Skip to comments.
Microsoft Plugs IE; Warns All Browsers At Risk (Test Your Browser Here)
TechWeb ^
| July 2, 2004
| Gregg Keizer
Posted on 07/03/2004 9:46:15 PM PDT by Eagle9
click here to read article
Navigation: use the links below to view more comments.
first previous 1-20 ... 41-60, 61-80, 81-100 ... 201-207 next last
To: Hawkeye's Girl
I think it does work though in Firefox 8 on Linux...
To: ShadowAce
Just tested again, looks like Firefox .8 has the problem running on Linux.
To: Eagle9
Thanks for posting this important information. I have just finished installing a crital patch from Microsoft.
Here's hoping!
To: All
i have a MAC and use Safari. It failed the test. I guess there'll be an update soon. Anyone have any suggestions on what to do in the meantime?
To: Swordmaker
While Secunia DID successfully inject its content onto the page, the return to the page did not replicate that injection
i guess that's what happened to me too then. so maybe i don't have to worry. please explain what replicating the injection means. thanks
To: freedom moose
Firefox is available for the Mac, and the latest version doesn't have this flaw. Try that for now. And the latest Windows Update DOES NOT fix this bug in IE. I just updated earlier & IE failed the test. Just a warning for people.
To: Eagle9; EGPWS; WestVirginiaRebel; First_Salute; backhoe; Byron_the_Aussie; TexasTransplant; ...
The update, which Microsoft tagged as Critical, isn't a patch per se, but rather an change to Windows that disables the ADODB.Stream object
FYI, the Internet Storm Center tested this latest Microsoft/IE 'fix' and found it
inadequate to stop hackers...
"...even after 'ADODB.Stream' is disabled, it is still possible to launch programs on the users system without user interaction."
A related suggestion was distributed
by security experts this week that could ALSO be of interest. They reiterate an MS security note (Microsoft Knowledge Base Article 833633) concerning the "Local Machine zone"...
For those of you that don't mind tinkering under the hood" of your computer such as to tighten ALL the security settings in every zone with: Control Panel --> Internet Options --> Security
MS announced a FIFTH security zone NOT shown in that tool with suggestions of tightening things THERE as well...
The control panel tool shows only these four zones:
- Trusted sites
- Local intranet
- Internet
- Restricted sites
The 5th (even higher level) zone is known as "Local Machine zone", and the MS article suggested it may be helpful for the security conscious, in some cases to even
strengthen some security settings there.
"a malicious user may try to take advantage of the power of the Local Machine zone to elevate their permissions and to run arbitrary code on your computer."
Those zone settings can only be tweaked using the registry editor (regedit), and the changes do the following for the Local Machine zone:
- Disables ActiveX Controls and plug-ins
- Disables Active scripting
- Disables data sources across domains
- Disables Java
If any of you say "you no longer use IE", be aware that a Windows computer STILL HAS SEVERAL OTHER programs that venture out on the internet and can be at risk (Windows Media Player) for example. Shutting off these vulnerabilities helps security in those OTHER programs as well.
With the latest sophistication of trojans, worms, and virus, I recommend tightening EVERY security zone (there is practically no such thing as a 'trusted site' anymore, and even the 'Local intranet' zone is commonly corrupted).
Then install a non-MS browser and emailer if you haven't already.
To: Eagle9
68
posted on
07/04/2004 4:10:15 AM PDT
by
Musket
To: FL_engineer
To: FL_engineer
Appreciate the info. I'm still cleaning garbage out of my machine.
70
posted on
07/04/2004 4:28:07 AM PDT
by
backhoe
(1990's? Decade of Frauds. 2000's? Decade of Lunatics...)
To: Eagle9; TenthAmendmentChampion
...if you read his thread, you'll be able to get rid of CoolWebSearch...Thanks, champ. However I finally managed to get rid of it last week, with Spy Sweeper. I had a terrific dream, that night- I was the Ultimate Techie, hunting hackers on the Net, wrecking their homepages, terrorising their forums, posting accounts of my exploits on my blog. And- receiving millions in Paypal donations, from long-suffering IE users. :) Cheers, By
71
posted on
07/04/2004 5:33:49 AM PDT
by
Byron_the_Aussie
(http://www.theinterviewwithgod.com/popup2.html)
To: Bush2000
Netscape 4.77 under Red Hat 7.3 is NOT vulnerable.
72
posted on
07/04/2004 5:40:51 AM PDT
by
TechJunkYard
(Hello, I'm a TAGLINE virus. Please help me spread by copying me into YOUR tag line.)
To: Bush2000
I'm getting a little tired of their continual lies. ooooh, it really burns you that Mozilla and Firefox have already fixed this "design flaw", doesn't it?
Bottom line -- once again, the open-source tool is safe while the proprietary one is not.
MS is to software what McDonalds is to food. You eat what you like, tho . . .
To: Eagle9
Using Mozilla 1.7. I passed, do I get a gold star?
74
posted on
07/04/2004 6:04:50 AM PDT
by
ovrtaxt
(Don't worry -- moderate Islam will save us!)
To: FL_engineer
I am using FireFox. I switched a couple of weeks ago at the suggestoin of some Freepers.
So far I like it.
75
posted on
07/04/2004 6:07:27 AM PDT
by
SeeRushToldU_So
(I laugh when I see women driving with cellphones in their ear.)
To: Eagle9
Hey, what about Win 95 w/IE 5.5? TX
76
posted on
07/04/2004 6:11:17 AM PDT
by
1234
(Border control or IMPEACHMENT)
To: octobersky
I'm in IE right now. Got an auto -update from MS yesterday.
IE failed the test.
Tried my usual browser, Mozilla 1.7. Passed
77
posted on
07/04/2004 6:18:07 AM PDT
by
Vinnie
To: Eagle9
This is an odd article. It talks about the IE ADODB vulnerability, and then goes on to an entirely different implementation problem, shared by some other browsers, which is not as serious, in an apparent attempt to downplay the problems with IE.
Note to everyone: this is not the same as the big problem the other day.
78
posted on
07/04/2004 6:19:11 AM PDT
by
B Knotts
To: FL_engineer
79
posted on
07/04/2004 6:19:19 AM PDT
by
lainde
(Heads up...We're coming and we've got tongue blades!!)
To: Bush2000; Swordmaker
Swordmaker: Bush, it IS possible to comment on this without insulting anyone. Bush2000: Stay out of it.
Too much coffee, Bob?
;)
80
posted on
07/04/2004 6:24:35 AM PDT
by
Liberal Classic
(No better friend, no worse enemy. Semper Fi!)
Navigation: use the links below to view more comments.
first previous 1-20 ... 41-60, 61-80, 81-100 ... 201-207 next last
Disclaimer:
Opinions posted on Free Republic are those of the individual
posters and do not necessarily represent the opinion of Free Republic or its
management. All materials posted herein are protected by copyright law and the
exemption for fair use of copyrighted works.
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson