Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Microsoft Plugs IE; Warns All Browsers At Risk (Test Your Browser Here)
TechWeb ^ | July 2, 2004 | Gregg Keizer

Posted on 07/03/2004 9:46:15 PM PDT by Eagle9

click here to read article


Navigation: use the links below to view more comments.
first previous 1-20 ... 101-120121-140141-160 ... 201-207 next last
To: Eagle9

Dang it man, I downloaded the patch from Microsoft last night myself and I still failed the test. I think I'll download Firefox and see what happens.


121 posted on 07/04/2004 12:00:46 PM PDT by pctech
[ Post Reply | Private Reply | To 1 | View Replies]

To: general_re

I think you're right; the menus aren't as deep and detailed as IEs or MSs usual offerings. But the GUI is so nice and the v7.1 is as fast or faster than IE, at least on my machines.

Thanks again for the assist of IE, g_r.


122 posted on 07/04/2004 12:04:02 PM PDT by 7.62 x 51mm (• Veni • Vidi • Vino •)
[ Post Reply | Private Reply | To 120 | View Replies]

To: 7.62 x 51mm
On the plus side, the fact that Moz 1.7 and Firefox 0.9 aren't affected tells me that the fix is already in the Mozilla codebase somewhere, so I expect that Netscape should - emphasis on should - be able to produce a patch for this fairly quickly.
123 posted on 07/04/2004 12:08:06 PM PDT by general_re (Drive offensively - the life you save may be your own.)
[ Post Reply | Private Reply | To 122 | View Replies]

To: 7.62 x 51mm

Oh, yeah - you're welcome ;)


124 posted on 07/04/2004 12:08:21 PM PDT by general_re (Drive offensively - the life you save may be your own.)
[ Post Reply | Private Reply | To 122 | View Replies]

To: Grampa Dave
My new SBC/Yahoo DSL downloaded the updates/patches in seconds. Then my computer installed them in about a minute. I shut down and restarted my computer to come back to Free Republic. All was done in less than 3 minutes.

Run the test again in post #1. You may need to manually set the security option outlined in post 1.

125 posted on 07/04/2004 12:15:32 PM PDT by js1138 (In a minute there is time, for decisions and revisions which a minute will reverse. J Forbes Kerry)
[ Post Reply | Private Reply | To 91 | View Replies]

To: Eagle9

My IE 6 passed...I don't know why yours didn't.


126 posted on 07/04/2004 12:18:44 PM PDT by neutrino (Against stupidity the very Gods themselves contend in vain.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Friend of thunder
I did the upgrade, Critical Update for ADODB.stream (KB870669) shut down my computer, restarted it and I am still was still vulnerable. Was that wrong upgrade?

Do this manually:

Internet Explorer users can stymie such spoofing attacks by disabling the “Navigate sub-frames across different domains” setting under Tools/Internet Options/Security.

127 posted on 07/04/2004 12:18:56 PM PDT by js1138 (In a minute there is time, for decisions and revisions which a minute will reverse. J Forbes Kerry)
[ Post Reply | Private Reply | To 103 | View Replies]

To: js1138

why didn't MS just fix it this way???


128 posted on 07/04/2004 12:26:02 PM PDT by Principled
[ Post Reply | Private Reply | To 127 | View Replies]

To: Principled
why didn't MS just fix it this way???

It's a useful option. You might as well ask why you should buy an expensive car, since it only attracts thieves. Please not that the problem includes all versions of Netscape and Opera. At one time the internet community thought this was a useful and desirable feature. So now it attracts evildoers, and we are supposed to blame the victims?

129 posted on 07/04/2004 12:51:56 PM PDT by js1138 (In a minute there is time, for decisions and revisions which a minute will reverse. J Forbes Kerry)
[ Post Reply | Private Reply | To 128 | View Replies]

To: js1138

No complaints here! I'm just wondering hy they don't tell MSIE users to use this feature instead of devising some patch...


130 posted on 07/04/2004 1:06:00 PM PDT by Principled
[ Post Reply | Private Reply | To 129 | View Replies]

To: Principled

I installed the upgrade on two home machines. on one the setting changed automatically. On the other I had to set it manually. To be fair. the second machine has never been quite right since it was overrun by viruses last year. (I wasn't using a scanner, and my wife belongs to lots of newsgroups.) There may also be more to the patch than I know about.


131 posted on 07/04/2004 1:10:34 PM PDT by js1138 (In a minute there is time, for decisions and revisions which a minute will reverse. J Forbes Kerry)
[ Post Reply | Private Reply | To 130 | View Replies]

To: Sir_Ed

You are actually calling us cretins because we buy Macintoshes???

I wouldn't worry too much about what Bush2000 says. Nobody else does.

I think that he (she) either works for Microsoft or is one of those MSXX certification types who hasn't figured out that he (she) owes his (her) livelihood to the fact that Microsoft produces garbage software. Either way, it severely damages his (her) credibility on such issues.

I have made a very good living for quite a number of years, largely due to the fact that Microsoft has created such a huge market for people like me to come in and fix problems that would have never occurred in software produced by a good software company. For that reason, I really like Microsoft. If they were to start making good software, a lot of people like me would have to start actually working for a living.

But, it's because my time is so valuable and I therefore don't have time to fight Microsoft problems on my own computer, that I use Macs, for my own business and home computing. After all, every hour that I might have to spend fixing problems on my own computer, would be an hour that I couldn't bill to a client. I'm not trying to get people to switch to Macs. I will, however, admit to the vice of having a bit of pride, in being one of the relatively few people who has the sense to recognize a superior computing platform, in spite of the massive propaganda from Microsoft.

