Microsoft Issues Workaround For IE 0-Day
Orome1 writes "Microsoft has issued a security advisory with advice on how to patch a Internet Explorer zero-day vulnerability recently spotted being exploited in the wild by attackers that might be the same ones that are behind the Nitro attacks. News that there is a previously unknown Internet Explorer vulnerability that is actively being misused in the wild by attackers that are believed to be the same ones that are behind the Nitro attacks has reverberated all over the Internet yesterday."
Click
What does this even mean? Is it the same 0-day? Is it a different 0-day? Can we get some editing up in this bitch or what?
you just mentioned the same thing twice in your short review of the story
The work around is load firefox or chrome.
Have been for 13 years. Linux.
Disable ActiveX and then demand it runs to "Prompt" in both Internet AND Intranet????? This is NOT a "work-around." A work-around would be how to allow our users to continue running without being prompted to run or not run things they don't understand and don't want to.
Or install an alternate browser.
Sheesh, is the Internet really worth this crap? Really?
Seriously, I don't use IE at home but until Chrome, Firefox, or Opera have tight integration and customization that can be centralled managed (GPO) IE will be the defacto standard browser for a lot of businesses. As an IT Manager I have tried repeatedly to move to a different browser and the tools to manage them just aren't there.
"Hahaha those losers use IE, they suck they should just switch to chrome" are not helpful comments and show just how little you know about the many current business environments. Your beloved Chrome and Firefox, by their actions, don't want to be the default browsers in business. They just don't. That leaves us with IE which, despite these 0 days and standards issues, is superios in every way in a Windows comprate environment. Until that changes IE will be what many businesses use because browser management is just so easy it's automagic.
And those Linux folks, switching to Linux isn't helpful either until some sort of same tier GPO management alternative that has simple interpoability is available. We could actually drop Windows and go full linux if I could gain the control I get from a Windows environment.
Disclaimer: I use Firefox, Opera, Ubuntu, and Mint at home.
http://technet.microsoft.com/en-us/security/advisory/2757760
Linking from "Microsoft issued an advisory" to submitter's site is kinda lowbrow.
Just turn off your browser, period, and then it'll not get infected.
Thankfully, I run Windows 8 and IE 10. The future is secure. The future is Microsoft.
Less IE users.
I remember that when Microsoft bound IE to the OS back in Win95, IE is now everywhere. That Windows Explorer window? Now subject to IE attacks. That HTML pane in Outlook? Now subject to IE attacks. That help window in SomeGame 2.0? Now subject to IE attacks.
I'm not sure how true this is now, but a guess is that it's still much this way.
Keep the legacy IE6 engine for old apps and use webkit or gecko as the "new IE". Maybe even give it a new name to shake the reputation. Bing Bismuth? Windows Live Web?
captcha: exploits.
You are doing it wrong. You are creating a tightly integrated application with IE/browser. Bad idea from the start. Then you are locked in forever till someone funds another tight integration. Your benefiting from IE infrastructure, but the world is messed up b/c you are stuck in 1990s.
So pls stop doing it or stop calling whatever you created a browser and make sure you exclude them from external network usage so we do not have to fell the pain caused by you decisions.
BY THE WAY. If you have to control your employees so much find ones that you can trust.
It's not the browser but the underlying Operating System that is at fault.
distrowatch
AccountKiller
Workaround != patch.
"A plan fiendishly clever in its intricacies"- Homer Simpson
It never ceases to amuse me, the glazed look on peoples faces when they ask me how I deal with Windows viruses and I explain I don't use Windows ..
Distrowatch
AccountKiller
You speak with authority but do not understand the principles and abstractions.
It's called COM. Windows is based on COM. It allows components to be reused, which is good design and good practice.
This is the same concept as WebKit being a shared library on Linux and gnome help, gnome file manager and Epiphany importing it.
I they discovered a WebKit hole: waah waah whinge whinge there is a hole in Gnome Help - save us all from the 0-day
That complaining never happens but if Microsoft fall to the same thing, they get slated. Hardly fair is it?
Unless things have changed in the last ~2 years, Outlook rolls its own HTML/CSS/JavaScript engine to avoid IE issues like this.
Unfortunately, it opens Outlook up to their own HTML/CSS/JavaScript related bugs, and their implementation is half-assed like old versions of IE (that is, you can't expect HTML and CSS to work normally, even for features that Outlook implements).
Sorry, PTSD moment from having to "fix" HTML newsletters for Outlook once upon a time...
