the trustworthiness of files offered for download should be based on the source of the file, this vulnerability can enable an attacker to undermine the soundness of that trust decision by providing the user with false information.
What causes the vulnerability?
This vulnerability occurs because of an error in how the URL of the originating server is determined by IE when processing a specially formed URL link. Specifically, if the IE File Download dialogue encounters certain special characters, it stops displaying the proper download location. By carefully crafting a URL that points to a file for download an attacker could cause IE to display a misleading origin for the file – one that the user might choose to trust.
What’s wrong with the way the File Download dialogue handles file origins?
When a URL link initiates a download, IE performs processing to present the name and origin of the file for download. These are then presented to the user when IE displays a dialogue that asks the user whether to save the file, open the file, or cancel the download. The user can then evaluate the trustworthiness of the file based on the location as presented, and take appropriate action.
There is a flaw in how IE determines the origin name to be displayed, when the URL for the download is specially malformed. Specifically, it is possible to cause a false origin to be displayed in the file download dialogue box. For example, an attacker could host a file on www.untrustedsite.com but it would be shown in the file download dialogue box as originating from www.trustedsite.com.
What could this enable an attacker to do?
This could enable an attacker to trick a user into making an invalid trust decision regarding a file offered for download on the Internet. Since the trustworthiness of a file should be based on the source of a file, this vulnerability provides a means by which an attacker can trick a user into making an invalid trust decision by presenting false information for that decision. As a consequence of this, the user could be tricked into accepting a file from what the user believes is a trusted source when, in fact, it actually originates from an untrusted source.
How might an attacker seek to exploit this vulnerability?
An attacker could seek to exploit this vulnerability by crafting a web page with the specially crafted URL. The attacker could then either post it on a web site or send it as an HTML email to the user.
Would the web page be able to automatically start such a download?
Yes. By design, a web page can always initiate a file download. However, it’s important to be specific about what that means. The user is still in control of whether the download will proceed or not. That is, as soon as the file download starts, the File Download dialogue is displayed, and the user has the opportunity to cancel the download. Nothing in the vulnerability enables the attacker to prevent the user from simply choosing “Cancel” at the download dialogue.
If the user did choose to let the download proceed, what would happen?
It would depend on the user’s choice. The default choice in the File Download dialogue is to save the file to a location of the user’s choosing on the system. If the user chose this option, the file would be stored on the system but would only run if the user later located the file and deliberately ran it. On the other hand, if the user chose the option to open it, the program would execute.
What does the patch do?
The patch addresses the vulnerability by ensuring that IE correctly determines the origin of a file download and displays is properly.
Cross Domain Verification in Object Tag (CAN-2002-0723):
What’s the scope of fifth vulnerability?
This is a vulnerability that can allow one web site to access information in another domain, including the local system. As a result, it´s possible for a web site to read files on the local file system that can be rendered in a browser, or to invoke executables on the local file system.
The ability to read information on the local file system sounds similar to the "Frame Domain Verification" vulnerability discussed in MS02-005, is this a variant of that?
No. The flaw that causes this vulnerability is different than the flaw which causes the "Frame Domain Verification" vulnerability. However, the scope of these two vulnerabilities are, in essence, identical. In both cases the vulnerability can be used to read files on the local system that can be rendered in a browser, provided the attacker knows the full path and file name.
The ability to invoke executables sounds similar to the scope of the "Local Executable Invocation via Object tag" vulnerability in MS02-015. Is this a variant of that vulnerability?
No. The flaw that causes this vulnerability is different from the flaw which causes the "Local Executable Invocation via Object tag" vulnerability. However, these two vulnerabilities both have the same scope: an attacker could use this vulnerability to invoke an application already present on the system.
Are the mitigating factors for the "Frame Domain Verification" vulnerability applicable to this vulnerability?
Yes. The same mitigating factors that constrain the "Frame Domain Verification" vulnerability apply to this vulnerability
Are the mitigating factors for the "Local Executable Invocation via Object tag" vulnerability applicable to this vulnerability?
Yes. The same mitigating factors that constrain the "Local Executable Invocation via Object tag" vulnerability apply to this vulnerability.
What causes the vulnerability?
The vulnerability results because of improper domain verification when the Object tag is used in a particular manner.
Where can I get more information on the Frame Domain Verification vulnerability?
Microsoft Security Bulletins MS00-033, MS00-055, MS00-093, MS01-015 and MS01-058 discuss the vulnerability in detail.
Where can I get more information on the Local Executable Invocation via Object tag?
Microsoft Security Bulletin MS02-015discusses the vulnerability in detail.
Are all versions of Internet Explorer equally affected by the vulnerability?
Internet Explorer 5.5, and 6 are all affected by the vulnerability. Internet Explorer 5.01 is not affected by this vulnerability.
How does the patch address the vulnerability?
The patch institutes proper domain checking when the Object tag is invoked.
Variant of Cross-Site Scripting in Local HTML Resource (CAN-2002-0691):
What’s the scope of sixth vulnerability?
This is a new variant of a vulnerability originally discussed in Microsoft Security Bulletin MS02-023. As in the original variant, an attacker who was able to successfully exploit this vulnerability could cause HTML scripts to execute as if they were run locally on the user´s system. As a consequence, the scripts could take any action on the local system as if it were run locally.
Are there any differences between this new variant and the original one discussed in MS02-023?
No. The scope, effect, and general method of exploitation all are the same as for the original variant.
Are all versions of Internet Explorer equally affected by the vulnerability?
Internet Explorer 5.01, 5.5, and 6 are all affected by the vulnerability. However, the patch that was delivered in Microsoft Security Bulletin MS02-023 eliminated both the original and new variants for Internet Explorer 6.
Does the patch eliminate the original as well as the new variant?
Yes.
Patch availability
Download locations for this patch
http://www.microsoft.com/windows/ie/downloads/critical/q323759ie/default.asp
Additional information about this patch
Installation platforms:
The IE 5.01 patch can be applied to Windows 2000 Systems with Service Pack 2 running IE 5.01 or with Service Pack 3 running IE 5.01.
The IE 5.5 patch can be installed on systems running IE 5.5 Service Pack 1 or Service Pack 2.
The IE 6.0 patch can be installed on system running IE 6.0 Gold.
Inclusion in future service packs:
The fixes for these issues will be included in IE 6.0 Service Pack 1.
The fixes for the issues affecting IE 5.01 Service Pack 2 and Service Pack 3 will be included in Windows 2000 Service Pack 4.
Reboot needed: Yes
Patch can be uninstalled: No
Superseded patches:
This patch supersedes the one provided in Microsoft Security Bulletin MS02-023, which is itself a cumulative patch, and the workaround discussed in Microsoft Security Bulletin MS02-027.
Verifying patch installation:
To verify that the patch has been installed on the machine, open IE, select Help, then select About Internet Explorer and confirm that Q323759 is listed in the Update Versions field.
To verify the individual files, use the patch manifest provided in Knowledge Base article Q323759.
Caveats:
None
Localization:
Localized versions of this patch are available at the locations discussed in "Patch Availability".
Obtaining other security patches:
Patches for other security issues are available from the following locations:
Security patches are available from the Microsoft Download Center, and can be most easily found by doing a keyword search for "security_patch".
Patches for consumer platforms are available from the WindowsUpdate web site
All patches available via WindowsUpdate also are available in a redistributable form from the WindowsUpdate Corporate site.
Other information:
Acknowledgments
Microsoft thanks the following people for working with us to protect customers:
GreyMagic Software for reporting the XML File Reading via Redirect vulnerability.
Mark Litchfield of Next Generation Security Software Ltd. for reporting the Buffer Overrun in Legacy Text Formatting ActiveX Control vulnerability.
Jouko Pynnonen of Oy Online Solutions Ltd for reporting the File Origin Spoofing vulnerability.
Support:
Microsoft Knowledge Base article Q323759 discusses this issue and will be available approximately 24 hours after the release of this bulletin. Knowledge Base articles can be found on the Microsoft Online Support web site.
Technical support is available from Microsoft Product Support Services. There is no charge for support calls associated with security patches.
Security Resources: The Microsoft TechNet Security Web Site provides additional information about security in Microsoft products.
Disclaimer:
The information provided in the Microsoft Knowledge Base is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.
Revisions:
V1.0 (August 22, 2002): Bulletin Created.