I just let what Bush2000 says, roll off my back, since he (she) is obviously a Microsoft bigot (for whatever reasons) and probably just feels a natural desire to preserve his (her) pride by slamming those who he (she) realizes, know that his (her) pride has no real foundation, in fact. I can't really blame him (her) for doing something that I might well do, if I had bought into the Microsoft propaganda and were stuck using a WinTel box.

 

132 posted on 07/04/2004 1:13:15 PM PDT by Action-America (Best President: Reagan * Worst President: Klinton * Worst GOP President: Dubya)
[ Post Reply | Private Reply | To 60 | View Replies]

To: pctech; 7.62 x 51mm; Principled; Friend of thunder; Ethrane; Eagle9
I think the ADODB patch, and the FRAMES vulnerability are two separate things. You can't use the 'frames test' shown here to test if the ADODB patch was successful. The later is very difficult to test, and security experts says it is ineffective. In all the Netscape spinoffs, Firefox/Mozilla etc, when you can't find a user interface to change some option, try entering the URL   about:config
THAT will give you a long list of options you can 'tweak'. Do a google search, and read up on anything there that looks interesting before you change any options. Try clicking the icon at the bottom of post 67. In my opinion, MS has cared more for internet-commerce concerns, than for privacy/security concerns. Almost all the security problems that a (Windows/I.E.) combination has, are NOT an issue with a (Windows/non-Microsoft browser) combination. And the modifying of other people's web content by tricking 'frames' has almost always been associated with evil-doers. There wre even some lawsuits that were supposed to plug that practice, but it seems they failed to correct it at microsoft.

It seems that Netscape 4.77 (circa 1999) did NOT have the frames vulnerability and that matches my recollection of how frames worked back then. But when IE came out with the OPPOSITE settings as a default, some of the other (newer) browsers apparently felt they had to follow suit or else they wouldn't be compatible with greenhorn website developers that ONLY developed and tested things with an IE browser.

133 posted on 07/04/2004 1:20:53 PM PDT by Future Useless Eater (FreedomLoving_Engineer)
[ Post Reply | Private Reply | To 128 | View Replies]

To: js1138
users can stymie such spoofing attacks by disabling the “Navigate sub-frames across different domains” setting under Tools/Internet Options/Security.

Thank you! That works.

I assume there times that I would want that this enabled or is this (the ability to navigate sub-frames across different domains) something that, while useful, is too easily exploitable by evildoers?

134 posted on 07/04/2004 1:48:43 PM PDT by Friend of thunder (No sane person wants war, but oppressors want oppression.)
[ Post Reply | Private Reply | To 127 | View Replies]

To: Principled
Principled, here is the link to the Firefox 0.9.1 download.

http://texturizer.net/firefox/download.html

Firefox is what used to be Firebird, but they ran into another trademark problem and had to change the name again. Before Firebird, it was Phoenix. But, under any name, it has always been a very good browser. The release of 0.8 and the more recent 0.9.1 marks the move from being a very good browser, to a really fine browser.

 

135 posted on 07/04/2004 1:54:15 PM PDT by Action-America (Best President: Reagan * Worst President: Klinton * Worst GOP President: Dubya)
[ Post Reply | Private Reply | To 130 | View Replies]

To: Friend of thunder

Apparently this "feature" was a bad idea and should be disabled by default.


136 posted on 07/04/2004 1:57:50 PM PDT by js1138 (In a minute there is time, for decisions and revisions which a minute will reverse. J Forbes Kerry)
[ Post Reply | Private Reply | To 134 | View Replies]

To: WestVirginiaRebel
Of course, this doesn't mean that I don't think that Microsoft are a bunch of greedy incompetents.

By my understanding, a lot of DRM these days is predicated upon the ability to embed code within a protected digital content file; under Microsoft's Palladium architecture, such embedded code would be encrypted (most likely with a one-way encryption algorithm so that companies could encrypt code that would run on others' machines without being able to decrypt others' code). Does anyone know if this is how things would work?

If so, can anyone spell "virus heaven"?

137 posted on 07/04/2004 2:46:37 PM PDT by supercat (Why is it that the more "gun safety" laws are passed, the less safe my guns seem?)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Sir_Ed
You are actually calling us cretins because we buy Macintoshes???

Do you always reply to posts that are addressed to other people as if they'd been addressed to you personally? Just curious. Because I wasn't addressing you -- or soliciting your opinion.
138 posted on 07/04/2004 3:16:16 PM PDT by Bush2000
[ Post Reply | Private Reply | To 60 | View Replies]

To: All; DreadCthulhu
But the latest versions of Mozilla & Firefox have this problem fixed; but Internet Explorer is still vunerable - I ran Windows Update 20 minutes ago, and IE still failed that security test.

You don't need a patch to fix this problem. Choose Tools | Internet Options | Security | Navigate Sub-Frames Across Different Domains | Disable. Takes 5 seconds. Done.
139 posted on 07/04/2004 3:18:25 PM PDT by Bush2000
[ Post Reply | Private Reply | To 53 | View Replies]

To: FastCoyote; Dominic Harr; All
Hmmm, some of us cretins have been running the Mozilla strains for quite a while and haven't been affected.

Neither has any IE user. I'd like anyone to point out a single user who was directly attacked by this hack. Bottom line: Nobody was. The threat is theoretical only -- and requires you to traverse to a malicious website. Hackers can't force you to go there; consequently, the actual threat is near zero to the average user.
140 posted on 07/04/2004 3:21:24 PM PDT by Bush2000
[ Post Reply | Private Reply | To 94 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-20 ... 101-120121-140141-160 ... 201-207 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson