<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IE 7 code injection - CSA tune in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646481#M92069</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have experienced this issue with the final release of IE 7 on WinXP SP2, fully patched, running CSA 4.51 r649.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Nov 2006 01:06:05 GMT</pubDate>
    <dc:creator>Thor-Ryan</dc:creator>
    <dc:date>2006-11-08T01:06:05Z</dc:date>
    <item>
      <title>IE 7 code injection - CSA tune</title>
      <link>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646469#M92052</link>
      <description>&lt;P&gt;I'm running CSA 451 r649.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IE 7 likes to inject code from IEFRAME.DLL into all processes when a user clicks on one of the drop-down menus in the IE 7 GUI.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need a better solution than the default query rule triggered in the example below, since CSA caches the user response and for the next hour iexplore.exe will be allowed to inject code from anywhere into other apps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have a secure dyno-tune they can share that would allow the following behavior? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"The process 'C:\Program Files\Internet Explorer\iexplore.exe' (as user MYPC\User) attempted to insert code ('C:\WINDOWS\system32\IEFRAME.dll') into another process. All processes were targeted. The user was queried and a 'No' response was received."&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:17:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646469#M92052</guid>
      <dc:creator>Thor-Ryan</dc:creator>
      <dc:date>2019-03-10T10:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: IE 7 code injection - CSA tune</title>
      <link>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646470#M92053</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't have a tuning for you, but I can tell you what its doing (I reported the issue to Microsoft back in July...after much back and forth, they determined it was "external" to IE and not their problem).  The code injection enables the drop-down menus in IE7.  Examples are the Favorites button in the upper left and the "Page" and "Tools" buttons in the upper right.  You can see this if you answer the "allow this?" query with "No, and kill the process"...you'll see IE7 die after the first access to the buttons.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW: I don't work with the CSA team, I was asked to check out IE7 with IDM and IEV for the IPS product.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Oct 2006 15:31:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646470#M92053</guid>
      <dc:creator>scothrel</dc:creator>
      <dc:date>2006-10-24T15:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: IE 7 code injection - CSA tune</title>
      <link>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646471#M92054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I also contacted the IE 7 beta team, documented the issue for them, and they claimed it was a problem with CSA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Oct 2006 18:52:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646471#M92054</guid>
      <dc:creator>Thor-Ryan</dc:creator>
      <dc:date>2006-10-26T18:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: IE 7 code injection - CSA tune</title>
      <link>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646472#M92055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't seem to be getting this event with either CSA 4.0.3 or 5.1.  Is it specific to 4.5.x?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom S&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Oct 2006 19:11:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646472#M92055</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2006-10-26T19:11:33Z</dc:date>
    </item>
    <item>
      <title>Re: IE 7 code injection - CSA tune</title>
      <link>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646473#M92056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Coincidentally, a co-worker of mine had a popup blocker on his local machine, which does not have CSA installed.  It kept warning about IEFRAME.DLL trying to open a Trusted Site.  I highly doubt this is a CSA issue, but rather a weird technique the MS programmers are using.  I'm sure there will be many flaws found for that dll when IE7 goes mainstream.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Oct 2006 20:33:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646473#M92056</guid>
      <dc:creator>RichardSW</dc:creator>
      <dc:date>2006-10-26T20:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: IE 7 code injection - CSA tune</title>
      <link>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646474#M92057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good question.  We only run 4.51 here.  Has anyone else experienced this on 4.03 or 5.0/5.1?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Oct 2006 17:53:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646474#M92057</guid>
      <dc:creator>Thor-Ryan</dc:creator>
      <dc:date>2006-10-27T17:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: IE 7 code injection - CSA tune</title>
      <link>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646475#M92058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I confirm, same with 5.1-74.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Nov 2006 09:38:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646475#M92058</guid>
      <dc:creator>nodayoda3k</dc:creator>
      <dc:date>2006-11-02T09:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: IE 7 code injection - CSA tune</title>
      <link>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646476#M92059</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Same error or no error?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Nov 2006 05:28:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646476#M92059</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2006-11-06T05:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: IE 7 code injection - CSA tune</title>
      <link>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646477#M92060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Same warning from CSA 5.1 about iframe injecting.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Nov 2006 08:01:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646477#M92060</guid>
      <dc:creator>nodayoda3k</dc:creator>
      <dc:date>2006-11-06T08:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: IE 7 code injection - CSA tune</title>
      <link>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646478#M92061</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am curious about what is different in my setup.  I have all desktop type policies enabled and am not in test mode. I installed over a customized version of IE6.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am running IE 7 (released version) on CSA 4.0.3-737 and 5.1-074 on Windows XP SP2 fully patched machines and do not get these messages. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the rule description and type that is triggering these messages? &lt;/P&gt;&lt;P&gt;What version of IEframe.dll? (I have 7.0.5730.11)&lt;/P&gt;&lt;P&gt;Did these machines have the a pre-release version of IE7 installed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom S&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Nov 2006 22:06:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646478#M92061</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2006-11-06T22:06:25Z</dc:date>
    </item>
    <item>
      <title>Re: IE 7 code injection - CSA tune</title>
      <link>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646479#M92062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my case, yes...it was a prerelease version of IE 7 installed over XP-SP2.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Nov 2006 19:06:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646479#M92062</guid>
      <dc:creator>scothrel</dc:creator>
      <dc:date>2006-11-07T19:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: IE 7 code injection - CSA tune</title>
      <link>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646480#M92066</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We had several issues with pre-release versions that we don't have in the released version.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Nov 2006 23:25:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646480#M92066</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2006-11-07T23:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: IE 7 code injection - CSA tune</title>
      <link>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646481#M92069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have experienced this issue with the final release of IE 7 on WinXP SP2, fully patched, running CSA 4.51 r649.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Nov 2006 01:06:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ie-7-code-injection-csa-tune/m-p/646481#M92069</guid>
      <dc:creator>Thor-Ryan</dc:creator>
      <dc:date>2006-11-08T01:06:05Z</dc:date>
    </item>
  </channel>
</rss>