Contact Us | E-mail this Page | TechNet Newsletter
© 2002 Microsoft Corporation. All rights reserved. Terms of Use Privacy Statement Accessibility
[0000F1CE] Loading Device = C:\WINDOWS\HIMEM.SYS
[0000F1CF] LoadSuccess = C:\WINDOWS\HIMEM.SYS
[0000F1CF] Loading Device = C:\WINDOWS\EMM386.EXE
[0000F1D3] LoadSuccess = C:\WINDOWS\EMM386.EXE
[0000F1D3] Loading Device = C:\WINDOWS\COMMAND\DISPLAY.SYS
[0000F1E0] LoadSuccess = C:\WINDOWS\COMMAND\DISPLAY.SYS
[0000F1E0] Loading Device = C:\WINDOWS\DBLBUFF.SYS
[0000F1E1] LoadSuccess = C:\WINDOWS\DBLBUFF.SYS
[0000F1E1] Loading Device = C:\WINDOWS\IFSHLP.SYS
[0000F1E0] LoadSuccess = C:\WINDOWS\IFSHLP.SYS
[0000F1E0]
C:\PROGRA~1\CREATIVE\SBLIVE\DOSDRV\SBEINIT.COM[000
0F1E1] starting
[0000F23C] C:\WINDOWS\COMMAND\MODE.COM[0000F23D] starting
[0000F23C] C:\WINDOWS\COMMAND\MODE.COM[0000F23D] starting
[0000F24E] C:\WINDOWS\COMMAND\KEYB.COM(Logo disabled)
[0000F24E] starting
[0000F285] Loading Vxd = VMM
[0000F285] LoadSuccess = VMM
[0000F285] Loading Vxd = C:\WINDOWS\SMARTDRV.EXE
[0000F284] LoadSuccess = C:\WINDOWS\SMARTDRV.EXE
[0000F285] Loading Vxd = ndis.vxd
[0000F296] LoadSuccess = ndis.vxd
[0000F296] Loading Vxd = ndis2sup.vxd
[0000F296] LoadFailed = ndis2sup.vxd
[0000F296] Loading Vxd = JAVASUP.VXD
[0000F296] LoadSuccess = JAVASUP.VXD
[0000F296] Loading Vxd = CONFIGMG
[0000F297] LoadSuccess = CONFIGMG
[0000F297] Loading Vxd = NTKERN
[0000F297] LoadSuccess = NTKERN
[0000F297] Loading Vxd = VWIN32
[0000F297] LoadSuccess = VWIN32
[0000F297] Loading Vxd = VFBACKUP
[0000F297] LoadSuccess = VFBACKUP
[0000F297] Loading Vxd = VCOMM
[0000F297] LoadSuccess = VCOMM
[0000F297] Loading Vxd = COMBUFF
[0000F297] LoadSuccess = COMBUFF
[0000F297] Loading Vxd = C:\WINDOWS\system\VMM32\IFSMGR.VXD
[0000F296] LoadSuccess = C:\WINDOWS\system\VMM32\IFSMGR.VXD
[0000F296] Loading Vxd = C:\WINDOWS\system\VMM32\IOS.VXD
[0000F296] LoadSuccess = C:\WINDOWS\system\VMM32\IOS.VXD
[0000F296] Loading Vxd = mtrr
[0000F296] LoadSuccess = mtrr
[0000F296] Loading Vxd = SPOOLER
[0000F296] LoadSuccess = SPOOLER
[0000F296] Loading Vxd = UDF
[0000F296] LoadSuccess = UDF
[0000F296] Loading Vxd = VFAT
[0000F297] LoadSuccess = VFAT
[0000F297] Loading Vxd = VCACHE
[0000F296] LoadSuccess = VCACHE
[0000F296] Loading Vxd = VCOND
[0000F296] LoadSuccess = VCOND
[0000F296] Loading Vxd = VCDFSD
[0000F296] LoadSuccess = VCDFSD
[0000F296] Loading Vxd = VXDLDR
[0000F296] LoadSuccess = VXDLDR
[0000F296] Loading Vxd = VDEF
[0000F296] LoadSuccess = VDEF
[0000F296] Loading Vxd = VPICD
[0000F296] LoadSuccess = VPICD
[0000F296] Loading Vxd = VTD
[0000F296] LoadSuccess = VTD
[0000F296] Loading Vxd = REBOOT
[0000F296] LoadSuccess = REBOOT
[0000F296] Loading Vxd = VDMAD
[0000F296] LoadSuccess = VDMAD
[0000F296] Loading Vxd = VSD
[0000F296] LoadSuccess = VSD
[0000F296] Loading Vxd = V86MMGR
[0000F296] LoadSuccess = V86MMGR
[0000F296] Loading Vxd = PAGESWAP
[0000F296] LoadSuccess = PAGESWAP
[0000F296] Loading Vxd = DOSMGR
[0000F296] LoadSuccess = DOSMGR
[0000F296] Loading Vxd = VMPOLL
[0000F296] LoadSuccess = VMPOLL
[0000F296] Loading Vxd = SHELL
[0000F296] LoadSuccess = SHELL
[0000F296] Loading Vxd = PARITY
[0000F296] LoadSuccess = PARITY
[0000F296] Loading Vxd = BIOSXLAT
[0000F296] LoadSuccess = BIOSXLAT
[0000F296] Loading Vxd = VMCPD
[0000F296] LoadSuccess = VMCPD
[0000F296] Loading Vxd = VTDAPI
[0000F296] LoadSuccess = VTDAPI
[0000F296] Loading Vxd = PERF
[0000F296] LoadSuccess = PERF
[0000F296] Loading Vxd = C:\WINDOWS\SYSTEM\vrtwd.386
[0000F296] LoadSuccess = C:\WINDOWS\SYSTEM\vrtwd.386
[0000F297] Loading Vxd = C:\WINDOWS\SYSTEM\vfixd.vxd
[0000F296] LoadSuccess = C:\WINDOWS\SYSTEM\vfixd.vxd
[0000F296] Loading Vxd = vnetbios.vxd
[0000F296] LoadSuccess = vnetbios.vxd
[0000F298] Loading Vxd = C:\PROGRA~1\SYMANTEC\SYMEVNT.386
[0000F296] LoadSuccess = C:\PROGRA~1\SYMANTEC\SYMEVNT.386
[0000F296] Loading Vxd = C:\PROGRA~1\NORTON~1\NORTON~2\NAVAP.VXD
[0000F2A8] LoadSuccess = C:\PROGRA~1\NORTON~1\NORTON~2\NAVAP.VXD
[0000F2A8] Loading Vxd = C:\PROGRA~1\NORTON~1\NORTON~3\NISDRV.VXD
[0000F2A8] LoadSuccess = C:\PROGRA~1\NORTON~1\NORTON~3\NISDRV.VXD
[0000F2A8] Loading Vxd = ASPIENUM.VXD
[0000F2A9] LoadSuccess = ASPIENUM.VXD
[0000F2A9] Loading Vxd = vgartd.vxd
[0000F2A8] LoadSuccess = vgartd.vxd
[0000F2A8] Loading Vxd = ebios
[0000F2A8] LoadSuccess = ebios
[0000F2A8] Loading Vxd = vmouse
[0000F2A8] LoadSuccess = vmouse
[0000F2A8] Loading Vxd = dynapage
[0000F2A9] LoadSuccess = dynapage
[0000F2A9] Loading Vxd = vcd
[0000F2A9] LoadSuccess = vcd
Project64 1.5 Official Cheats Database (Project64.cht)
From The emu64cheats authors
-----Version 1.5 Cheat Changes - 29th August 2002-----
Welcome to the new look & feel of Project64.
There has been many changes to PJ64 since the release of PJ64 1.4
so make sure you read all the readme & changes docs.
So what has changed on the Cheats front ?
Have a look http://www.pj64cheats.net
This will walk you through all the do´s & Don´ts´ of adding, Using,
Plus the CheatsFAQ will tell you all you need to know !
You can find the CheatsFAQ in this Folder Docs\Cheat Codes\cheatsfaq.txt
& also on the web site from the FAQ Link.
We have Added & Improved Cheat Code Supported for following Regions.:
(U) = USA
(E) = Europe
(A) = Australia
(F) = France
(G) = Germany
(J) = Japan
If you experience any problems when using these cheats in pj64
please visit the pj64cheats web site http://www.pj64cheats.net
this should help you with all you need to know.
If you have a problem that is not covered on the site
then we also have a pj64cheats Message Board on emutalk.net
If you are not a member on emutalk.net we suggest you become one
so you can be upto date on the pj64cheats progression.