- chrish
Internet Explorer users don't check for updates let alone understand what zero-day means.
Oh, right. Fail IT departments who have kludged apps that require IE because the developers were lazy and stupid. In other words, slashdotters.
Find the actual advisory here: http://technet.microsoft.com/en-us/security/advisory/2757760
[Grumble]Should have been included in the post...[/Grumble]
Firefox Issues Workaround for IE 0-Day
http://getfirefox.com/
Chrome Issues Workaround for IE 0-Day
https://www.google.com/intl/en/chrome/browser/
Ya think too small
http://www.ubuntu.com/download
Jack of all trades,master of none
It allows components to be reused, which is good design and good practice
It's only good design practice if the shared components dont royally suck.
Submitter is a idiot.
Confucius say, "Find worm in apple - bad. Find half a worm - worse."
All but one supported edition of IE is affected: 2001s IE6, 2006s IE7, 2009s IE8 and last year’s IE9. Together, those browsers accounted for 53% of all browsers used worldwide. The only exception is IE10, the browser bundled with the new Windows 8, which does not contain the bug.
http://www.thetechnologygeek.org
"There's still the threat of compromised 3rd party ad servers spewing malware from otherwise credible sites. Safe browsing habits won't save you from that. Even if you know what you are doing there's always a chance that you can get hit." - by Anonymous Coward on Tuesday September 18, @11:36AM (#41374769)
IF you don't want to be tracked, & to get your speed/bandwidth back you paid for (as well as electricity, CPU cycles, RAM, & other forms of I/O as well), better "layered-security"/"defense-in-depth", reliability (vs. DNS poisoning redirection OR being "downed"), & even anonymity (to an extent vs. DNS request logs) + being able to "blow by" what you may feel are unjust blocks (in DNSBL's) & more...
---
APK Hosts File Engine 5.0++ 32-bit & 64-bit:
http://start64.com/index.php?option=com_content&view=article&id=5851:apk-hosts-file-engine-64bit-version&catid=26:64bit-security-software&Itemid=74
---
Custom hosts files gain me the following benefits (A short summary of where custom hosts files can be extremely useful - NOTE: The "TOP 5" Address YOUR concern, with ease, & with a tool/file your system ALREADY has, as does ANY BSD derived IP stack using OS, usually):
---
1.) Blocking out malware/malscripted sites
2.) Blocking out Known sites-servers/hosts-domains that are known to serve up malware
3.) Blocking out Bogus DNS servers malware makers use
4.) Blocking out Botnet C&C servers
5.) Blocking out Bogus adbanners that are full of malicious script content
6.) Getting you back speed/bandwidth you paid for by blocking out adbanners + hardcoding in your favorite sites (faster than remote DNS server resolution)
7.) Added reliability (vs. downed or misdirect/poisoned DNS servers).
8.) Added "anonymity" (to an extent, vs. DNS request logs)
9.) The ability to bypass DNSBL's (DNS block lists you may not agree with).
10.) Blocking out TRACKERS
11.) More screen "real estate" (since no more adbanners appear onscreen eating up CPU, Memory, & other forms of I/O too - bonus!)
12.) Truly UNIVERSAL PROTECTION (since any OS, even on smartphones, usually has a BSD drived IP stack).
13.) Faster & MORE EFFICIENT operation vs. browser plugins (which "layer on" ontop of Ring 3/RPL 3/usermode browsers - whereas the hosts file operates @ the Ring 0/RPL 0/Kernelmode of operation (far faster) as a filter for the IP stack itself...)
14.) Custom hosts files work on ANY & ALL webbound apps (browser plugins do not).
15.) Custom hosts files offer a better, faster, more efficient way, & safer way to surf the web & are COMPLETELY controlled by the end-user of them.
---
* There you go... & above all else IF you choose to try it for the enumerated list of benefits I extolled above?
Enjoy the program!
APK
P.S.=> Of course, THIS is NOT going to "go well" with 3 types of people out there online, profiting by advertising & nefarious exploits + more @ YOUR expense as the consumer:
---
A.) Malware makers & the like (botnet masters, etc./et al)
B.) ADVERTISERS - the TRULY offended ones, as it is their "lifeblood" in psychological attack galore, tracking, & more, etc.!
C.) Possibly webmasters (who profit by ad banners, but fail to realize that those SAME adbanners suck away the users' bandwidth/speed, electricity, CPU cycles, RAM, & other forms of I/O they PAY FOR, plus, adbanners DO get infested with malicious code, & if anyone wants many "examples thereof" from the past near-decade now? Ask!)
---
... apk
I got "suckered" by DCC transfer on IRC (got a "lemon" from a pal there no less I knew for years 1994-2000), & because of it?
Well - I decided to learn how to DO something about it & other threats online and, to share it with others!
The result? This below ( & yes, it works, IF followed "to the letter"):
To "immunize" a Windows system, I effectively use the principles in "layered security" possibles!
http://www.bing.com/search?q=%22HOW+TO+SECURE+Windows+2000%2FXP%22&go=&form=QBRE
I.E./E.G.-> I have done so since 1997-1998 with the most viewed, highly rated guide online for Windows security there really is which came from the fact I also created the 1st guide for securing Windows, highly rated @ NEOWIN (as far back as 1998-2001) here:
http://www.neowin.net/news/apk-a-to-z-internet-speedup--security-text
& from as far back as 1997 -> http://web.archive.org/web/20020205091023/www.ntcompatible.com/article1.shtml which Neowin above picked up on & rated very highly.
That has evolved more currently, into the MOST viewed & highly rated one there is for years now since 2008 online in the 1st URL link above...
Which has well over 500,000++ views online (actually MORE, but 1 site with 75,000 views of it went offline/out-of-business) & it's been made either:
---
1.) An Essential Guide
2.) 5-5 star rated
3.) A "sticky-pinned" thread
4.) Most viewed in the category it's in (usually security)
5.) Got me PAID by winning a contest @ PCPitStop (quite unexpectedly - I was only posting it for the good of all, & yes, "the Lord works in mysterious ways", it even got me PAID -> http://techtalk.pcpitstop.com/2007/09/04/pc-pitstop-winners/ (see January 2008))
---
Across 15-20 or so sites I posted it on back in 2008...
The IMPORTANT part, in some sample testimonials to the "layered security" methodology efficacy, is in my 'p.s.' below!
---
* The ONLY time I got infested was on IRC using DCC transfers (got a "lemon" from a pal no less - I too had to learn what the dangers are online & was my OWN "weakest link" but after that? Nothing since, due to my learning what's in the guide above I authored!)...
What's above? Helps... & even SUGGESTS what this EMET tool is doing for IE (and more - pure "layered-security"/"defense-in-depth" and yes, it works).
APK
P.S.=> Here's a testimonial from a fellow that did extremely well using what that security guide for Windows NT-based OS users I authored & what HE experienced for YEARS no less, for himself, family, friends, & yes - even CUSTOMERS and, of course, I've been enjoying the same...
http://www.xtremepccentral.com/forums/showthread.php?s=672ebdf47af75a0c5b0d9e7278be305f&t=28430&page=2
"I recently, months ago when you finally got this guide done, had authorization to try this on simple work station for kids. My client, who paid me an ungodly amount of money to do this, has been PROBLEM FREE FOR MONTHS! I haven't even had a follow up call which is unusual." - THRONKA, user of my guide @ XTremePcCentral
AND
"APK, thanks for such a great guide. This would, and should, be an inspiration to such security measures. Also, the pc that has "tweaks": IS STILL GOING! NO PROBLEMS!" - THRONKA, user of my guide @ XTremePcCentral
AND
It allows components to be reused, which is good design and good practice.
It's good practice except when those components are written by the company responsible for more rooted boxes than any other in history.
WebKit isn't closed code that's dripping with exploits, publicly known and otherwise. I can't tell if you're on the MS payroll or if you're really just that stupid.
In either case, please stop posting.
To be honest they have shipped more boxes than anyone in history.
WebKit has had its fair share of exploits over the years. I first worked with it when it was known as KHTML and have followed it over the years.
I work for a corporation that has source access for IE (MS shared source) and it's a remarkably well put together product which equals WebKit.
That is trading one problem for another. Chromium or Opera are the way to go.
MS suggests to use EMET (a tool that enfonrces ASLR and DEP), but Brian Krebs reports that this does not really plug the hole
Considering the fact that they were using Internet Explorer, i think Ubuntu would be a good idea.
Unless of course you want people spamming the internet with stupid questions relating to Linux.
I thought IE exploits only had an effect on people using MS Internet Explorer, and who the hell in his right mind does THAT anymore? Right, guys?
First of all, COM is not "principles and abstractions", it's just an binary interop technology.So please RTFM first. Second, WebKit is not a shared library. Bottom line: Microsoft IE sucks, and stupid idea of pushing IE everywhere (and screwed up layering in Windows) makes this clusterfuck even worse.