Slashdot Mirror


Widespread Attacks Exploit Newly-Patched IE Bug

itwbennett writes "The first widespread attack to leverage the Internet Explorer flaw that Microsoft patched in an emergency update Thursday morning has surfaced. By midday Thursday Symantec had spotted hundreds of Web sites that hosted the attack code. The attack installs a Trojan horse program that is able to bypass some security products and then give hackers access to the system, said Joshua Talbot, a security intelligence manager with Symantec. Once it has infected a PC, the Trojan sends a notification e-mail to the attackers, using a US-based, free e-mail service that Symantec declined to name." Relatedly, reader N!NJA was among several to point out that Microsoft has apparently been aware of this flaw since September.

9 of 141 comments (clear)

  1. kind of makes you wonder by v1 · · Score: 5, Interesting

    in TFA: The flaw was in the Microsoft Security Response Center's (MSRC) queue to be fixed in the the next batch of patches due in February but the targeted zero-day attacks against U.S.

    Kinda makes you wonder just how many of these critical security bugs IE currently has in their queue to be fixed "sometime in the near future"?

    And at the same time you have to wonder just how nasty some of the others are that haven't made the cut yet, just waiting to become the next "zero day we own your computer, again"? We see how big of an issue this is, and MS was clearly in no hurry to fix it, so you'd have to assume that there are at least a few more of these that they know about and aren't fixing yet.

    --
    I work for the Department of Redundancy Department.
    1. Re:kind of makes you wonder by BartholomewBernsteyn · · Score: 5, Insightful

      That is the main problem with closed source software; in the event of a security hole, you as a customer / company are left to the mercy / arrogance of your software vendor to patch the flaw. Until he does, you can do nothing but become increasingly concerned, since you're left to the increasing danger of having your machine compromised in the meantime. This might be the right time to educate people about the main merit of open source software: As soon as a security hole is discovered, virtually anyone can contribute to a timely resolution. 0day? Fixed tomorrow!

    2. Re:kind of makes you wonder by b4dc0d3r · · Score: 5, Insightful

      I'm a software developer. I have a list of things I need to fix, some things are higher priority. We set a date, and work as many patches as we can toward that date, into a single release or patch. Makes it easier to test when you bundle several things together, and can test 5 patches with a single test case instead of individually. That makes the cycle more efficient.

      Now, a large company would have more patches, and more would be high priority. So they fix what they can, that makes sense. Open the bug list, sort by priority, own one (or get assigned one). To the developer, this is just one of several (hundred?) problems on the list. Management has to increase the priority based on input from triage.

      The entire world might know a defect is a security vulnerability, but if it's not made clear to the triage guy, it will sit as "possible denial of service" medium or medium-well priority until the known vectors are taken care of.

      Thinking about it this way makes Microsoft's blunders understandable. Not forgivable of course. My customer sends me a bug report and says "gwah, you're exposing my entire database to everyone fix it now or face a lawsuit!!!!eleventy". I say, let's take a look, we find out that yes you can see the entire data set - after you enter your credentials and only while on your company's network, and you just sent a mail to your competitor with your credentials in it. Change your password, WONTFIX. In other words, MS has to have good info in order to decide how to prioritize.

      At the same time, they have to keep their customers and shareholders happy, so while the triage guy says "this is the worst bug ever in the history of everything and it needs to be fixed yesterday" the company itself says to the employee "sure, but follow all processes and have it reviewed and put it in the next patch cycle and we'll test all of them next week and prepare for a release next week."

      Then to its customers and shareholders it says "A small, hard-to-exploit exploit has been found and even though ASLR and DEP and sandboxing are in place, someone might after a million failures be able to exploit this exploit so we've decided to be proactive and fix this exploit. We haven't heard of anyone exploiting this exploit, but we didn't really ask any of our friends in the malicious software industry - but that was just because we didn't want to tip our hand. Your security is, after all, very important to us. Exploit."

      In short: there are more than we'll ever know.

    3. Re:kind of makes you wonder by mpe · · Score: 5, Insightful

      That is the main problem with closed source software; in the event of a security hole, you as a customer / company are left to the mercy / arrogance of your software vendor to patch the flaw.

      Or even admit that there actually is a flaw. Microsoft were told about this months ago and there's no reason to believe that the first person to find a flaw with be a "white hat".

  2. threat? by clarkn0va · · Score: 4, Insightful

    Microsoft has apparently been aware of this flaw since September.

    Further evidence that the only "threat" as far as MS is concerned is the threat of a damaged public perception. Although I suppose that's an improvement in itself.

    --
    I am literally 3000 tokens away from the chaotic crossbow --Stephen
    1. Re:threat? by 1s44c · · Score: 5, Informative

      I just laugh. I haven't had to reformat the drive even once since I obscured IE.

      If you use windows without IE you are still very much at risk from the many other windows holes. You will cracked sooner or later and you may not even notice.

    2. Re:threat? by v1 · · Score: 4, Insightful

      What's unfortunate here is there's still a lot of people out there that don't understand why some security researchers publish security bugs they find. It's issues like this where "We reported this to you FOUR MONTHS AGO and you haven't fixed it yet. We're going public with it tomorrow." Oh noes! Everyone's computer getting owned, it's all your fault, you should keep security bugs QUIET so we have time to fix them!.

      Ya, right, whatever. They don't want the researchers to keep the bugs quiet so they "have time to fix them". Clearly four months is more than enough time to fix anything important. So, just how many more of these critical security bugs are we continuing to keep under wraps until someone exploits them before getting around to fixing? The logical conclusion is the researchers should give companies like MS a flat 30 days notice, and then go public immediately after that. At least we'd be getting the bugs patched 35 days after discovery, instead of 130 days. Either way, the amount of exposure we experience is the same, they're going to drag their feet until someone lights a fire under them. The only one this "irresponsible disclosure" hurts is the publisher. In the end, it helps the users, because the publishers now have a concrete deadline to avoid losing face, rather than "lets hope no one else discovers this before spring".

      We don't need them gambling with our security, and that's exactly what they're pushing with their cries for "responsible disclosure".

      --
      I work for the Department of Redundancy Department.
    3. Re:threat? by nmb3000 · · Score: 4, Informative

      IE market share is below 40%

      Anyone who uses w3schools's browser stats as a reference for general browser usage needs to get knocked on the head a few times. That is a perfect example of biased results due to the nature of the sample.

      A better number is about 62%.

      --
      "What do you despise? By this are you truly known." --Princess Irulan, Manual of Muad'Dib
      /)
  3. Re:Exactly how does it work. by Arancaytar · · Score: 5, Informative

    Once Windows is compromised (by a sophisticated worm, not something that places advertisements in IE), there is very little a user can do that the worm cannot prevent or bypass.

    The Windows settings assistant may nod and smile, and say the port is closed, while the worm is using it in the background. You might see that if you look at the router's logs, but inside Windows the worm can control what you see or do.