We also have a IRC Channel #pj64cheats on EFnet for a chat in real time
if you have a problem that isn´t mentioned on the Site Or the Board.
Thank You for your help & support.
Here is a list below of Games that are Support with cheats in the new pj64.cht File
//--------------- (J) Region Cheat Codes ---------------
Airboarder 64
Akumajou Dracula Mokushiroku - Real Action Adventure
All Star! Dairantou Smash Brothers
BAKU-BOMBERMAN
Baku Bomberman 2
Banjo to Kazooie no Dai Bouken
Banjo to Kazooie no Dai Bouken 2
Blast Dozer
Bomberman 64 - Arcade Edition
Chou Snowbow Kids
Chameleon Twist
Chameleon Twist 2
Dance Dance Revolution - Disney Dancing Museum
Doom 64
Dual Heroes
Eltale Monsters
Gauntlet Legends
Hybrid Heaven
King Hill 64 - Extreme Snowboarding
Puyo Puyo Sun 64
Super Robot Spirits
Snowbow Kids
Super Mario 64
Super Mario 64 Shindou Edition
Super Speed Race 64
Turok - Dinosaur Hunter
Wave Race 64
WWF Wrestlemania 2000
Zelda no Densetsu - Toki no Ocarina
Zelda no Densetsu 2 - Mujura no Kamen
//--------------- (JU) Region Cheat Codes ---------------
1080 Snowboarding
//--------------- (U) Region Cheat Codes ---------------
A Bug´s Life
AERO FIGHTERS ASSAUL
AEROGAUGE
All-Star Baseball 99
All-Star Baseball 2000
ALL STAR TENNIS ´99
Army Men - Air Combat
Army Men - Sarge´s Heroes
Army Men - Sarge´s Heroes 2
Armorines - Project S.W.A.R.M.
Asteroids Hyper 64
Automobili Lamborghini
Banjo-Kazooie [v1.0]
BASS HUNTER 64
Bassmasters 2000
Batman Beyond - Return of the Joker
BattleTanx
BattleTanx - Global Assault
Battlezone - Rise of the Black Dogs
Beast Wars Transmetal
Beetle Adventure Racing
Big Mountain 2000
Bio F.R.E.A.K.S.
Blast Corps. [v1.0]
Blues Brothers 2000
Body Harvest
Bomberman 64
Bomberman 64 - The Second Attack!
Bomberman Hero
Buck Bumble
Bust A Move ´99
Bust-A-Move 2 - Arcade Edition
California Speed
Castlevania
Castlevania - Legacy of Darkness
Chameleon Twist
Charlie Blast´s Territory
Chopper Attack
Clay Fighter 63 1-3
Clay Fighter - Sculptor´s Cut
Command & Conquer
Conker´s Bad Fur Day
Cruis´n USA [v1.0]
Cruis´n USA [v1.1]
Cruis´n USA [v1.2]
Cruis´n World
CyberTiger
Deadly Arts
Destruction Derby 64
Diddy Kong Racing [v1.0]
Disney´s Donald Duck - Goin´ Quackers
Disney´s Tarzan
Donkey Kong 64
Doom 64
Dual Heroes
Duck Dodgers Starring Daffy Duck
Duke Nukem 64
Earthworm Jim 3D
ECW Hardcore Revolution
Elmo´s Letter Adventure
Elmo´s Number Journey
Excitebike 64
Extreme-G
Extreme-G XG2
F-1 Pole Position 64
Fighter´s Destiny
Fighter Destiny 2
Fighting Force 64
Flying Dragon
Forsaken 64
Fox Sports College Hoops ´99
F-Zero X
Gex 3: Deep Cover Gecko
Gex 64: Enter The Gecko
Glover
Goemon´s Great Adventure
Goldeneye 007
Harvest Moon
Hercules: The Legendary Journeys
Hexen
Hot Wheels Turbo Racing
Hybrid Heaven
Hydro Thunder
Indy Racing 2000
Iggy´s Reckin´ Balls
Jeopardy
Jeremy McGrath Supercross 2000
Jet Force Gemini (Patched)
John Romero´s Daikatana
Ken Griffey Jr.´s Slugfest
Killer Instinct Gold [v1.0]
Kirby 64 - The Crystal Shards
Knife Edge - Nose Gunner
Knockout Kings 2000
Legend of Zelda 2, The - Majora´s Mask
Legend of Zelda, The - Ocarina of Time [v1.0]
Legend of Zelda, The - Ocarina of Time [v1.1]
Legend of Zelda, The - Ocarina of Time [v1.2]
LEGO Racers
Lode Runner 3-D
Mace - The Dark Ages
Madden 2000
Madden Football 64
Madden NFL 99
Madden NFL 2001
Magical Tetris Challenge
Mario Golf 64
Mario Kart 64
Mario Party
Mario Party 2
Mario Party 3
Mario Tennis
Mega Man 64
Micro Machines 64 Turbo
Mike Piazza´s Strike Zone
Milo´s Astro Lanes
Mischief Makers
Mission Impossible
Monaco Grand Prix
Monopoly
Monster Truck Madness 64
Mortal Kombat 4
Mortal Kombat Trilogy [v1.0]
MRC - Multi Racing Championship
Ms. Pac-Man Maze Madness
Mystical Ninja - Starring Goemon
Nagano Winter Olympics ´98
Namco Museum 64
NASCAR 99
NASCAR 2000
NBA HANGTIME
NBA JAM 99
NBA In The Zone ´98
NBA In The Zone ´99
NBA LIVE 2000
NHL Breakaway 98 (U) [!]
NHL Blades Of Steel ´99
NFL Blitz 2001
NFL Quarterback Club 2000
NFL Quarterback Club 2001
NFL Quarterback Club 99
NFL Quarterback Club 2000
New Tetris, The
Nuclear Strike 64
Off Road Challenge
Ogre Battle 64 - Person of Lordly Caliber
Paperboy
Paper Mario
Perfect Dark [v1.0]
PGA European Tour
Pilotwings 64
Pokemon Snap
Pokemon Stadium
Pokemon Stadium 2
Power Rangers - Lightspeed Rescue
Powerpuff Girls, The - Chemical X-traction
Quake 64
Quake II
Quest 64
Rally Challenge 2000
Rampage - World Tour
Rampage 2: Universal Tour
Rat Attack
Rayman 2 The Great Escape
Ready 2 Rumble Boxing
Ready 2 Rumble Boxing: Round 2
Re-Volt
Road Rash 64
Robotron 64
Rocket: Robot On Wheels
RR64 - Ridge Racer 64
Rugrats in Paris - The Movie
Rush 2 - Extreme Racing
SCARS
San Francisco Rush - Extreme Racing
San Francisco Rush 2049
Scooby-Doo - Classic Creep Capers
Shadow Man
Snowboard Kids
Snowboard Kids 2
South Park
South Park; Chef´s L
South Park Rally
Spacestation Silicon Valley (U) [!]
Space Invaders
Spider-Man
STARCRAFT 64
Star Fox 64
Star Soldier: Vanishing Earth
Star Wars EP1 Pod Racer
Star Wars - Shadows of the Empire [V1.0]
Super Mario 64
Super Smash Brothers
Superman
Tetrisphere
Tom and Jerry in Fists of Furry
Tom Clancy´s Rainbow Six
Tony Hawk´s Pro Skater
Tony Hawk´s Pro Skater 2
Top Gear Hyper Bike
Top Gear Overdrive
Top Gear Rally
Top Gear Rally 2
Toy Story 2
Turok: Dinosaur Hunter [v1.0]
Turok: Dinosaur Hunter [v1.1]
Turok: Rage Wars
Turok 2: Seeds of Evil - Kiosk
Turok 2: Seeds of Evil
Turok 3: Shadow of Oblivion
World is Not Enough, The
Twisted Edge Extreme Snowboarding
Vigilante 8
Vigilante 8 - 2nd Offense
Virtual Chess 64
Virtual Pool 64
V-Rally Edition 99
Waialae Country Club - True Golf Classics
War Gods
Wave Race 64 [v1.0]
Wave Race 64 [v1.1]
Wayne Gretzky´s 3D Hockey
Wayne Gretzky´s 3D Hockey ´98
WCW Mayhem
Wetrix
Wheel Of Fortune
WinBack - Covert Operations
Wipeout 64
World Cup 98
WWF - Warzone
WWF Attitude
WWF No Mercy
WWF WrestleMania 2000
Xena Warrior Princess: The Talisman of Fate
Yoshi´s Story
//--------------- PAL (E) Reigion Cheat Codes
007 The World is Not Enough
1080 Snowboarding
A Bug´s Life
AeroGauge
Airboarder 64
Armorines - Project S.W.A.R.M.
All Star Baseball ´99
All Star Tennis ´99
Army Men - Sarge´s Heroes
Automobili Lamborghini
Banjo-Kazooie
Bass Hunter 64
Batman Beyond - Return of the Joker
BattleTanx - Global Assault
Beetle Adventure Racing
Blast Corps.
Bio F.R.E.A.K.S.
Blues Brothers 2000
Body Harvest
Buck Bumble
Bust-A-Move 2 - Arcade Edition
Castlevania
Castlevania - Legacy of Darkness
Centre Court Tennis
Chopper Attack
Clay Fighter 63 1/3
Command & Conquer
CONKER BFD
Cruis´n USA [V1.0]
Cruis´n USA [V1.1]
Cruis´n USA [V1.2]
Cruis´n World
Cyber Tiger
Dark Rift
Destruction Derby 64
Diddy Kong Racing [V1.0]
Diddy Kong Racing [V1.1]
Disney´s Tarzan
Donald Duck - Quack Attack
Donkey Kong 64
Doom 64
Dual Heroes
Duke Nukem 64
Duke Nukem Zero Hour
Earthworm Jim 3D
Excitebike 64
Extreme-G
Extreme-G XG2
F-1 World Grand Prix II
F-Zero X
F1 Racing Championship
FIFA - Road to World Cup 98
FIFA 99
FIFA Soccer 64
Fighter´s Destiny
Fighting Force 64
Forsaken 64
Gauntlet Legends
Gex 3 - Deep Cover Gecko
Gex 64 - Enter the Gecko
Glover
GoldenEye 007
GT 64 Championship Edition
HERCULES - The Legendary Journeys
Hexen
Holy Magic Century
Hot Wheels Turbo Racing
Hybrid Heaven
Hydro Thunder
Iggy´s Reckin´ Balls
International Superstar Soccer 64
International Superstar Soccer ´98
Jet Force Gemini Patched
John Romero´s Daikatana
Killer Instinct Gold
Kirby 64 - The Crystal Shards
Knife Edge - Nose Gunner
Knockout Kings 2000
Legend of Zelda 2, Majora´s Mask
Legend of Zelda, The - Ocarina of Time [V1.0]
Legend of Zelda, The - Ocarina of Time [V1.1]
Lode Runner 3D
Looney Tunes - Duck Dodgers
Mace - The Dark Age
Mario Golf 64
Mario Kart 64 [V1.0]
Mario Kart 64 [v1.1]
Mario Party
Mario Tennis
Micro Machines 64 Turbo
Mischief Makers
Mission Impossible
Mortal Kombat 4
Mortal Kombat Trilogy
MRC - Multi Racing Championship
Mystical Ninja - Starring Goemon
NASCAR 99
NHL Breakaway 98
Nuclear Strike 64
Operation WinBack - Covert Operations
Paperboy 64
Paper Mario
Perfect Dark
Pokemon Stadium
Pokemon Stadium 2
Quake 64
Quake II
Resident Evil 2
Re-Volt
Road Rash 64
Roadsters
Robotron 64
Rocket - Robot on Wheels
Rayman2 The Great Escape
Ready 2 Rumble Boxing
RR64 - Ridge Racer 64
Rugrats - Treasure Hunt
Rugrats in Paris - The Movie
SCARS
San Francisco Rush - Extreme Racing
San Francisco Rush 2 - Extreme Racing
San Francisco Rush 2049
Scooby-Doo - Classic Creep Capers
Shadow Man
Snowboard Kids
Snowboard Kids 2
South Park Rally
Spacestation Silicon Valley
Star Craft 64
Star Fox 64 Lylat Wars
Starshot - Space Circus Fever
Star Wars - Rogue Squadron
Star Wars - Shadows of the Empire
Star Wars Episode I - Battle for Naboo
Star Wars EP1 Pod Racer
Super Mario 64
Super Smash Bros
Superman
Tigger´s Honey Hunt
Tom and Jerry in Fists of Fury
Tony Hawk´s Pro Skater
Tony Hawk´s Pro Skater 2
Top Gear Hyper Bike
Top Gear Overdrive
Top Gear Rally
Top Gear Rally 2
Toy Story 2
Turok - Dinosaur Hunter [V1.0]
Turok - Dinosaur Hunter [V1.1]
Turok - Rage Wars
Turok 2 - Seeds of Evil
Turok 3 - Shadow of Oblivion
Twisted Edge Extreme Snowboarding
Vigilante 8
Virtual Pool 64
V-Rally Edition 99
Waialae Country Club - True Golf Classics
War Gods
Wave Race 64
Wayne Gretzky´s 3D Hockey ´98
Wetrix
Wipeout 64
WWF No Mercy
WWF WrestleMania 2000
Xena Warrior Princess - Talisman of Fate
Yoshi´s Story
//--------------- PAL (A) Reigion Cheat Codes
Star Fox 64 Lylat Wars
Super Smash Bros
//--------------- PAL (F) Reigion Cheat Codes
A Bug´s Life
Holy Magic Century
Disney´s Tarzan
Shadow Man
//--------------- PAL (G) Reigion Cheat Codes
A Bug´s Life
Holy Magic Century
Disney´s Tarzan
Turok - Dinosaur Hunter
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@lllllllllllllllllllll
llllllllllllllleeeeeeeeeeeeeeeeeeeeerrrrrrrrrrrrrt
tttttttttttttteeeeeeeeeeeee rooooooooooooouuuuggggggggggggeeeeeeeeeeeeee : :::::::::===========(((((((((
BULLETIN D´ALERTE DU CERTA
Objet : Risque de divulgation de données personnelles/confidentielles par des produits Microsoft
Gestion du document
Référence CERTA-2001-ALE-014
Titre Risque de divulgation de données personnelles/confidentielles par des produits Microsoft
Date de la première version 19 octobre 2001
Date de la dernière version -
Source(s) Bulletin du CIAC, révision du 18 octobre 2001
Pièce(s) jointe(s) Aucune
Une gestion de version détaillée se trouve à la fin de ce document.
1 Risque
Divulgation d´informations personnelles et/ou confidentielles.
2 Systèmes affectés
Internet Explorer 5.x et 6 sous Windows 98, 98SE, Me, NT4 et 2000.
Windows XP
Office XP
3 Résumé
Internet Explorer (versions supérieures à 5), Windows XP et Office XP peuvent faire appel à un programme dénommé ``Error Reporting Tool´´ (Outil de Rapport d´Erreur) pour transmettre, via internet, à Microsoft des informations de déboggage et un vidage mémoire en cas d´erreur non récupérable. Cette fonctionnalité est justifiée par Microsoft comme permettant d´accélérer le cycle de correction des problèmes.
4 Description
L´outil cité ci-dessus est installé par défaut avec Windows XP, Office XP et Internet Explorer 6. Il fait partie des mises à jour proposées pour Internet Explorer 5. Un vidage mémoire peut contenir tout ou partie des documents ou des pages web consultés. Cela implique potentiellement la divulgation de données confidentielles, personnelles (explicites ou sur les préférences de l´utilisateur).
Une boîte de dialogue est présentée à l´utilisateur avant l´envoi, mais ce dernier n´est bien sûr pas systématiquement en charge de la politique de sécurité.
5 Contournement provisoire
5.1 Office XP
Utiliser l´une des 2 méthodes ci-dessous :
A l´aide de Regedit dans le menu ``Edition/Nouveau/Valeur DWORD´´ :
Rajouter les entrées suivantes avec une valeur de 1 pour chaque utilisateur dans
HKCU\Software\Policies\Microsoft\Office\10.0\Commo
n\ :
DWNeverUpload
DWNoExternalURL
DWNoFileCollection
DWNoSecondLevelCollection
Rajouter les entrées suivantes avec une valeur de 1 dans
HKU\.Default\Software\Policies\Microsoft\Office\10
.0\Common\ :
DWNeverUpload
DWNoExternalURL
DWNoFileCollection
DWNoSecondLevelCollection
Télécharger et lancer le fichier :
http://www.ciac.org/ciac/bulletins/office/UnWatsonXP.reg
5.2 Internet Explorer 5
Dans le ``Panneau de configuration´´, choisir ``Ajouter/Supprimer des programmes´´, sélectionner ``Internet Explorer Error Reporting´´ et cliquer ``Ajouter/Supprimer´´ ou ``Modifier/Supprimer´´ selon les versions de Windows.
