Major "hole" / exploit found in IE7

Post Reply
Paolo
Articles: 0
Posts: 9709
Joined: Wed May 16, 2001 8:53 am

Posting Rank

Major "hole" / exploit found in IE7

Post by Paolo »

From the BBC:

http://newsvote.bbc.co.uk/mpapps/pageto ... 8.stm?ad=1

Users of Microsoft's Internet Explorer are being urged by experts to switch to a rival until a serious security flaw has been fixed.

The flaw in Microsoft's Internet Explorer could allow criminals to take control of people's computers and steal their passwords, internet experts say.

Microsoft urged people to be vigilant while it investigated and prepared an emergency patch to resolve it.

Internet Explorer is used by the vast majority of the world's computer users.

"Microsoft is continuing its investigation of public reports of attacks against a new vulnerability in Internet Explorer," said the firm in a security advisory alert about the flaw.

Microsoft says it has detected attacks against IE 7.0 but said the "underlying vulnerability" was present in all versions of the browser.

Other browsers, such as Firefox, Opera, Chrome, Safari, are not vulnerable to the flaw Microsoft has identified.

Browser bait

"In this case, hackers found the hole before Microsoft did," said Rick Ferguson, senior security advisor at Trend Micro. "This is never a good thing."

As many as 10,000 websites have been compromised since the vulnerability was discovered, he said.

"What we've seen from the exploit so far is it stealing game passwords, but it's inevitable that it will be adapted by criminals," he said. "It's just a question of modifying the payload the trojan installs."

Said Mr Ferguson: "If users can find an alternative browser, then that's good mitigation against the threat."

But Microsoft counselled against taking such action.

"I cannot recommend people switch due to this one flaw," said John Curran, head of Microsoft UK's Windows group.

He added: "We're trying to get this resolved as soon as possible.

"At present, this exploit only seems to affect 0.02% of internet sites," said Mr Curran. "In terms of vulnerability, it only seems to be affecting IE7 users at the moment, but could well encompass other versions in time."

Richard Cox, chief information officer of anti-spam body The Spamhaus Project and an expert on privacy and cyber security, echoed Trend Micro's warning.

"It won't be long before someone reverse engineers this exploit for more fraudulent purposes. Trend Mico's advice [of switching to an alternative web browser] is very sensible," he said.

PC Pro magazine's security editor, Darien Graham-Smith, said that there was a virtual arms race going on, with hackers always on the look out for new vulnerabilities.

"The message needs to get out that this malicious code can be planted on any web site, so simple careful browsing isn't enough."

"It's a shame Microsoft have not been able to fix this more quickly, but letting people know about this flaw was the right thing to do. If you keep flaws like this quiet, people are put at risk without knowing it."

"Every browser is susceptible to vulnerabilities from time to time. It's fine to say 'don't use Internet Explorer' for now, but other browsers may well find themselves in a similar situation," he added.
bobbie (imported)
Articles: 0
Posts: 1563
Joined: Mon Dec 09, 2002 5:24 pm

Posting Rank

Re: Major "hole" / exploit found in IE7

Post by bobbie (imported) »

You wounder why people want to keep the browser a separate program not part of the operating system.
IbPervert (imported)
Articles: 0
Posts: 801
Joined: Wed Jan 10, 2007 6:13 pm

Posting Rank

Re: Major "hole" / exploit found in IE7

Post by IbPervert (imported) »

I use Firefox with no script add on installed. Plus you need a good firewall plus anti virus program like Norton Internet Security 2009
Paolo
Articles: 0
Posts: 9709
Joined: Wed May 16, 2001 8:53 am

Posting Rank

Re: Major "hole" / exploit found in IE7

Post by Paolo »

Funny how, in less than 24 hours of this announcement, Firefox released 305 up from 304 with "security fixes". Still nothing from Micro$haft.
Castroboi (imported)
Articles: 0
Posts: 64
Joined: Sun Aug 31, 2008 4:41 am

Posting Rank

Re: Major "hole" / exploit found in IE7

Post by Castroboi (imported) »

This is one of the big reasons I vowed never to own another Microsoft made product, and instead decided to go buy an iMac.
ramses (imported)
Articles: 0
Posts: 628
Joined: Thu May 24, 2007 3:23 pm

Posting Rank

Re: Major "hole" / exploit found in IE7

Post by ramses (imported) »

The software patch, which is expected to be issued today, can be downloaded from:

www.update.microsoft.com/windowsupdate/v6/default.aspx

The patch will download to some computers automatically.
micropenis (imported)
Articles: 0
Posts: 235
Joined: Sun Mar 18, 2007 10:37 pm

Posting Rank

Re: Major "hole" / exploit found in IE7

Post by micropenis (imported) »

ramses (imported) wrote: Thu Dec 18, 2008 11:19 am The software patch, which is expected to be issued today, can be downloaded from:

www.update.microsoft.com/windowsupdate/v6/default.aspx

The patch will download to some computers automatically.

The patch has been issued. I just got it. I still prefer Firefox. It has fewer problems and can be set to clear all browsing history every time you close.
Post Reply

Return to “Archive Technical Help”