Update on Internet Explorer Exploit in the wild



If you use Internet Explorer to browse the web, I’d suggest finding the instructions to disable active scripting, or drop it and use something else in light of the recent exploit floating around. It seems that in spite of Microsoft’s infinite wisdom that “Microsoft has determined that an attacker who exploits this vulnerability would have no way to force users to visit a malicious Web site. Instead, an attacker would have to persuade them to visit the Web site, typically by getting them to click a link that takes them to the attacker’s Web site”…. the reality is that legitimate sites have been hacked and the malicious code has been added. (Over 200 legit sites…)


Good details on this come from The security fix. The available options seem to be 1) disable active scripting (some sites may not work after this unless you add them to trusted sites…) 2) download IE7 beta2 preview (unstable beta browser?) 3) USE ANOTHER BROWSER. I would highly recommend option 3 and/or option 1, in that order…. The most popular rendition of this exploit seems to be dropping software that’s collecting private information.

Hopefully there will be an out of cycle patch for this, but from Microsoft’s official releases, it doesn’t seem they see it as a big problem “an attacker would have to persuade them to visit the Web site, typically by getting them to click a link that takes them to the attacker’s Web site”

If you’re interested in more details in what’s getting collected… Sans has a page analyzing some of what’s being snatched.

Be cautious….

Related Posts

Blog Traffic Exchange Related Posts
  • Disinfecting a PC… part 4 So, AVG has been scanning away finding things we've really got a foothold on the system and the malware has a fight on it's hands. It's good to see progress. Up to this point we've had multiple Spool32 errors (printer related). These errors are what prompted the system to be......
  • How Microsoft could patch VML vulnerability before October's patch day SO, there's the second big vulnerability exploit for Internet Explorer making the rounds in about a week and Microsoft's advisory says that the most recent flaw will likely be patched on October's patch day ("unless the need arises...") So, what would trigger that need? Lot's of browsers being subjected to......
  • Google Analytics under the microscope I've spent some time this evening looking at Google Analytics. (Now the data is being collected.) And I've got to say I'm impressed with the scope of what I'm seeing. First, since last night, more stats have been collected, there seem to be some missing from today yet (maybe ~12......
Blog Traffic Exchange Related Websites
  • Mini Sites Vs. Authority Sites - Which Is Better? Mini sites and authority sites represent two alternative online marketing models, and not everyone understands the real differences. Inexperienced internet marketers often don't know the difference or have trouble choosing between these alternatives. Among the many considerations that are involved, you can't ignore Google's algorithms when it comes to ranking......
  • How To Boost Your Productivity On Social Media Sites Today social media marketing leads the way for marketing efforts online. There are several companies that are taking advantage of social media to get more exposure and to drive targeted traffic to their sites. The biggest issue, though, is that it is really, really hard to be productive when you......
  • Reciprocal Link Building - Double The Web Traffic To Your Site Reciprocal Link Building - Double The Web Traffic To Your Site Reciprocal reciprocal link building is one of the best ways to attract a substantial amount of web traffic to your site. In this process, you have to exchange link with another high traffic website. You start the process by......
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site