5.3 Internet Explorer 6 pour Windows XP, Windows XP
Dans le ``Panneau de configuration´´, choisir ``Performances et maintenance´´, ``Système´´, onglet ``Avancé´´, bouton ``Rapport d´erreurs´´ et :
soit sélectionner ``Désactiver le rapport d´erreurs´´,
soit décocher ``Système d´exploitation Windows´´ et/ou ``Programmes´´ selon la politique de sécurité.
5.4 Internet Explorer 6 (autres versions de Windows)
Utiliser l´une des 2 méthodes ci-dessous :
A l´aide de Regedit dans le menu ``Edition/Nouveau/Valeur DWORD´´ rajouter l´entrée suivante, avec une valeur de 0, dans
HKLM\Software\Microsoft\Internet Explorer\Main\ :
IEWatsonEnabled
Télécharger et lancer le fichier :
http://www.ciac.org/ciac/bulletins/office/UnWatsonIE6.reg
6 Documentation
Bulletin du CIAC :
http://www.ciac.org/ciac/bulletins/m-005.shtml
Article de Microsoft ``Description and Availability of Internet Explorer Error Reporting Tool´´
http://support.microsoft.com/support/kb/articles/Q276/5/50.ASP
``Microsoft Error Reporting - Data Collection Policy´´
http://watson.microsoft.com/dw/1033/dcp.asp
Kit de ressource technique office XP ``Reporting Office Application Crashes´´
http://www.microsoft.com/m/office/ork/xp/two/admA05.htm
Gestion détaillée du document
19 octobre 2001
version initiale.
Alertes (les 5 plus récentes)
Les alertes sont des documents destinés à prévenir d´un danger immédiat.
CERTA-2002-ALE-007 (html)(PDF) Cédérom Pages Pro (4 septembre 2002)
CERTA-2002-ALE-006 (html)(PDF) Propagation du ver Spida (Microsoft SQL Server) (04 juin 2002)
CERTA-2002-ALE-005 (html)(PDF) Risque de compromission des auto-commutateurs (PABX) ALCATEL 4400 (20 février 2002)
CERTA-2002-ALE-004 (html)(PDF) Multiples implémentations de SNMP V1 vulnérables (13 février 2002)
CERTA-2002-ALE-001 (html)(PDF) Exploitation massive d´une faille de CDE (24 janvier 2002)
Avis (les 20 plus récents)
Les avis sont des documents faisant état de vulnérabilité et des moyens de s´en prémunir.
CERTA-2002-AVI-224 (html)(PDF) Vulnérabilités du serveur Apache (11 octobre 2002)
CERTA-2002-AVI-223 (html)(PDF) Vulnérabilité dans Microsoft Outlook Express (11 octobre 2002)
CERTA-2002-AVI-222 (html)(PDF) Multiples vulnérabilités dans Services for Unix 3.0 de Microsoft (03 octobre 2002)
CERTA-2002-AVI-221 (html)(PDF) Vulnérabilités de la fonction d´aide sous Windows (03 octobre 2002)
CERTA-2002-AVI-220 (html)(PDF) Multiples vulnérabilités dans MS-SQL (03 octobre 2002)
CERTA-2002-AVI-219 (html)(PDF) Vulnérabilités dans les fonctions de décompression des dossiers sous Windows (03 octobre 2002)
CERTA-2002-AVI-218 (html)(PDF) Vulnérabilité dans le serveur Microsoft FrontPage (26 septembre 2002)
CERTA-2002-AVI-162 (html)(PDF) Multiples vulnérabilités dans OpenSSL (26 septembre 2002)
CERTA-2002-AVI-217 (html)(PDF) Vulnérabilité de PHP (20 septembre 2002)
CERTA-2002-AVI-216 (html)(PDF) Vulnérabilité des anti-virus pour passerelles de messagerie (20 septembre 2002)
CERTA-2002-AVI-215 (html)(PDF) Multiples Vulnérabilités dans Microsoft java (19 septembre 2002)
CERTA-2002-AVI-214 (html)(PDF) Vulnérabilité d´ISS Scanner (19 septembre 2002)
CERTA-2002-AVI-213 (html)(PDF) Vulnérabilité du protocole RDP dans les systèmes Windows (19 septembre 2002)
CERTA-2002-AVI-212 (html)(PDF) Multiples vulnérabilités du client VPN 5000 de Cisco (19 septembre 2002)
CERTA-2002-AVI-209 (html)(PDF) Vulnérabilités sur HP Tru64 Unix (19 septembre 2002)
CERTA-2002-AVI-211 (html)(PDF) Vulnérabilité du Help Center de Windows XP (18 septembre 2002)
CERTA-2002-AVI-147 (html)(PDF) Vulnérabilités de CDE Tooltalk (18 septembre 2002)
CERTA-2002-AVI-210 (html)(PDF) Vulnérabilité de aspppls sous solaris 8 (17 septembre 2002)
CERTA-2002-AVI-207 (html)(PDF) Contournement des règles de sécurité dans Konqueror (17 septembre 2002)
CERTA-2002-AVI-173 (html)(PDF) Vulnérabilité de ToolTalk (17 septembre 2002)
Notes d´information (les 5 plus récentes)
Les notes d´informations font état de phénomènes à portée générale.
CERTA-2002-INF-002 (html)(PDF) Les bons réflexes en cas d´intrusion sur un système d´information. (17 juin 2002)
CERTA-2002-INF-001 (html)(PDF) Vulnérabilité de type « Cross Site Scripting » (22 mars 2002)
CERTA-2000-INF-003 (html)(PDF) Évolution des outils de déni de service distribué (29 mai 2000)
CERTA-2001-INF-005 (html)(PDF) Apparition de vers exploitant des vulnérabilités de MS-SQL Server (26 novembre 2001)
CERTA-2001-INF-004 (html)(PDF) Acquisition des correctifs (04 octobre 2001)
Recommandations (les 5 plus récentes)
CERTA-2002-REC-002 (html)(PDF) Sécurité des réseaux sans fil utilisant la norme 802.11b (Wi-Fi) (8 août 2002)
CERTA-2002-REC-001 (html)(PDF) Usage de la messagerie instantanée ou de l´IRC (28 mars 2002)
CERTA-2001-REC-001 (html)(PDF) Visualisation inexacte de documents par le logiciel WORD. (16 novembre 2001)
CERTA-2000-REC-002 (html)(PDF) Mise en garde au sujet des messages de voeux (21 décembre 2000)
CERTA-2000-REC-001 (html)(PDF) Retour d´expérience du ver ILOVEYOU (16 mai 2000)
S . G . D . N
Direction centrale
de la sécurité des
systèmes d´information
Le directeur Paris, le 28 mars 2002
No CERTA-2002-REC-001
Affaire suivie par :
CERTA
N O T E
Objet : Usage de la messagerie instantanée ou de l´IRC
Gestion du document
Tableau 1: gestion du document Référence CERTA-2002-REC-001
Titre Usage de la messagerie instantanée ou de l´IRC
Date de la première version 28 mars 2002
Date de la dernière version -
Source(s) Note d´incident du CERT/CC IN-2002-03
Avis de sécurité du CERTA CERTA-2002-AVI-012
Pièce(s) jointe(s) Aucune
Une gestion de version détaillée se trouve à la fin de ce document.
1 Risque
Divulgation d´informations ;
exécution de code arbitraire ;
participation à des attaques en déni de service distribuées (DDoS).
2 Résumé
Les logiciels de messagerie instantanée et de discussion en ligne (IRC, Chat ou « causette ») sont de plus en plus répandus. Ces logiciels comportent certains risques qu´il faut connaître :
ils exposent l´utilisateur à une divulgation rapide de son identité ou éventuellement d´autres informations le concernant ou concernant son système ;
l´utilisateur peut être tenté de télécharger toute sorte d´outils contenant des chevaux de Troie et permettant à un utilisateur mal intentionné d´exploiter les machines de ses victimes ;
ces logiciels, souvent installés par défaut sur les systèmes Windows ou avec un navigateur web, présentent un certain nombre de vulnérabilités connues.
