Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

MS warns over zero-day IE bug
the register ^

Posted on 12/23/2010 10:13:08 AM PST by Gomez

Microsoft warned on Wednesday of a new zero-day vulnerability in Internet Explorer.

The flaw creates a means for hackers to inject malware onto vulnerable systems, providing surfers are first tricked into visiting booby-trapped websites. As such the flaw poses a severe drive-by download risk.

All established version of IE (from 6 to 8) are affected. It's unclear whether or not the IE 9 beta is similarly vulnerable. The flaw reportedly involves the handling of Cascading Style Sheets by Microsoft's browser software. The bug first came to light on the seclists.org full disclosure mailing list earlier this month.

A module exploiting the bug – which is noteworthy because it defeats Data Execution Prevention (DEP) and Address Space Layout Randomisation (ASLR) security defences in Microsoft products – has been added by the Metasploit project.

No patch is available but Redmond has published an advisory explaining how to mitigate against possible attack.

A more detailed discussion of the flaw can be found in a blog post by Paul Duckin of Sophos here.


TOPICS: Computers/Internet
KEYWORDS: malware; microsofttax

1 posted on 12/23/2010 10:13:09 AM PST by Gomez
[ Post Reply | Private Reply | View Replies]

To: ShadowAce

ping


2 posted on 12/23/2010 10:13:53 AM PST by Gomez (shibboleet)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Gomez

“providing surfers are first tricked into visiting booby-trapped websites”

which, as always, could be disney.com or anything provided they get into the banner ad system


3 posted on 12/23/2010 10:14:45 AM PST by Christian Engineer Mass (Leftys who zone in on Palin miss the point. America's not about single figures. That's for NK/Cuba.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Gomez

I have XP but I don’t use IE. Who uses IE?


4 posted on 12/23/2010 10:15:22 AM PST by ReneeLynn (Socialism is SO yesterday. Fascism, it*s the new black. Mmm Mmm Mmm.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Gomez

I am assuming this threat is fully mitigated by simply using a non-Microsoft browser for web surfing. Yes?


5 posted on 12/23/2010 10:19:01 AM PST by so_real ( "The Congress of the United States recommends and approves the Holy Bible for use in all schools.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Gomez

God Bless FireFox.


6 posted on 12/23/2010 10:25:19 AM PST by Le Chien Rouge
[ Post Reply | Private Reply | To 1 | View Replies]

To: ReneeLynn

>>I have XP but I don’t use IE. Who uses IE?<<

I remember when I switched to Firefox several years ago. Before that I had adaware running constantly, and constantly clearing stuff off my computer.

About six months after installing Firefox, I uninstalled Ad aware. I could have done it immediately, but I wanted to be safe. :)


7 posted on 12/23/2010 10:36:31 AM PST by RobRoy (The US Today: Revelation 18:4)
[ Post Reply | Private Reply | To 4 | View Replies]

To: ReneeLynn

I use IE for one thing only, corporate webmail access when I don’t have my laptop.


8 posted on 12/23/2010 10:38:47 AM PST by Cletus.D.Yokel (Islam is a violent and tyrannical political ideology and has nothing to do with "religion".)
[ Post Reply | Private Reply | To 4 | View Replies]

To: RobRoy

I haven’t used Firefox. I am probably the only Microsoft Windows user using Safari.

Safari is ok.


9 posted on 12/23/2010 10:41:16 AM PST by archivist007
[ Post Reply | Private Reply | To 7 | View Replies]

To: Gomez

Thanks!


10 posted on 12/23/2010 10:41:22 AM PST by MeganC (January 20, 2013 - President Sarah Palin)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ReneeLynn

“I have XP but I don’t use IE. Who uses IE?”

You do. Even if you use another browser on your XP machine the browser runs on top of the Windows Kernel and IE is integral to that kernel.


11 posted on 12/23/2010 10:43:09 AM PST by MeganC (January 20, 2013 - President Sarah Palin)
[ Post Reply | Private Reply | To 4 | View Replies]

To: archivist007

If I could remember how to post a pic you would see me raising my hand.

I was raised on Apple and Mac. I bought an Acer last year because, with 6 kids, I couldn’t justify the cost of a new Mac (we won our last one). I use Safari because I can not stand all the bars across the top of the screen. By the time all the bars load, slllowwwwlllyyy, there is one inch of page under them (an exaggeration but it seems like it) It is very clean looking and I can find things much easier mostly because I am used to it.


12 posted on 12/23/2010 10:48:42 AM PST by momto6
[ Post Reply | Private Reply | To 9 | View Replies]

To: Gomez

FireFox + NoScript is the way to go.


13 posted on 12/23/2010 10:58:00 AM PST by MarineBrat (Better dead than red!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: momto6
If I could remember how to post a pic you would see me raising my hand. I was raised on Apple and Mac. I bought an Acer last year because, with 6 kids, I couldn’t justify the cost of a new Mac (we won our last one). I use Safari because I can not stand all the bars across the top of the screen. By the time all the bars load, slllowwwwlllyyy, there is one inch of page under them (an exaggeration but it seems like it) It is very clean looking and I can find things much easier mostly because I am used to it.

Example on posting a picture:

img src = "http://chasness.files.wordpress.com/2008/06/tomorrow_never_dies.jpg" width=555 height=755

Just put a < before img and a > after height=755 and the image would show up. The height and width may need to be changed so the picture is displayed correctly.

<>

My dad uses Internet Explorer and gives me a hard time using Safari. I don't think he has used any other browser, however. I have no idea why he hasn't though.

14 posted on 12/23/2010 11:12:52 AM PST by archivist007
[ Post Reply | Private Reply | To 12 | View Replies]

To: archivist007
Like this?
15 posted on 12/23/2010 11:32:28 AM PST by momto6
[ Post Reply | Private Reply | To 14 | View Replies]

To: Gomez
Zero Day. Hmmmmm....maybe that's what Janet Napolitano was talking about the other day when she said that the TSA was working hard 24/7 364 days a year. We're screwed!!
16 posted on 12/23/2010 11:49:50 AM PST by rickomatic
[ Post Reply | Private Reply | To 1 | View Replies]

To: momto6
1sm111 Pictures, Images and PhotosLike this?

Yes.

17 posted on 12/23/2010 12:03:57 PM PST by archivist007
[ Post Reply | Private Reply | To 15 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson