views:

18

answers:

1

So I have a security issue with my fresh install of Outlook 2003 (on Windows 7 + Internet Explorer 8). I just received an email with an HTML page attached. I (stupidly) double clicked the attachment, which opened up IE, and which contained javascript that ran and took me to a malware site.

Some interesting facts:

(1) When I create an html file with javascript in it on my desktop and double click it, IE correctly refuses to execute the script. (2) When I send this html file to myself and open it, IE executes it!

It seems to have something to do with the magical folder C:\Users(username)\AppData\Local\Microsoft\Windows\Temporary Internet Files\OLK48

Why does it work this way? What setting do I change to fix this?

A: 

If i'm not mistaken you just got pwn3d by the Help Centre 0-day. 0-day means that it hasn't been fixed, so the only way to prevent this from happening is by stop using IE. If you care about security use Chrome, IE has by far the worst security track record of any browser.

You should also be running and Anti-virus, if you poor/cheap then use AVG.

Rook