Slashdot Mirror


Zone-Spoofing Fixed for IE 7 Home Users

BeanBunny writes "The IE 7 dev team has essentially removed the intranet zone for Home users, resulting in a Web browser that is effectively invulnerable to a zone-spoofing attack. This security feature does not exist, however, on any installation that is part of a managed network. It also does not exist if you manually change the permissions on your Internet zone. However, in Windows Vista, both zones will be run in a 'protected mode,' something that allegedly prevents the invisible installation of code."

24 of 115 comments (clear)

  1. So . . . by Hey+Pope+Felcher+.+. · · Score: 4, Funny

    Everybody will be safe and secure, except of course for every single business in the known world?

  2. Protected Mode by BobPaul · · Score: 2, Informative

    Protected mode sounds kind of like the security wrappers Firefox Deer Park places around extensions.

  3. Re:First by tradiuz · · Score: 2, Funny

    You must have zone spoofed your way in.

  4. Remove the Internet Zone too by 4D6963 · · Score: 5, Funny
    They should also remove the Internet Zone too. if they do so, they'll have the most unvulnurable browser in the world.

    No browser is safer that IE if you prevent it from accessing a network!

    --
    You just got troll'd!
    1. Re:Remove the Internet Zone too by Cheapy · · Score: 2, Interesting

      "No browser is safer that IE if you prevent it from accessing a network!"

      Oh, I'm sure someone will still find a way.

      --
      Would you kindly mod me +1 insightful?
  5. Essentially... allegedly... I smell BS. by Ruff_ilb · · Score: 3, Insightful

    The OP doesn't seem too sure of this new security ploy - I don't know how they plan to implement this, but I think claiming to have a completely secure way of doing things doesn't help your security in the long run. Immune to today's typical attack, maybe, but if/when vista takes over as the OS of choice for most computers, its vulnerablilities will be found and exploited. I remember how SP2 was supposed to be some sort of security godsend, and when I first tried to install it it BSOD'd my computer every startup until I reformatted & reinstalled windows. That's slightly off topic, but it's an example of how good-intentioned 'security' fixes can do little more than break something that's been manually secured in the first place.

    --
    http://www.TheGamerNation.com/Forums
  6. Code signing will finally be more effective by stonebeat.org · · Score: 2, Interesting

    I like this move. Code signing of Active X controls will be more effective, since all code will have to signed before execution. Plus I.E. 7 has capability to create Whitelist of certain trusted signers, and reject everything else. See Do you Code Sign ??? for more details.

    1. Re:Code signing will finally be more effective by mpapet · · Score: 2, Insightful

      Hmmm,

      Maybe you fix one or two weaknesses, but there's so many others in windows it amounts to broken anyway. All this security blathering by MS is part of their "security" media message. What happens when Longwait gets here? More of the same.

      Code signing has it's own troubles, the biggest of which is the PHB or consumer that doesn't know or care.

      Who's the signer and how much will they charge? Annually? You squelch innovation as the entry barrier into the desktop just got raised. Not to mention if you make something the signer doesn't want to endorse.

      --
      http://www.maxineudall.com/2010/02/should-economists-be-sued-for-malpractice.html
  7. Hmmm.. by slashes · · Score: 3, Insightful

    Sounds like a good start for IE7. If vista comes around, I still won't use IE7 anyway. It's reputation is tarnished and no matter what Microsoft does, it won't bring back us Firefox, Opera, Safari and etc users.

    If I was Microsoft, I'd implent IE competely away from shell and work with it individualy. I think it'll solve the majority of the problems.

  8. Vista is taking a page from *nix by wyckedone · · Score: 3, Interesting

    IE7 is supposed to run in a fully protected mode by default. The protected mode is similar to a non-root user in *nix so that non-admin user programs do not have access to modify system files or settings. This is supposed to prevent spyware/adware that hooks into Windows processes and keep something one user may install from affecting other users of the system.

    Slowly but surely MS is learning a few good tricks from the Linux crowd.

    1. Re:Vista is taking a page from *nix by I'm+Don+Giovanni · · Score: 2, Funny

      "Those who do not understand Unix are condemned to reinvent it, poorly."

      Yep. Just look at Linux.

      --
      -- "I never gave these stories much credence." - HAL 9000
    2. Re:Vista is taking a page from *nix by I'm+Don+Giovanni · · Score: 3, Insightful

      Actually, in Vista, the default user account is non-admin, and IE7 runs in a mode even more limited than that.