Il faut donc rester aussi vigilant pour les logiciels de messagerie instantanée et pour l´IRC que pour le mél.
3 Introduction
Le mél est un moyen simple et rapide de communication, avec tous les risques qu´il comporte (fichiers attachés, courrier composé en HTML et renfermant des scripts ou autres contenus actifs, liens cachés, etc.). Il existe d´autres outils de communication plus simples et plus ludiques :
la messagerie instantanée : ICQ (I Seek You), AIM (AOL Instant Messenger), MSN Messenger (the MicroSoft Network Messenger), Yahoo Messenger, etc.
l´IRC (Internet Relay Chat) aussi appelé chat.
3.0.1 Qu´est-ce que la messagerie instantanée ?
La messagerie instantanée est un moyen de communiquer en privé avec d´autres personnes de son choix. Le client se connecte à un serveur qui contient les informations sur tous les utilisateurs inscrits, connectés ou non. Chaque personne possède un pseudonyme qui n´est pas forcément unique, et un identifiant unique dans la base de données du serveur. Cet identifiant peut être un numéro, une adresse mél, etc. Si l´on désire parler à une personne, on la recherche dans cette base. On peut créer une liste d´interlocuteurs préférés. Deux personnes peuvent communiquer en direct si elles sont simultanément connectées au serveur. Sinon, elles peuvent consulter leurs messages dans leur boîte aux lettres au moment où elles se connectent.
3.0.2 Qu´est-ce que l´IRC ?
L´IRC est un moyen de communiquer en direct avec des groupes de personnes via l´Internet. Les clients se connectent à des serveurs qui sont eux-mêmes reliés entre eux, formant un réseau IRC. Tous les clients sont donc susceptibles de communiquer entre eux en temps réel à travers le réseau.
4 Les dangers
4.1 Divulgation d´informations « sensibles »
Sur IRC ou par messagerie instantanée, certains de vos interlocuteurs chercheront à obtenir des informations sur vous, votre employeur ou sur le système que vous utilisez :
il faut savoir que sur IRC et sur la plupart des logiciels de messagerie instantanée, votre adresse IP est visible de façon immédiate ;
vos messages transitent par des serveurs bien définis :
certains systèmes de messagerie instantanée sont des logiciels propriétaires se connectant à des serveurs administrés par des sociétés de droit privé souvent situées à l´étranger ;
Sur IRC, les opérateurs IRC et les administrateurs des serveurs ont la possibilité de suivre les conversations tenues sur un canal ou suivre les connexions d´une adresse IP donnée. De plus, l´administrateur de serveur IRC peut avoir une visibilité complète de tous les échanges réalisés au travers de son serveur.
Comme par téléphone, vous prenez part à une discussion, vous n´écrivez pas une lettre que vous pourrez relire. Une phrase envoyée est lue instantanément par vos correspondants. Il n´est plus possible de la corriger . ..
Faites attention à ce que vous dites. Parler en direct fait parfois dire beaucoup (trop) de choses . ..
Sur les logiciels de messagerie instantanée, il est possible de remplir un formulaire d´informations vous concernant. Ce que vous mettrez dans ce formulaire sera visible par n´importe quelle personne utilisant le même logiciel. Dans certains cas, ces informations sont aussi visibles sur un site web dédié à ce logiciel.
Sur IRC, il est possible de donner des informations supplémentaires dans les paramètres de votre client (nom d´utilisateur, nom réel,etc.). Ne laissez pas ces paramètres tels qu´ils sont définis par défaut, il peuvent être révélateurs pour un curieux. Ne mettez pas de vraies informations si celles-ci sont sensibles.
4.2 Les sites web incitant à installer un outil
Comme indiqué dans l´alerte CERTA-2001-ALE-011 concernant la propagation d´un cheval de Troie au moyen d´un site web proposant de télécharger un faux anti-virus, méfiez-vous de la publicité reçue par mél, sur votre messagerie instantanée ou en arrivant dans un canal IRC, vous incitant à télécharger tel ou tel programme.
N´installez que des logiciels téléchargés depuis le site web de leur éditeur (les autres pouvant contenir des portes dérobées par exemple) et préférez les CD-ROM originaux.
Ne faites pas confiance aux pièces jointes d´un mél même s´il a l´air de provenir d´un éditeur de logiciel ou de personnes connues.
Mettez à jour votre anti-virus et contrôlez avec celui-ci les fichiers téléchargés.
Sous Linux il est possible d´aller vérifier les signatures MD5 sur le site web de la distribution concernée (commande md5sum dont le résultat est à comparer avec celui indiqué sur le site de l´éditeur).
Evitez d´installer des scripts IRC, ils peuvent contenir un cheval de Troie, changer les paramètres de votre client, voire y ajouter des composantes contrôlables à distance.
4.3 Téléchargement de fichiers
Avec les logiciels de messagerie instantanée, il est possible d´envoyer des fichiers en point à point. Vous pouvez envoyer une image, un document, ou un fichier exécutable à vos correspondants ; vous devenez alors serveur pendant le temps de cet envoi.
De même, deux clients IRC peuvent s´échanger d´autres éléments que des messages. Ils peuvent aussi échanger des fichiers. Pour celà il faut établir une connexion DCC (Direct Client to Client). Le récepteur doit accepter la requête (en faisant DCC Get), mais souvent les interfaces des clients IRC masquent cette étape. Encore une fois, certains clients sont paramétrés par défaut de façon à accepter automatiquement tout transfert de fichier par DCC.
Enfin, il est possible d´ajouter des scripts permettant aux clients IRC d´effectuer des tâches plus ou moins automatisées. Ces scripts sont un moyen de propagation supplémentaire pour les vers et les virus (cf. CERTA-2001-ALERTE-001 et CERTA-2001-ALE-009).
Comme pour le mél, prenez les précautions de base :
n´exécutez pas ce qui provient d´un inconnu et vérifiez que vos interlocuteurs connus ne vous ont pas envoyé un fichier à leur insu. Vérifiez systématiquement le fichier avec un antivirus que vous avez mis à jour ;
sachez qu´un éditeur d´antivirus ou de logiciel ne vous enverra jamais de correctif ou de mise à jour par le biais de la messagerie instantanée, de l´IRC ou du mél ;
il est possible que votre logiciel soit paramétré par défaut pour accepter ces fichiers, assurez-vous que vous avez bien modifié ces configurations avant de vous connecter ;
n´installez pas de scripts si vous n´en connaissez pas toutes les fonctionnalités (maîtriser le language utilisé, et lire les sources). Surveillez les modifications des fichiers de scripts dans le répertoire courant du logiciel IRC ;
ne suivez pas tous les liens hypertexte que vous lisez quelque soit leur moyen de diffusion.
4.4 Vulnérabilités des clients
Le logiciel en lui-même peut être vulnérable, et permettre l´exécution de code arbitraire par le biais d´un débordement de mémoire (cf. CERTA-2002-AVI-012).
Inversement, un logiciel de messagerie instantanée peut appeler d´autres composants Windows, tels que le navigateur web par défaut ou les éléments de Netmeeting par exemple. Il peut aussi exister des vulnérabilités dans ces composants (cf. CERTA-2000-AVI-063).
Ainsi il faut maintenir à jour des correctifs de tous les logiciels quels qu´ils soient. Un élément du système ou un module externe d´un logiciel doit être mis à jour s´il possède une vulnérabilité connue. Supprimez les outils non utilisés.
5 Documentation
Les bulletins de sécurité du CERTA :
Débordement de mémoire dans ICQ : CERTA-2002-AVI-012
Antivirus2001 est un cheval de Troie : CERTA-2001-ALE-011
Alerte de virus LOVE-LETTER-FOR-YOU (ILOVEYOU) : CERTA-2000-ALERTE-001
Retour d´expérience du ver ILOVEYOU : CERTA-2000-REC-001
Propagation du ver LifeStages : CERTA-2001-ALE-009
Les bulletins de sécurité et notes d´incidents du CERT/CC sur le sujet :
Attaques par ingénierie sociale via l´IRC et messagerie instantanée :
http://www.cert.org/incident_notes/IN-2002-03.html
Propagation du ver I Love You :
http://www.cert.org/advisories/CA-2000-04.html
Propagation du ver Goner.scr :
http://www.cert.org/incident_notes/IN-2001-15.html
Vulnérabilité du client ICQ :
http://www.cert.org/advisories/CA-2002-02.html
Gestion détaillée du document
28 mars 2002
version initiale.
--------------------------------------------------
------------------------------
CERTA
2002-10-13
CERT® Advisory CA-2000-04 Love Letter Worm
Original release date: May 4, 2000
Last revised: May 9, 2000
Source: CERT/CC
A complete revision history is at the end of this file.
Systems Affected
Systems running Microsoft Windows with Windows Scripting Host enabled
Overview
The "Love Letter" worm is a malicious VBScript program which spreads in a variety of ways. As of 5:00 pm EDT(GMT-4) May 8, 2000, the CERT Coordination Center has received reports from more than 650 individual sites indicating more than 500,000 individual systems are affected. In addition, we have several reports of sites suffering considerable network degradation as a result of mail, file, and web traffic generated by the "Love Letter" worm.
I. Description
You can be infected with the "Love Letter" worm in a variety of ways, including electronic mail, Windows file sharing, IRC, USENET news, and possibly via webpages. Once the worm has executed on your system, it will take the actions described in the Impact section.
Electronic Mail
When the worm executes, it attempts to send copies of itself using Microsoft Outlook to all the entries in all the address books. The mail it sends has the following characteristics:
An attachment named "LOVE-LETTER-FOR-YOU.TXT.VBS"
A subject of "ILOVEYOU"
The body of the message reads "kindly check the attached LOVELETTER coming from me."
People who receive copies of the worm via electronic mail will most likely recognize the sender. We encourage people to avoid executing code, including VBScripts, received through electronic mail regardless of the sender without firsthand prior knowledge of the origin of the code.
Internet Relay Chat
When the worm executes, it will attempt to create a file named script.ini in any directory that contains certain files associated with the popular IRC client mIRC. The script file will attempt to send a copy of the worm via DCC to other people in any IRC channel joined by the victim. We encourage people to disable automatic reception of files via DCC in any IRC client.
Executing Files on Shared File Systems
When the worm executes, it will search for certain types of files and replace them with a copy of the worm (see the Impact section for more details). Executing (double clicking) files modified by other infected users will result in executing the worm. Files modified by the worm may also be started automatically, for example from a startup script.
Reading USENET News
There have been reports of the worm appearing in USENET newsgroups. The suggestions above should be applied to users reading messages in USENET newsgroups.
II. Impact
When the worm is executed, it takes the following steps:
Replaces Files with Copies of the Worm
When the worm executes, it will search for certain types of files and make changes to those files depending on the type of file. For files on fixed or network drives, it will take the following steps:
For files whose extension is vbs or vbe it will replace those files with a copy of itself.
For files whose extensions are js, jse, css, wsh, sct, or hta, it will replace those files with a copy of itself and change the extension to vbs. For example, a file named x.css will be replaced with a file named x.vbs containing a copy of the worm.
For files whose extension is jpg or jpeg, it will replace those files with a copy of the worm and add a vbs extension. For example, a file named x.jpg will be replaced by a file called x.jpg.vbs containing a copy of the worm.
For files whose extension is mp3 or mp2, it will create a copy of itself in a file named with a vbs extension in the same manner as for a jpg file. The original file is preserved, but its attributes are changed to hidden.
Since the modified files are overwritten by the worm code rather than being deleted, file recovery is difficult and may be impossible.
Users executing files that have been modified in this step will cause the worm to begin executing again. If these files are on a filesystem shared over a local area network, new users may be affected.
Creates an mIRC Script
While the worm is examining files as described in the previous section, it may take additional steps to create a mIRC script file. If the file name being examined is mirc32.exe, mlink32.exe, mirc.ini, script.ini, or mirc.hlp, the worm will create a file named script.ini in the same folder. The script.ini file will contain:
[script]
n0=on 1:JOIN:#:{
n1= /if ( $nick == $me ) { halt }
n2= /.dcc send $nick DIRSYSTEM\LOVE-LETTER-FOR-YOU.HTM
n3=}
where DIRSYSTEM varies based on the platform where the worm is executed. If the file script.ini already exists, no changes occur.
This code defines an mIRC script so that when a new user joins an IRC channel the infected user has previously joined, a copy of the worm will be sent to the new user via DCC. The script.ini file is created only once per folder processed by the worm.
Modifies the Internet Explorer Start Page
If the file <DIRSYSTEM>\WinFAT32.exe does not exist, the worm sets the Internet Explorer Start page to one of four randomly selected URLs. These URLs all refer to a file named WIN-BUGSFIX.exe, which presumably contains malicious code. The worm checks for this file in the Internet Explorer downloads directory, and if found, the file is added to the list of programs to run at reboot. The Internet Explorer Start page is then reset to "about:blank". Information about the impact of running WIN-BUGSFIX.exe will be added to this document as soon as it is available.
Sends Copies of Itself via Email
The worm attempts to use Microsoft Outlook to send copies of itself to all entries in all address books as described in the Description section.
Modifies Other Registry Keys
In addition to other changes, the worm updates the following registry keys:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
\MSKernel32
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Services\Win32DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
\WIN-BUGSFIX
HKCU\Software\Microsoft\Windows Scripting Host\Settings\Timeout
HKCU\Software\Microsoft\Internet Explorer\Main\Start Page
HKCU\Software\Microsoft\WAB\*
Note that when the worm is sending email, it updates the last entry each time it sends a message. If a large number of messages are sent, the size of the registry may grow significantly, possibly introducing additional problems.
III. Solution
Update Your Anti-Virus Product
It is important for users to update their anti-virus software. Some anti-virus software vendors have released updated information, tools, or virus databases to help prevent and combat this worm. A list of vendor-specific anti-virus information can be found in Appendix A.
Disable Windows Scripting Host
Because the worm is written in VBS, it requires the Windows Scripting Host (WSH) to run. Disabling WSH prevents the worm from executing. For information about disabling WSH, see:
http://www.sophos.com/support/faqs/wsh.html
This change may disable functionality the user desires. Exercise caution when implementing this solution.
Disable Active Scripting in Internet Explorer
Information about disabling active scripting in Internet Explorer can be found at:
http://www.cert.org/tech_tips/malicious_code_FAQ.html#steps
This change may disable functionality the user desires. Exercise caution when implementing this solution.
Disable Auto-DCC Reception in IRC Clients
Users of Internet Relay Chat (IRC) programs should disable automatic reception of files offered to them via DCC.
Filter the Worm in E-Mail
Sites can use email filtering techniques to delete messages containing subject lines known to contain the worm. For sites using unix, here are some possible methods:
Sendmail
Sendmail, Inc. has published information about blocking the worm in incoming email at:
http://www2.sendmail.com/loveletter
PostFix
Add the following line in /etc/postfix/header_checks:
/^Subject: ILOVEYOU/ REJECT
The main Postfix configuration file must contain the following line to enable the check :
header_checks = regexp:/etc/postfix/header_checks
Postfix must also be reloaded after this information is added.
Exim
A generic Windows-executable content-blocking filter has been produced for Exim. This will block messages with attachments whose extensions are vbs, as well as several other types that Windows may consider executable by default. The filter, which includes some supporting installation documention within the filter file itself, can be found at:
ftp://https://www.jeuxvideo.com//ftp.exim.org/pub/filter
Procmail
This procmail rule also deletes any messages with the Subject: line containing "ILOVEYOU":
: 0 D
* ^Subject:[[tab] ]+ILOVEYOU
/dev/null
Note that in all of these examples, [tab] represents a literal tab character, and must be replaced with a tab for them to work correctly.
It is important to note that these three methods, as described, do not prevent the worm from spreading if the Subject: line of the email has changed. Administrators can use more complicated procmail rules to block the worm based on the body of the email, but such methods require more processing time on mail servers, and may not be feasible at sites with high volumes of email traffic.
Exercise Caution When Opening Attachments
Exercise caution with attachments in email. Users should disable auto-opening or previewing of email attachments in their mail programs. Users should never open attachments from an untrusted origin, or that appear suspicious in any way.
