Quick Login   
 
Register AdminFusion Tutorials
 
Featured Sponsors


One.com Domain and Hosting


Register
Forum of the Month
Australian Webmaster
fotm

A webmaster forum specifically catering for Australian site owners. We discuss site development, marketing and management issues.

Tag Cloud
Latest Threads
Forum Stats
7,846 Members
164,851 Posts
35 Users Online

Please welcome our newest member, discotoast!

Affiliates
Go Back AdminFusion » The Break Room » Off Topic » Critical Internet Explorer Flaw Patched
Welcome to the AdminFusion. AdminFusion is the ultimate resource for forum administrators and moderators. With exclusive articles, interviews with the experts, free downloadable skins, and the revolutionary post exchange system - PostFusion, AdminFusion is the place to go for all of your forum needs.  By joining AdminFusion, you will become part of a thriving admin community and immediately gain access to all of these resources. Registration is fast, simple and absolutely free so please join us today!
Want more than our forums? Try these: Post Fusion Forum Matrix
Old 03-29-2006, 08:33 AM   #1

shellspeare's Avatar

Title: Forum Enthusiast

Points: 16,350, Level: 38Points: 16,350, Level: 38Points: 16,350, Level: 38
Level up: 39%, 100 Points neededLevel up: 39%, 100 Points neededLevel up: 39%, 100 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Aug 2005

Posts: 2,521

Location: England

shellspeare is on a distinguished road
Send a message via MSN to shellspeare  
 
Arrow Critical Internet Explorer Flaw Patched

Critical Internet Explorer Flaw Patched

by Third Party Jay Wrolstad,
newsfactor.com
Tue Mar 28, 2:20 PM ET
source: http://news.yahoo.com/s/nf/20060328/...N5bnN1YmNhdA--




While Microsoft works on a patch for a critical Internet Explorer 6 script vulnerability that can allow a hacker to take control of a Windows PC, another firm has beaten Microsoft to the punch, releasing its own fix for the problem.

The new patch from eEye Digital Security is not meant to replace the forthcoming Microsoft patch, but it does provide immediate protection in lieu of an available fix. It is designed to remove itself automatically when Microsoft's official patch becomes available.

Microsoft's official update might not be released until next month, according to a blog posting on the company's security site.

The notice states that the company has seen only limited numbers of attacks targeting the newly found flaw and that an Internet Explorer 6 update will be released as soon as it is ready. Currently, Microsoft's plan is to prepare the fix in time for its next set of monthly patches, due to be released in early April.

Seeking Feedback

Meanwhile, the software giant has introduced an Internet Explorer feedback database in an effort to collect information on potential bugs found in the beta version of Internet Explorer 7.

The company noted on the Internet Explorer site that customers have requested a better way to alert Microsoft to bugs. For now, visitors to the feedback database will need a Microsoft Passport to view or report browser problems, although Microsoft plans eventually to allow anonymous access to the site.

The feedback site is for Internet Explorer 7 and future versions the browser. Once IE7 has shipped, the site will be used to gather feedback so Microsoft can improve future iterations.

Bugs can be marked either as public or private. A public bug can be viewed by anyone who goes to the feedback database, enabling those who discover the same issues to evaluate them and know that they are entered.

Forrester analyst Paul Stamp suggested that, given the ongoing problems associated with Internet Explorer, both security-related issues and those involving basic navigation, Microsoft needs a forum for input from users.

"Browsers are so complex now that there are more bases to cover," he said. "And because Microsoft went years before taking a proactive approach to Explorer bugs, there will be more flaws cropping up."

Exploits Reported

As for the current vulnerability, security experts have noted that, while the flaw is serious, those wishing to exploit it would have to entice users to click a link that takes them to a specially crafted Web site. In addition, for a PC to be affected, it must be running in administrator mode.

The vulnerability is exploitable via Web surfing, e-mail, and instant messaging, and several versions of the exploit are already in the wild and are being used actively by hackers, eEye reported.

Those whose accounts are configured to have fewer user rights are less vulnerable than users who operate their PCs with full admin rights turned on. Currently, there have been numerous reports of this vulnerability being used in attempts to install spyware and remote-control "bot" software for use in distributed denial-of-service (DDoS) attacks.

The recommended action required to protect systems against this exploit is to disable Active Scripting from within Internet Explorer.

This can be done by opening the Internet Options settings listed in Internet Explorer's Tools menu, clicking on the Security tab, selecting the Internet zone, and clicking on the Custom Level option. The active-scripting setting is available toward the end of the list.
__________________
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

 
Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
Unwritten Rules of Forums Ryan Handling Problem Members 3 08-17-2008 03:17 AM
Firefox VS. Internet Explorer Neil Off Topic 39 12-07-2006 05:19 AM
Microsoft Patches Two Critical Flaws shellspeare Off Topic 0 01-13-2006 10:58 AM
Critical IE Bug shellspeare Off Topic 4 11-23-2005 05:09 PM
A New 'Malicious Marketplace' for Internet Attacks shellspeare Off Topic 0 11-23-2005 02:05 PM

AdminFusion

All times are GMT +1. The time now is 09:54 AM. Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0 © 2005-2008 AdminFusion - All Rights Reserved



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72