      Slowly but surely MS is learning a few good tricks from the Linux crowd.

      Please get over yourself. The "Linux crowd" didn't invent the security system that's in Linux. If MS is learning from anyone, it's from the Unix crowd, which Microsoft itself is a part of, having created Xenix in the late 80's. But essentially, MS is learning from its own problems, which were created by migrating its userbase from a single-user no-security system (DOS, Win3.x, Win 9x) to a multi-user system with security (NT and its decendents). During this migration, the default accounts have been admin because that's what they were (essentially) in Win9x. In order to keep Win9x programs working, the default accounts in NT have been admin. This is changing with Vista, and has nothing to do with "learning" from Linux.

      --
      -- "I never gave these stories much credence." - HAL 9000
  9. Why do we need zones? by Anonymous Coward · · Score: 4, Insightful

    I still fail to understand why IE needs zones at all. If the security settings were less complicated and more reasonable, this wouldn't be a problem. Instead of trusted/intranet/internet, etc... why not a 'whitelist' and 'blacklist.' Simple and easy. Zones are complicated and confusing for most users, and many people end up setting the internet zone to low security so they can access their favorite Java/Flash/JS/ActiveX-addled whiz-bang website anyway.

  10. So we know that security will be covered in Vista by mattyohe · · Score: 4, Interesting

    But where is the innovation?

    I'll be honest, I haven't followed the Vista track that closely, but I have yet to hear of any evolutional or even revolutional features that I can look forward to. I read the slashdots and the diggs of the internet so, are these sources too Google and Apple happy to report on the Windows front? Or is there simply nothing to report?

    Other than Metro and their attempts at making their OS work like Tiger, what is left?

    Don't say security.

    --
    - what is the definition of simultanagnosia?! I've been meaning to look it up!
  11. How about... by nurb432 · · Score: 2, Interesting

    How about they just fix the damned holes instead?

    This is about as bad as putting duct tape over the rusted out holes in an old car: "see, its all better now"

    --
    ---- Booth was a patriot ----
    1. Re:How about... by wyckedone · · Score: 2, Insightful

      This is an attempt at fixing a hole. Zone-spoofing is a threat and MS realized that. It may not be the best fix but it is a start.

  12. Formula for Posting by Lee_in_KC · · Score: 2, Insightful

    {Rhetorical question}

    {Admit you don't know anything about what you are about to talk about but think your way is better}

    {Slam Microsoft}

    Does that about cover it? I think I can rig up some rotating cookies to accrue good karma here if I can just get curl to work in Cygwin correctly. :-)

    Seriously though, IE is the browser MANY companies choose and need to use so I think changes to improve security are good, doesn;t everyone else? If you want to contribute get on the Beta team. If you just want to complain, well, nevermind I guess you are in the right place.

  13. Always Trust Content From This Provider by Nom+du+Keyboard · · Score: 4, Insightful
    Always trust content from this provider.

    Everyone should know that checkbox well -- and leave it alone and unchecked.

    But where is the Never trust content from this provider ever again checkbox? The one I want to check every time I go to a site (all seemingly signed by the same certificate provider) that tries to install the 24-hour Time Manager, or You Must Click Yes to View This Site's Content when all trying to do is get out of a site I hadn't wanted in the first place.

    That's what I want my browser to offer me -- along with an inability for any web-site to affect my browser's basic functioning, like disabling the right mouse key. When is that patch coming?

    --
    "It's the height of ridiculousness to say for those 9 lines you get hundreds of millions."
  14. Misleading article title ? by Chaffar · · Score: 2, Insightful
    Microsoft To Beef Up Internet Explorer 7 Security

    Shouldn't it be something along the lines of "Microsoft removes yet another feature that proved to be a security threat"? It's not like they added a new security measure that beefs up Internet security. They just disabled the intranet zone, not too different than that feature that doesn't let you access /programfiles/ or /windows/ from the local network (dunno if you can circumvent that, but it is what happened to me by default)->(I think it's from SP2), which IMO is extremely annoying, because it makes me HAVE to change rooms to copy something from those folders.

    Ah, spin doctors, you never cease to amaze me...

  15. Re:In related news by Scarletdown · · Score: 2, Funny
    Microsoft is coming out with another version of it's popular XP operating system that is the most secure OS to date claims Balmer


    I thought they already did this years ago...

    http://ftp.pcworld.com/pub/screencams/mscement2.gi f

    --
    This space unintentionally left blank.
  16. My idea by Spy+der+Mann · · Score: 2, Insightful

    1) add to the file system the origin of the file, like an "evil bit". Local (0) = good, internet (1) = bad. Let's call this the "unsafe" bit.

    2) Files created by scripts / java applets / your internet browser will ALWAYS have their "unsafe" bit set to 1. Copying files (even with floppies) will also copy their internet bit.

    3) Never execute files with the "internet bit" set to one.

    So what about executables installed from the internet? You set their internet bit to 0. But here's the catch: They CANNOT set or unset other files' unsafe bits, that's something only the admin can do, with a program by the operating system.

    4) applets / scripts / etc cannot read or write files with the "internet bit" set to 0. They can only alter "internet" files.

    This will allow applets or scripts to use caches, etc, but they can't make a script and later tell windows shell to run it. This will trigger a security warning, and possibly ban the originating applet / script.

    Perhaps adding another bit "operating_system / user program" might improve this even further. os programs can create and alter os or user files, but a user program cannot modify an os file.

    Of course, this is only an idea, and i really haven't thought how viable it is.

  17. Sadly, the slashdot crowd WANTS IE to be insecure by I'm+Don+Giovanni · · Score: 5, Interesting

    All of the snide remarks in this thread indicate that most of you hate any improvement in IE for fear of losing some of your anti-M$ ammo. Deep down in your hearts, you WANT IE to be insecure, you WANT Windows to be insecure, you WANT Vista to bomb, just like you LOVED Win9x crashes. The fact is, Microsoft is addressing their security problems, just as they did their stability problems, and that scares you guys to death.

    You lost your stability argument, and slowly but surely, you're losing your security argument (the last major security outbreak happened back in 2003, and things will only get worse for you in Vista, where the default accounts are non-admin). Face the facts that you're going to have to find another argument ("free, as in beer", I suspect).

    --
    -- "I never gave these stories much credence." - HAL 9000
  18. Interesting Security Moves with IE7/Vista by ThinkFr33ly · · Score: 2, Informative

    IE 7 on Vista will run in sandbox that isn't really like anything out there today. (That I know of, anyway.) Even if you're an admin user, IE 7 is contained in such a way that it is not able to access anything outside of its sandbox without explicit permission.

    This helps even when non-admins are running IE 7 because it doesn't just prevent system changes (like adding a program to the startup folder), it also prevents changes to anything outside of the sandbox... including files that the non-admin user has full access to.

    They accomplish this by using the concept of a broker which IE 7 has to ask to do pretty much anything to the local system, independant of the privledges of the user running the browser. Want to save a file to your desktop? IE 7 must first ask the broker for permission. When the broker gets this request it then asks the user using a dialog. If the user approves, the broker then gets the appropriate information from IE 7 and saves the file for IE 7. At no point does the IE 7 process have access to the desktop or any of the users files.

    The net effect is isolating all dangerous code in the broker, which is far simpler and easier to audit and debug than IE 7, thereby decreasing the attack surface dramatically.

    For a detailed description of all this, check out the channel 9 video about it.

  19. Re:Sadly, the slashdot crowd WANTS IE to be insecu by freeweed · · Score: 3, Informative

    the last major security outbreak happened back in 2003

    Hahahahahahahaha (x1000)

    The last catastophic, taking-down-millions-of-systems, DoSing-the-Internet, making-headlines-all-over-the-world-for-days-after wards outbreak happened in 2003.

    Several major outbreaks have happened this year, Zobot for one. The only thing that saved the day was the uptake in XP installs; otherwise, we would have had another Code Red on our hands.

    Incremental improvement. A good thing for Microsoft, a good thing for average users, a good thing for the internet, yes. But "slowly but surely, you're losing your security argument"? Call me when a million Linux webservers get infected. Call me when desktop Linux starts spreading automatically executed worm code.

    Most importantly, call me when Linux sees as many viruses and/or outbreaks as its marketshare would imply. Not the almsot nonexistent numbers we see today. That always seems to be the argument, that it's a marketshare thing. So just keep in touch, and let me know when 5% (or whatever Linux is at) of viruses/worms/spyware is targetted at, and infecting, Linux. Then you might actually have a point.

    --
    Endless arguments over trivial contradictions in books written by ignorant savages to explain thunder in the dark.