Free Republic
Browse · Search
News/Activism
Topics · Post Article

US-CERT Vulnerability Note #416092

(excerpt)

III. Solution

We are currently unaware of a practical solution to this problem. Until a patch or update is available consider the following workarounds:

Refer to the following workarounds listed in Microsoft Security Advisory (925568):


Do not follow unsolicited links

In order to convince users to visit their sites, attackers often use URL encoding, IP address variations, long URLs, intentional misspellings, and other techniques to create misleading links. Do not click on unsolicited links received in email, instant messages, web forums, or internet relay chat (IRC) channels. Type URLs directly into the browser to avoid these misleading links. While these are generally good security practices, following these behaviors will not prevent exploitation of this vulnerability in all cases, particularly if a trusted site has been compromised or allows cross-site scripting.

______________________________________________________________________

I choose to use an alternative solution: Firefox or Opera as my browser.

1 posted on 09/19/2006 5:36:04 PM PDT by Eagle9
[ Post Reply | Private Reply | View Replies ]


Navigation: use the links below to view more comments.
first 1-2021-25 next last
To: Swordmaker

So... you wanna ping Bush2k?

: )


2 posted on 09/19/2006 5:38:16 PM PDT by IncPen (Bush Iraq Truth WMD http://freedomkeys.com/whyiraq.htm)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

Only idiots or masochists still use IE. Smart, sane people use Firefox, Mozilla/Seamonkey, and/or Opera 9.


3 posted on 09/19/2006 5:38:44 PM PDT by bigdcaldavis (Xandros : In a world without fences, who needs Gates?)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

I'm with you. Not only is Firefox minus the MS security bugs, it was faster than IE from the first day. Now, I have converted many friends and relatives to Mozilla's browser and their Email client (Thundebird) as well. And, the Mozilla community has new extension and plug-ins for both apps all th e time.


4 posted on 09/19/2006 5:40:22 PM PDT by Wuli
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

"So far, said Eric Sites, vice president of research and development at Sunbelt, the exploit has shown up on hardcore porn sites, which are serving a buffet of badware to users who visit those sites. "

Oh, well. I guess I'm safe then, since I never go to porn sites. Porn sites have had nasty adware on them for years.


7 posted on 09/19/2006 5:46:15 PM PDT by MineralMan
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

Firefox. It's better anyway IMO. Lots better.


13 posted on 09/19/2006 5:50:30 PM PDT by Principled
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

Clearly...George Bush's fault.


17 posted on 09/19/2006 5:55:41 PM PDT by mattdono (150 Million bloodthirsty Arabs vs. 4.8 Million Jewish Israelis. That's not fair. [Off Sarcasm])
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9
I'm sorry, but I can't reproduce the bug in Firefox on my MEPIS box.

Doesn't work on my Mac mini either.

Can someone verify this is a real issue, please?
25 posted on 09/19/2006 6:03:47 PM PDT by dyed_in_the_wool ("O you who believe! do not take the Jews and the Christians for friends" - Koran 5.51)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

Wouldnt a simple solution be to not go to porn sites?

(ducking)


27 posted on 09/19/2006 6:08:11 PM PDT by VanDeKoik (Fitzmas Has Been Canceled.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

If I site requires me to use IE, I will generally email the contact people listed in the WHOIS record and then stop using the site. Since I use Linux as my desktop OS, using IE is not an option and I couldn't be happier. Again, I simply stop using that site if I have to use IE. The trick is not to use IE in the first place; and I never have. I've transitioned from Netscape -> Mozilla -> Firefox and never took that poison pill that is the blue e.

Secondly, IE is years behind in features. I cannot browse the web without tabs and the RSS/live bookmarks in Firefox. IE 6 with SP2, for example, finally included an integrated a pop-up blocker. Opera and the Mozilla browsers had them since at least 2002. Tabs? Again, Opera has had them since the late 90's and Mozilla-based browsers since '02 or so. IE7 will have tabs, only a few years behind. RSS? Yup. For a couple of years now feeds can be incorporated into Firefox. IE7 will have them.

The development team for IE7 was given one directive: "copy Firefox."

If you don't ditch IE for security, least you can do is it ditch it for its dearth of features.

By the way, IE is also a piece of junk.


31 posted on 09/19/2006 6:15:07 PM PDT by bws53
[ Post Reply | Private Reply | To 1 | View Replies ]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...

35 posted on 09/19/2006 6:43:33 PM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9
the exploit has shown up on hardcore porn sites, which are serving a buffet of badware to users who visit those sites.

stop looking at porn and you dont have anything to worry about. :)

36 posted on 09/19/2006 6:49:23 PM PDT by Echo Talon
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9; potlatch; ntnychik; Smartass; Boazo; Alamo-Girl; PhilDragoo; The Spirit Of Allegiance; ...

save yourselves - ping!


40 posted on 09/19/2006 6:59:29 PM PDT by bitt ("And an angel still rides in the whirlwind and directs this storm.")
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

A website about drugs (legal OTC and prescription stuff) that was the top result on Google recently downloaded a trojan on my computer. The stupid thing would show as infecting my computer everytime I rebooted even after the anti-virus said it cleaned it. It took several hours of running several online AV scans, deleting, rebooting and deleting system restores to get the stupid thing clean.


41 posted on 09/19/2006 7:02:23 PM PDT by OrangeDaisy
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

Another great commercial for firefox.


42 posted on 09/19/2006 7:06:29 PM PDT by mysterio
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9
To really make these alerts effective they should post very detailed information on how to use the exploits.

That would really light a fire under their asses!
54 posted on 09/19/2006 7:53:34 PM PDT by KoRn
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

III. Solution:XPLite


62 posted on 09/19/2006 8:16:04 PM PDT by philetus (Keep doing what you always do and you'll keep getting what you always get.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

"I choose to use an alternative solution: Firefox or Opera as my browser."

Ditto, at least for anything other than a bank site. I hope the financial industry starts supporting Firefox better. The handwriting is on the wall.


63 posted on 09/19/2006 8:30:52 PM PDT by FastCoyote
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

bookmark


73 posted on 09/19/2006 9:47:07 PM PDT by DocRock
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

OK, I'm getting Firefox tomorrow. Freakin Microsoft.


74 posted on 09/19/2006 9:52:55 PM PDT by Mr. Silverback ("Now they will know better than to fight a martial arts master who is also made of gelatin!")
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

Hmmm...I posted that before I noticed that most of the users encountering this problem are getting it at porn sites. I WILL NOT have that problem...but i'm still changing to firefox.


75 posted on 09/19/2006 10:00:33 PM PDT by Mr. Silverback ("Now they will know better than to fight a martial arts master who is also made of gelatin!")
[ Post Reply | Private Reply | To 1 | View Replies ]


Navigation: use the links below to view more comments.
first 1-2021-25 next last

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson