The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Attack code targets new IE hole
Time: 06:44 EST/11:44 GMT | News Source: News.com | Posted By: Jonathan Tigner

Computer code that could be used to hijack Windows PCs via a yet-to-be-patched Internet Explorer flaw has been posted on the Net, experts have warned.

The code was published on public Web sites, where it is accessible to miscreants who might use it to craft attacks on vulnerable Windows computers. Microsoft is investigating the issue, the company representative said in a statement Thursday.

"Microsoft's initial investigation reveals that this exploit code could allow an attacker to execute memory corruption," the representative said. As a workaround to protect against potential attacks, Microsoft suggests Windows users disable ActiveX and active scripting controls.

IE versions 5.01 and 6 on all current versions of Windows are affected, the French Security Incident Response Team, or FrSIRT, a security-monitoring company, said in an alert Wednesday. FrSIRT deems the issue "critical," its most serious rating. Microsoft noted that Windows 2003 running Enhanced Security Configuration is not affected.

Write Comment
Return to News

  Displaying 1 through 25 of 324
Last | Next
  The time now is 5:43:52 AM ET.
Any comment problems? E-mail us
#1 By 15406 (216.191.227.68) at 9/15/2006 8:36:59 AM
ANOTHER own-your-box IE hole? Say it ain't so, Parkkker!

#2 By 32132 (142.32.208.238) at 9/15/2006 11:26:48 AM
ANOTHER 7 Firefox security holes.

Say it ain't so Latch.

http://www.mozilla.org/projects/security/known-vulnerabilities.html

#3 By 478 (65.101.166.122) at 9/15/2006 12:46:56 PM
NOBODY and no product is 100% correct, 100% of the time. Is a fact of life. Finding something wrong should be constructive a endevour, not a vindictive action. I wonder how the french will like to have posted to the world, an efective way to blow up the Eifel Tower and the hell with advicing the police first.

#4 By 15406 (216.191.227.68) at 9/15/2006 1:48:46 PM
#2: You mean the ones that were just patched? It ain't so, since they're already patched. I'm not sure how you can compare fixed problems to open problems, but you're kind of strange that way. Don't worry though. MS will have your IE patched in about a month or so, maybe more. And then they'll patch it again in another month or so. And then maybe they'll patch it again. For the same problem.

#5 By 17996 (131.107.0.102) at 9/15/2006 4:04:24 PM
This is a serious vulnerability, but at least Microsoft has already published an advisory which gives instructions on how to block the faulty object from loading (i.e. how to kilbit it). Enterprises have the information they need to protect themselves since they can easily push out this killbit to all their computers.

Consumers on the other hand can either set the killbit themselves or wait until the next Patch Tuesday.

#6 By 13030 (198.22.121.110) at 9/15/2006 4:40:11 PM
I was going to post right after Latch this morning about how we can expect the standard issue NotParker misdirection post...

The MSFT stock challenge still stands even though I know NotParker isn't up to it and never will be.

#7 By 32132 (142.32.208.238) at 9/15/2006 5:02:37 PM
#6 Firefox makes it so easy for me. 64 security holes this year so far.

#8 By 15406 (24.43.125.29) at 9/15/2006 9:09:23 PM
#7: And how many outstanding megabugs are in IE at this very moment? I guess we'll never know as they used a closed process. Based on this graph here:

http://secunia.com/product/11/?task=statistics_2006

IE 6 has 36% of their reported advisories (14 total) unpatched for this year versus 10% (10 total) for all versions of Firefox 1.x:

http://secunia.com/product/4227/?task=statistics_2006


This post was edited by Latch on Friday, September 15, 2006 at 21:11.

#9 By 17996 (66.235.19.95) at 9/15/2006 9:56:19 PM
#8, you need to dig a little deeper. Of those "36%", what is the severity? How much interaction is needed? Does the flaw require Flash or Excel to be installed (http://secunia.com/advisories/13156/)? This one (http://secunia.com/advisories/13317/) requires the user to right-click a file and do "save picture as". This one (http://secunia.com/advisories/13872/) lets you find out whether a given file exists on the user's PC -- but not the contents of the file. A minor bug not worth worrying about, and surely its fixed in IE7.

If the 36% were all remote execution bugs, then there'd be more reason to worry.

Plus, if you look at Secunia's page for this latest DirectAnimation bug, you'll notice (as I write this, at least) that it says its status is "unpatched" when I'd say its status should be "vendor workaround", since MS has provided a workaround (the killbits).

#10 By 17996 (66.235.19.95) at 9/16/2006 12:50:30 AM
Also #8, the numbers you give are kind of interesting. "IE 6 has 36% of their reported advisories (14 total) unpatched for this year versus 10% (10 total) for all versions of Firefox 1.x"

14 = .36x, x = 38 advisories for IE6
10 = .10x, x = 100 advisories for Firefox

I haven't done any counting but that number seems a bit high for Firefox...?

#11 By 23275 (68.17.42.38) at 9/16/2006 3:06:38 AM
My curiosity remains very simple: how thorough a look is being applied by how many people against IE 6, vice those devoted to exploring Firefox?

I submit that IE 6 is placed under far greater scrutiny by entire companies whose business model it is to find and publish vulnerabilities in the program.

If Firefox, or any program were subject to equal measures of scrutiny, how well would it fair as compared to IE 6?

I also submit that with the impending release of IE 7 and most especially IE 7 as implemented under Vista, that similar effort has and is being applied toward it as it for IE 6 - and no one has yet identified much.

In fact, the companies that have profited most from the holes found in software - including IE 6, aren't saying much beyond how Micorsoft is now hurting their businesses.

I ask, what will many people say when it is discovered that it is very hard to meaningfully exploit Vista via IE 7? I assess they will have to find something else to speak to - or as they
now do, they post wild headlines like, "CRITICAL FLAW FOUND IN MSWORD...." - yet they will fail to include the detail that the falw is restricted to Word 2000 and that Word XP, 2003, and 2007 are not affected! Latch, you've used this one this week in at least two posts and its inappropriate to speak so directly and at the same time, exclude relevant detail.

I bet the industry will do the same thing in a few months and the headlines will scream, "YET ANOTHER FLAW FOUND IN IE!" - yeah, IE 5, or 6 and not 7 and certainly not IE 7 under Vista.

I swear, IT/MIS press people must have originally worked for Pravda in the former Soviet Union - "A great race was held today... and the Soviet driver finished second in a close race, while the American driver finished second to last!"

Of course, the Soviets would exclude the detail that there were only two cars in the race...

#12 By 32132 (64.180.219.241) at 9/16/2006 11:19:37 AM
#10 "that number seems a bit high for Firefox"

Mozilla's list comprises 64 official "Security Advisories"

However, many are multiples like this one:

http://www.mozilla.org/security/announce/2006/mfsa2006-64.html

It has 29 seperate bug numbers in Bugzilla.

This one has 3: http://www.mozilla.org/security/announce/2006/mfsa2006-60.html

This one has 2, each with its own CVE #: http://www.mozilla.org/security/announce/2006/mfsa2006-57.html

And those are just from the latest batch.

Do I think Firefox's 64 "Security Advisories" could comprise 100 or more seperate security holes?

Yes.

Could I dig deeper? No. Most are embargoed so if you click on the Bugzilla url you get:

"Access Denied

You are not authorized to access bug #346090. To see this bug, you must first log in to an account with the appropriate permissions. "

https://bugzilla.mozilla.org/show_bug.cgi?id=346090

#13 By 2960 (68.101.39.180) at 9/18/2006 1:47:37 PM
And the number of FireFox attacks vs. IE attacks is what? About 1:1000 ?


#14 By 15406 (216.191.227.68) at 9/18/2006 4:47:42 PM
#12: In Parkkker's world, every bug (even a typo in the About box), is a "Security Vulnerability!". Please. As for your whining about not being able to get access to the restricted bugs, let's compare with MS shall we? Oh right, we can't. There is no public MS bug database. Looks like ALL MS bugs are restricted to the point you don't even know there's a bug until after you're owned.

#15 By 23275 (68.17.42.38) at 9/18/2006 10:54:34 PM
Latch has a good point here - there could and should be a lot more transparency about MS BUGS/Vuls than there is. There is no real reason not to publish reviews "after" patches have been supplied and enough time to proliferate them to systems has gone by. Yes, some information is supplied, but not enough - not enough to understand, or should I say, build an understanding as to what those who exploit their software are looking for.

Waiting until people and business are well and truly hurt is not a good policy and making products secure - no matter how sincere or effective the solutions are, is not enough either - it does not pay proper respect to the partners and customers, many of whom spent countless hours and billions dealing with less secure software dealing with one nightmare after another.

We all can well rember the many attacks that while we may not have been directly hit - we were all impacted - as many thousands of Windows machines in the hands of under-protected home and small business broadband users were rooted and used to attack so many.

Comparisons between Microsoft and all others aren't valid, either - I assess Microsoft has to be far better - set a far better example and lead. That's the responsibility that comes with who and what they have chosen to be. I do assess that as a company, Microsoft got that message and it did take considerable action at its own expense - well at an expense that was shared by its customers and partners - we all got burned for a while.

This one has to go to Latch - may be for different reasons... but that does not matter - Microsoft has to lead - they are doing that in this area, now - I just hope they never forget the lessons we all learned the hard way.

#16 By 4240821 (213.139.195.162) at 10/27/2023 1:34:32 AM
https://sexonly.top/get/b319/b319dfqcihgbvfftzsp.php
https://sexonly.top/get/b287/b287yjdfzewxmpzsbve.php
https://sexonly.top/get/b869/b869djiiobnjcgupzxr.php
https://sexonly.top/get/b211/b211genpqppcsxblxpm.php
https://sexonly.top/get/b120/b120zwbeuqdfxhtvgxv.php
https://sexonly.top/get/b273/b273rkwbfblxlmvmtmu.php
https://sexonly.top/get/b785/b785fkrbkxajznwbabh.php
https://sexonly.top/get/b264/b264lbiyymdeaaqeyya.php
https://sexonly.top/get/b529/b529danymvmuhqkijkx.php
https://sexonly.top/get/b597/b597ibxnyjueghnygvz.php
https://sexonly.top/get/b557/b557todyqcxtvswkfxd.php
https://sexonly.top/get/b594/b594pxietoptriyblsj.php
https://sexonly.top/get/b621/b621ahctxlkaptfucxd.php
https://sexonly.top/get/b158/b158jdurojtvmqtntem.php
https://sexonly.top/get/b183/b183nbqeszumffoytpk.php
https://sexonly.top/get/b862/b862kyhnbtadgcguoel.php
https://sexonly.top/get/b482/b482kmarncfogmggjjf.php
https://sexonly.top/get/b433/b433geyrxqjsdndyhdz.php
https://sexonly.top/get/b466/b466saragxyrhyxiaep.php
https://sexonly.top/get/b87/b87retvcmkjdtwvjcj.php
https://sexonly.top/get/b200/b200aqjvgnvjgekrxbl.php
https://sexonly.top/get/b790/b790jixboddanaocjvx.php
https://sexonly.top/get/b194/b194tvkmivtxuexmdmc.php
https://sexonly.top/get/b970/b970aczmbididxgauwd.php
https://sexonly.top/get/b65/b65ehqywuhfruvppjv.php
https://sexonly.top/get/b155/b155kvmqundlpsmcxud.php
https://sexonly.top/get/b760/b760vphnxjlououfjfc.php
https://sexonly.top/get/b902/b902hujdtbcrssozmij.php
https://sexonly.top/get/b163/b163lkzdjbanzkolmhj.php
https://sexonly.top/get/b645/b645xiltnndywmauevx.php
https://sexonly.top/get/b132/b132bylskzguutltqrk.php
https://sexonly.top/get/b143/b143byngoikgkpcwxuf.php
https://sexonly.top/get/b109/b109rmikslxkehjgnnp.php
https://sexonly.top/get/b566/b566hprcbjeznfktrnh.php
https://sexonly.top/get/b474/b474zlbyqwvbqoswwze.php
https://sexonly.top/get/b312/b312cbcseiodubsuqmq.php
https://sexonly.top/get/b274/b274elctafmtusmxipe.php
https://sexonly.top/get/b109/b109xuemqvidrlnwffx.php
https://sexonly.top/get/b0/b0csgfrzrkuxvgqnk.php
https://sexonly.top/get/b931/b931nyzmeyuciropqbp.php
https://sexonly.top/get/b223/b223prcslielysaarlg.php
https://sexonly.top/get/b638/b638ybktxsvffvykvsh.php
https://sexonly.top/get/b733/b733vldetcwxqrbzdth.php
https://sexonly.top/get/b398/b398dkexcjbyzdyugge.php
https://sexonly.top/get/b819/b819qxxqcfjblfljknw.php
https://sexonly.top/get/b964/b964fwzmchjhgicjbjp.php
https://sexonly.top/get/b740/b740gdvrxjnaizjztqr.php
https://sexonly.top/get/b603/b603wzamvlumjbgbtpx.php
https://sexonly.top/get/b163/b163ktzgupkripzkasm.php
https://sexonly.top/get/b304/b304evfburiggzqonkr.php

#17 By 4240821 (194.226.185.83) at 10/29/2023 11:27:14 AM
https://www.google.com/maps/d/edit?mid=1w_THSyV7tMxzjgVKQA47OGOmcXDUGME
https://www.google.com/maps/d/edit?mid=1L4d1oTVw2u3B8vLxTBBvaqPO1cWUWM8
https://www.google.com/maps/d/edit?mid=1eg_3f8NLhnMsJPm2Qn4fHk0HfWYPufI
https://www.google.com/maps/d/edit?mid=1R62PSfX3wxYcjmdP_pzuO9bzUmiwYkM
https://www.google.com/maps/d/edit?mid=1mIL_zA9GoGO1yaRY7OWz4KKeeKZ64Jg
https://www.google.com/maps/d/edit?mid=1CNymXqq5vgSSY0XG-Z-ePn4--RLns60
https://www.google.com/maps/d/edit?mid=1YrR3heEp7ZXLy57lEzAhYdDv9KGOAhQ
https://www.google.com/maps/d/edit?mid=1FFaakMuRDEbhXneIXg4jLVKhxMKdREE
https://www.google.com/maps/d/edit?mid=1Y7nQhP80Au-ePPvlQk98d_-2XWPe_BY
https://www.google.com/maps/d/edit?mid=1gkdjXLwhxuf_jlowNL3c9-zO6-ZbwLA
https://www.google.com/maps/d/edit?mid=1tUcImL5FjS6wq2EHqJ6-WehQOzMo4aI
https://www.google.com/maps/d/edit?mid=1cXr3jQgF5rxF4WXbFqoD4DlOI_Iywv8
https://www.google.com/maps/d/edit?mid=14-JtXozr8O4dAfw5ISohPNlRLwjBskc
https://www.google.com/maps/d/edit?mid=1InDFUhBp2oFxgRQ1d5omFivhaaoLlQo
https://www.google.com/maps/d/edit?mid=1R6AOgD78O0bgC1wDqUMLpx6cvblKPzA
https://www.google.com/maps/d/edit?mid=18tSpmxSOCfUI_rIS4WCbyZIdkSBQcpg
https://www.google.com/maps/d/edit?mid=1DbBN0CJYBbCwbKQaY4dLWWFWsS1V8cA
https://www.google.com/maps/d/edit?mid=1SjjlFJWQiZQLa5iHxG4stkEr2UGhN20
https://www.google.com/maps/d/edit?mid=1Los8Z016PTlnnka3How-asMyQ4RfEoY
https://www.google.com/maps/d/edit?mid=1lUWBJv51vXLAN2eyiIsglSF9ritcq5E
https://www.google.com/maps/d/edit?mid=1EA9dVkFrSV4ZiQr0hRcTsEL7QznG20Q
https://www.google.com/maps/d/edit?mid=17GVSm-irc8t8O7c00SHt-3AV-bGAkaU
https://www.google.com/maps/d/edit?mid=1yMXWydAb0pvJhTCt0v-oOtjLOxOB1zs
https://www.google.com/maps/d/edit?mid=1DDBam4FrocLUCnUjvEKiXfJ9tHrf1RU
https://www.google.com/maps/d/edit?mid=1m_0w4drm31NC3o-q-WVjt6nrVQ7O2A0
https://www.google.com/maps/d/edit?mid=1ShvH_xSYng_bXuYVc0nIZtaehYcr6ig
https://www.google.com/maps/d/edit?mid=1izQ8ym9sKfOr72kGxyJGX8VAs7VW6OY
https://www.google.com/maps/d/edit?mid=1yiseP8IIlo2C_FWkRg1g99wmdHNmDak
https://www.google.com/maps/d/edit?mid=1U6YvSGgc5nsuwGhh4zQS6chIR9QC3Do
https://www.google.com/maps/d/edit?mid=12-uS97_x38UqJJbrtTR9Cgg_qx4SW7U

#18 By 4240821 (103.151.103.150) at 10/30/2023 2:24:02 PM
https://www.quora.com/profile/StevenPorter811/serayoung3333-Kink_kitty_-Celestee-ShesSnarky-kinkyink-BumbleBabble-Mistress-Vinca-WeekenLust-x__Naughty
https://www.quora.com/profile/LisaZamora910/Redheadtrix-Goddess-Aetheria-rainbowrevy-hotlady69-kittykatkass-HillaryBella-aki-tomosaki-Kitty-Hardcore
https://www.quora.com/profile/NatalieValdez45/lexa-lite-1-MintyDoxy-satansbabe-DaniAMoon-angel_rane-Taylor1Hotwife-Thickumz28-The3kins-Aria-Andromeda
https://www.quora.com/profile/TanyaStevenson1/mistress_zabava-katASShley-Lady-Loyalty-Crystal-Carter-Brittany-Oconnell-zoefelicitas99-ladymaya-1-Dakotah
https://www.quora.com/profile/AnaPartridge836/SkiMaskBxtch-JadeeHarlow-Jade-Sin-MILFMOMMY420-Creepitreal69-Cakedupp-BabyKhocolate-pocahontas-1-Graziel
https://www.quora.com/profile/JohnGibson605/Brownskinn_BBW-Skylar-Waters-JordynnJets-LaylaEve-C4OTICDUWM13-wetprincess5150-spookybetty-Arya_Storm-bo
https://www.quora.com/profile/RachelJarvinen382/tiny-chocobo-Lunna-Real-SydneyStJames-Teri-Starr-Ashley-Alban-KarinaKane-BlackHoneyBunz-Lexiilexii-Blond
https://www.quora.com/profile/JasonGuzman16/bleauvelvet-Seka-Black-Arielxoxo13-SammiSugarqueer-ViHimura-alyssa-bounty-bratty20-Lorie_Cruz-triggered2
https://www.quora.com/profile/DanielleCooper28/Dutchbbcgirl-Dabhoneyy-KristeeLixx-AnnieRainna-TeenyTinyMiki-lilgothbaby-MsWinterMonroe-Smilesarah-Luxur
https://www.quora.com/profile/BinkMccraw897/riruonlyfan-GameKitten42-Beautyntek-LaWeraa-Secret_fox-Queen__Charlene-LexiiEros-kristinnka-cherry-leigh

#19 By 4240821 (103.152.17.80) at 10/31/2023 9:16:38 AM
https://app.socie.com.br/read-blog/97483
https://app.socie.com.br/read-blog/97486
https://app.socie.com.br/read-blog/97519
https://app.socie.com.br/SmokeGoddessArcticKitty69
https://app.socie.com.br/read-blog/97519
https://app.socie.com.br/CookieBBWLissieLove
https://app.socie.com.br/read-blog/97232
https://app.socie.com.br/CharmshyPrincessVinaKai
https://app.socie.com.br/read-blog/97654
https://app.socie.com.br/Phatfetishkia1

#20 By 4240821 (103.151.103.150) at 10/31/2023 5:34:35 PM
https://app.socie.com.br/LittleKitttyyAlexxaAngel
https://app.socie.com.br/read-blog/98213
https://app.socie.com.br/godbabeExpensiveEbony
https://app.socie.com.br/read-blog/97525
https://app.socie.com.br/PameyLeoLunalovlace
https://app.socie.com.br/HederaHelixLillaQuinn
https://app.socie.com.br/read-blog/97592
https://app.socie.com.br/read-blog/97321
https://app.socie.com.br/melodymarksEbonymistress955
https://app.socie.com.br/read-blog/97847

#21 By 4240821 (62.76.146.75) at 11/1/2023 7:13:27 AM
http://activewin.com/mac/comments.asp?ThreadIndex=28782&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=27229&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=10437&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=68254&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=35166&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=56703&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=25058&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=57806&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=82705&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=28372&Group=Last

#22 By 4240821 (2.57.151.31) at 11/2/2023 12:23:56 AM
http://activewin.com/mac/comments.asp?ThreadIndex=18791&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=28729&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=30187&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=2974&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=40290&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=5575&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=21448&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=23098&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=15974&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=35341&Group=Last

#23 By 4240821 (212.193.138.10) at 11/3/2023 11:00:01 AM
http://activewin.com/mac/comments.asp?ThreadIndex=27804&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=7976&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=63394&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=53792&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=19824&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=13382&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=27348&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=28786&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=23076&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=34696&Group=Last

#24 By 4240821 (109.94.216.41) at 11/5/2023 1:28:37 AM
https://hotslutss.bdsmlr.com/post/655874629
https://hotslutss.bdsmlr.com/post/652331316
https://hotslutss.bdsmlr.com/post/651294899
https://hotslutss.bdsmlr.com/post/651032006
https://hotslutss.bdsmlr.com/post/651882687
https://hotslutss.bdsmlr.com/post/656155238
https://hotslutss.bdsmlr.com/post/660303007
https://hotslutss.bdsmlr.com/post/660653978
https://hotslutss.bdsmlr.com/post/649747590
https://hotslutss.bdsmlr.com/post/654493737

#25 By 4240821 (92.119.163.194) at 11/5/2023 11:19:00 PM
https://printable-calendar.mn.co/members/19897073
https://printable-calendar.mn.co/members/19904884
https://printable-calendar.mn.co/members/19911852
https://printable-calendar.mn.co/members/19914676
https://printable-calendar.mn.co/members/19899100
https://printable-calendar.mn.co/members/19919234
https://printable-calendar.mn.co/members/19894731
https://printable-calendar.mn.co/members/19897239
https://printable-calendar.mn.co/members/19897486
https://printable-calendar.mn.co/members/19898716

Write Comment
Return to News
  Displaying 1 through 25 of 324
Last | Next
  The time now is 5:43:52 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *