Announcement

Collapse
No announcement yet.

Internet Explorer Zero Day Vulnerability

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Internet Explorer Zero Day Vulnerability

    All - I've just got this message from my First Alert system (its real, no hoax, check the web) - thought I'd pass it on in case anyone needs it.

    Kevin

    ===

    "Recently, a zero-day exploit has been released that affects Microsoft’s Internet Explorer web browser. A zero-day exploit is one that takes advantage of security vulnerabilities before the software vendor or public knows the issue exists. In this case the exploit attacks flaws within all versions of Microsoft’s Internet Explorer web browser and could be used to take total control of the vulnerable system. As of today, Microsoft has not released a system patch to correct these vulnerabilities.

    Within the last week, attackers on the public Internet have started taking advantage of these flaws. The MaximumASP security team has been monitoring Internet traffic to ensure no infected systems exist on our internal network, but we need your help to ensure all systems on the MaximumASP network remain safe and secure.

    The exploit in question relies on the victim surfing to an infected website with a vulnerable browser. The easiest way to avoid being compromised by this particular vulnerability is to use an alternate to the Internet Explorer browser until Microsoft releases a patch to correct this issue. The MaximumASP Security team recommends using Firefox version 3 with the noscript module installed. The noscript module stops all javascript or other browser side executables from running on your system unless you explicitly whitelist a website. We recommend you install an alternate browser on any system that you use to surf the public Internet. This includes desktops, laptops, servers, home systems and work systems. As always, remember to follow Security Best Practices. You should NOT be using your production servers to surf the public Internet.

    If you have any type of SQL injection issues with your code be on the lookout for attackers to inject malicious javascript or IFRAME links to vulnerable executables. This attack is very wide spread and moving through the Internet very quickly. If you use an alternate browser like Firefox you will not become a victim to this latest attack.

    Links to Firefox and the Noscript module:

    Firefox:

    http://www.mozilla.com/en-US/firefox/

    Noscript:

    http://noscript.net/

    Links to further information on this attack:

    http://isc.sans.org/

    http://www.shadowserver.org/wiki/

    If you have any questions or concerns please feel free to call customer support or start a new ticket.

    Thanks,

    MaximumASP Security Team"

    KDM Digital Media - Actinic web design and hosting

    #2
    Nice one - good old MS

    Comment


      #3
      I wonder if the infected website has to be intentionally infected (ie malicious) or whether any website could be infected?

      Aquazuro - designer stainless steel accessories

      Comment


        #4
        Originally posted by Mark H View Post
        I wonder if the infected website has to be intentionally infected (ie malicious) or whether any website could be infected?
        See: http://www.shadowserver.org/wiki/pmw...endar.20081210
        KDM Digital Media - Actinic web design and hosting

        Comment


          #5
          Thanks Kevin - they look malicious to me. I'll make sure that my Snort rules are in place togther with NIPS, NIDS, SnortSnarf, sguil, OSSIM, and BASE, Bleeding Edge, ClamAV, SPADE, and implementation of DEP for IE7.

          Or, perhaps I'll use Safari.

          (with apologies to Wikipedia)

          Aquazuro - designer stainless steel accessories

          Comment


            #6
            I barely understood a word of that last post, and even after googling the various terms I am still not much clearer.
            I think I need to go and have a lie down, it sounds like terms from Gabe's World and not world I want to even think about.
            Darren Guppy
            Golf Tee Warehouse
            Golf Tees and Golf Accessories.

            Comment


              #7
              Originally posted by Golf Tee Warehouse View Post
              I barely understood a word of that last post, and even after googling the various terms I am still not much clearer.
              I think I need to go and have a lie down, it sounds like terms from Gabe's World and not world I want to even think about.
              It basically means what with the credit crisis, the negetivity in the press and the IE exploit the best place to be over Christmas is under your bed!
              KDM Digital Media - Actinic web design and hosting

              Comment


                #8
                If you're really interested (and to be honest, I wouldn't bother) Google for "Snort rules wiki".

                Aquazuro - designer stainless steel accessories

                Comment


                  #9
                  More mainstream news now: http://news.bbc.co.uk/1/hi/technology/7784908.stm
                  KDM Digital Media - Actinic web design and hosting

                  Comment


                    #10
                    I've just downloaded an update for IE that I assume has fixed this.

                    Mike
                    -----------------------------------------

                    First Tackle - Fly Fishing and Game Angling

                    -----------------------------------------

                    Comment


                      #11
                      Yes, it was released around 5pm yesterday on Windows Update. I would encourage everybody to download the update asap.
                      KDM Digital Media - Actinic web design and hosting

                      Comment


                        #12
                        Originally posted by CymraegKev View Post
                        Yes, it was released around 5pm yesterday on Windows Update. I would encourage everybody to download the update asap.
                        Or switch to firefox permanently

                        Malcolm

                        SellerDeck Accredited Partner,
                        SellerDeck 2016 Extensions, and
                        Custom Packages

                        Comment


                          #13
                          Originally posted by malbro View Post
                          Or switch to firefox permanently
                          Firefox is vulnerable too (as are all browsers). Not to this particular issue, but plenty of others. MS did well to get a patch out for a zero day in such short time. Mozila wouldn't have been able to do it that quick in my opinion.

                          Also - even if you don't use IE you are advised to install the update as other software may use the IE engine on your machine that you are not aware of.
                          KDM Digital Media - Actinic web design and hosting

                          Comment


                            #14
                            I have to stick my oar in and say that MS was unlucky in this case, but does anyone seriously consider IE* to be in any way secure for anything?

                            Seriously?

                            I'd not even browse google with IE. I have disabled all forms of script in it, and have physically removed it from my xp install.

                            It's a fool who browses the web with it, and an argument that has raged on for many years.

                            You're asking for trouble, by merely opening the blasted thing up. Heaven forbid why people use it to buy things online, and force us to make our sites deliberately non-compliant to standards.

                            Some would say that if IE werent here, then it'd be another broewser taking all the flak. I put it to those that defend IE, that its the *underlying OS* that is flawed.

                            I have IE running in crossover office, and I can browse all day without problems, why? becasue i'm running it in an operating system(s) that take file and device ownership seriously.

                            What people should really be looking at here, is why MS have been working on this bloody browser for thousands of years now, and yet still there are sad security holes like this one, causing widespread panic.

                            nuff said.

                            Comment


                              #15
                              Not entirely sure I follow you Gabe. It sounds like you're saying IE is not safe to use, but even if it was it's still no use because it runs on windows? Doesn't that kind of limit the other browsers too, in which they're all as bad as each other.

                              Is all the panic justified? As you say, there are other holes in security anyway and are people protected if they take other precautions?

                              I'm sitting here using IE7, but then I also have Zonealarm, AVG, Windows Defender and spybot SD running. Hopefully that makes me a bit more secure.

                              Mike
                              -----------------------------------------

                              First Tackle - Fly Fishing and Game Angling

                              -----------------------------------------

                              Comment

                              Working...
                              X