Appendix A. Anti-Virus Vendor Information
Aladdin Knowledge Systems
http://www.aks.com/home/csrt/valerts.asp
Command Software Systems, Inc.
http://www.command.co.uk/html/virus/love.html
http://www.commandcom.com/virus/love.html
Computer Associates
http://www.ca.com/virusinfo/virusalert.htm
F-Secure
http://www.f-secure.com/ddownload-purchase/updates.html
Finjan Software, Ltd.
http://www.finjan.com/attack_release_detail.cfm?attack_release_id=34
McAfee / Network Associates
http://vil.nai.com/villibib/dispVirus.asp?virus_k=98617
http://www.cert.org/advisories/CA-2000-04/nai.dat
Proland Software
http://www.pspl.com/virusirus_info/worms/loveletter.htm
Sophos
http://www.sophos.com/virusinfo/analyses/vbsloveleta.html
http://www.sophos.com/virusinfo/analyses/trojloveleta.html
Symantec
http://www.symantec.com/avcenter/venc/data/vbs.loveletter.a.html
Trend Micro
http://www.antivirus.com/vinfo
Appendix B. Variants
The CERT Coordination Center has received reports of worms that are nearly identical or are very similar to the Love Letter worm. The information provided above applies to these variants except as noted below. This section is not intended to be comprehensive, and we are aware of reports involving additional variants not described here.
Joke / Very Funny
This variant changes several references to LOVE-LETTER-FOR-YOU in the source code to Very Funny. This primarily results in an email attachment name Very Funny.vbs. The email messages sent by this variant have a subject of "fwd: Joke", and an empty message body.
Mothers Day
The subject of this variant is "Thanks for your purchase!" and the body of the message contains:
We have proceeded to charge your credit card for the amount of $326.92 for the mothers day diamond special. We have attached a detailed invoice to this email. Please print out the attachment and keep it in a safe place. Thanks Again and Have a Happy Mothers Day!
This variant infects files as previously described, with the exception of jpg and jpeg files. Instead, this variant infects ini and bat in a similar way. Specifically, for files whose extension is ini or bat, it will replace those files with a copy of the worm and add a vbs extension. For example, a file named x.ini will be replaced by a file called x.ini.vbs containing a copy of the worm.
This variant also includes different URLs for the Internet Explorer Start Page.
--------------------------------------------------
------------------------------
The CERT Coordination Center thanks David Slade of Lucent Technologies for help in constructing this advisory; Christopher Lindsey for the providing the procmail rule; and Jeff Rife for catching an error in an earlier version of this advisory.
--------------------------------------------------
------------------------------
The following people were involved in the creation of this document: Jeff Carpenter, Cory Cohen, Chad Dougherty, Ian Finlay, Kathy Fithen, Rhonda Green, Robert Hanson, Jeff Havrilla, Shawn Hernan, Kevin Houle, Brian King, Jed Pickel, Joseph Pruszynski, Robin Ruefle, John Shaffer, and Mark Zajicek
--------------------------------------------------
------------------------------
This document is available from: http://www.cert.org/advisories/CA-2000-04.html
--------------------------------------------------
------------------------------
CERT/CC Contact Information
Email: cert@cert.org
Phone: +1 412-268-7090 (24-hour hotline)
Fax: +1 412-268-6989
Postal address:
CERT Coordination Center
Software Engineering Institute
Carnegie Mellon University
Pittsburgh PA 15213-3890
U.S.A.
CERT/CC personnel answer the hotline 08:00-17:00 EST(GMT-5) / EDT(GMT-4) Monday through Friday; they are on call for emergencies during other hours, on U.S. holidays, and on weekends.
Using encryption
We strongly urge you to encrypt sensitive information sent by email. Our public PGP key is available from
http://www.cert.org/CERT_PGP.key
If you prefer to use DES, please call the CERT hotline for more information.
Getting security information
CERT publications and other security information are available from our web site
http://www.cert.org/
To subscribe to the CERT mailing list for advisories and bulletins, send email to majordomo@cert.org. Please include in the body of your message
subscribe cert-advisory
--------------------------------------------------
------------------------------
NO WARRANTY
Any material furnished by Carnegie Mellon University and the Software Engineering Institute is furnished on an "as is" basis. Carnegie Mellon University makes no warranties of any kind, either expressed or implied as to any matter including, but not limited to, warranty of fitness for a particular purpose or merchantability, exclusivity or results obtained from use of the material. Carnegie Mellon University does not make any warranty of any kind with respect to freedom from patent, trademark, or copyright infringement.
--------------------------------------------------
------------------------------
Conditions for use, disclaimers, and sponsorship information
Copyright 2000 Carnegie Mellon University.
Revision History
May 4, 2000: Initial release
May 5, 2000: Updates to Postfix information
May 5, 2000: Fixed an error in the statement regarding the actions
of the worm when it checks for the existance of the
<DIRSYSTEM>\WinFAT32.exe file. We incorrectly
reported that if this file exists, then the value of the IE start page
will be changed. In fact, the value of the start page is changed if
the file does not exist. Our thanks to Jeff Rife for catching
this error.
May 5, 2000: Added information on variants
May 9, 2000: Updated affected site count
May 9, 2000: Added EXIM information
May 9, 2000: Clarified mIRC script description
Sujet : ====>> Zthe Topic a Moi <<=== | ß=)) ¡¡°
Répondre - Nouveau sujet - Liste sujets
Aller à la page : 1 2 3 4
Page suivante - >>Dernière page
profdephilo Posté le 04 août 2002 à 18:41:47
···l **l·········/*****\·····l **l··········
···l **l·······/**/···\**\···l **l··········
···l **l······l**l······l**l··l **l·········
···l **l__···\**\···/**/····l **l__·····
···l *****l·····\*****/·····l *****l······
···¯¯¯¯¯······¯¯¯········¯¯¯¯····
priere de ne pas effacer ce topic perso a wham!
Amour2MaVie Posté le 04 août 2002 à 18:45:04
ce signe, je l´ai deja vu sur un forum perdu...
profdephilo Posté le 04 août 2002 à 18:53:13
eeeeeeee...zzzzzzzzzzzzzzzzz
e................z-------------- zzzzz
e................z------------zzzz
e................z----------zzzz
eeeeeeee...z--------zzzz
e................z------zzzz
e................z-----zzzz
eeeeeeee...z---zzzzzzzzzzzzzz
profdephilo Posté le 04 août 2002 à 18:58:39
Par hazard personne ne saurait pourquoi mon signe Euro donne ca sur jv.com ? ?
==> Regardez ==> €
B0N0B0 Posté le 04 août 2002 à 20:38:50
Ouah je suis là pour l´inauguration prof !
0tacon Posté le 04 août 2002 à 20:39:56
Je suis aussi là Snake ! !
Frequence du Codec 189.95 !
profdephilo Posté le 04 août 2002 à 20:42:16
Bon premier objectif : les 87 messages effacer du forum guerre des consoles a refaire ici ! !
EZ-Toni Posté le 04 août 2002 à 23:05:22
EZ-Toni was here!
and will be here many times
objectif 10000000000 de messages
profdephilo Posté le 05 août 2002 à 13:22:15
En tout cas je reste en 2001 sur mon pc ! !
profdephilo Posté le 05 août 2002 à 13:22:49
Pour feinter Norton Antivirus 2000 ! ! !
comme ca je paye pas ! !
FrancisHUcast Posté le 05 août 2002 à 17:58:41
bijour mesdames
EZ-Toni Posté le 05 août 2002 à 20:45:39
bonjours mademoiselle!
EZ-Toni Posté le 06 août 2002 à 08:21:00
. ..+===+......+===+.......+====+......+===+...
. .
.||....))......||....))......||....||......||.....
. ..
. ;.||==//......||==//......||....||......||==
+...
. ..||............||...\\.......||....||...
. ..||.......
...U............U.....\\......+===+.......U.......
.
arggggggggggggggggggggggggggg plus que 3 mess ! !!!!
. Forum Final Fantasy 10 16.329 msg/sem
2. Forum Mario Sunshine 15.947 msg/sem
3. Forum Grand Theft Auto : Vice City 10.498 msg/sem
4. Forum L´entraineur Saison 2001/2002 6.972 msg/sem
5. Forum Super Smash Bros Melee 6.665 msg/sem
lool je vais battre ca grace a un prog de flood en C++ ! !!!!!
pfoui g fini mon telechargemnt sur KaZaA!!!
profdephilo Posté le 18 octobre 2002 à 23:04:14
. Forum Final Fantasy 10 16.329 msg/sem
2. Forum Mario Sunshine 15.947 msg/sem
3. Forum Grand Theft Auto : Vice City 10.498 msg/sem
4. Forum L´entraineur Saison 2001/2002 6.972 msg/sem
5. Forum Super Smash Bros Melee 6.665 msg/sem
lool je vais battre ca grace a un prog de flood en C++ ! ! !!!!
€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€€
flooding !