Exploits a plenty – IE / Excel (Firefox?)



There are a number of vulnerabilities that are currently unpatched, but have working publicly known exploits for Excel (*2) and Internet Explorer (2 vulnerabilities here as well.) Proof of Concept code has been released for both the Excel and Internet Explorer vulnerabilities. This means, with the code publicly available, it won’t be long before it’s bundled into other malware delivery structures…. You might look at alternative browsers, BUT…. be forewarned that one of these vulnerabilities appears to work on a fully patched install of Mozilla-Firefox. (According to Sans – the Secunia code doesn’t – but the full disclosure exploit code does affect Firefox.) I’ve seen word of early 1.5.0.5 builds being available – I wonder if that will be modified to fix this issue?


The Excel flaws have been talked about for a while, code is now available which ratchets up the concern around those. For web browsing – it might be worthwhile to consider browsers other than IE unless absolutely necessary. Yes, firefox is affected by one of these, but time to patch has typically been shorter for browsers OTHER than IE.

Avoid clicking links in unexpected emails/attachments in unexpected emails. It’s all a matter of trust….

For IE users – you might protect yourself by running as a limited user or one of the various programs that will let IE drop priviliges. Sandboxie.com might be one possibility for you.

–UPDATE — 6/30/06 –

It appears that Firefox IS NOT VULNERABLE to the above vulnerabilities. According to SANS there had been some initial concern that one of these vulnerability exploits also worked with Firefox. Further investigation has turned that out to be false. There’s also a brief comment at a mozillazine.org weblog on the issue (referring to the SANS post.)

Related Posts

Blog Traffic Exchange Related Posts
  • Firefox 1.5 vulnerability Incidents.org has reported on the first announced vulnerability with Mozilla Firefox 1.5 since it's release. The vulnerability is along these lines. History of visited sites is kept in a file called history.dat IF a URL for a visited site is long enough it will cause a buffer overflow and denial......
  • Try another web browser - Mozilla Firefox Most people use Internet Explorer for windows and why not? It's preinstalled on every Windows PC. Well, there are a number of reasons to consider using another product. One is security. I'm not about to say that open source software does not have security vulnerabilities. It does. I have found......
  • Ebay "sell your item" upgrade leaves linux behind? Ebay is apparently aware of some problems with their new "Sell your item" tool and linux web browsers. The linux.com article above says that they tried with several browsers windows/linux/mac and the common denominator was linux. Even firefox on linux failed where firefox on windows worked (and the user agent......
Blog Traffic Exchange Related Websites
  • Solidifying WP Security Designed with PHP, and powered by mySQL directories, WordPress is used by an amazing 8.5% of all websites. Web delivered spyware and web page hacking are becoming progressively more common. With such a lot of web content using WordPress as a CMS, any security weaknesses in the CMS structure or......
  • Recover Lost Windows Keys [/caption] It's frustrating to lose your keys, particularly if it is your Product Registration Key for Windows or other software products.  Karl Gechlik over at makeuseof.com has a nice little write-up about a product called the Magic Jelly Bean Finder that helps you to recover lost product codes.  I've used......
  • FTP And Other File Transfer Tools In Web Hosting Anything related to the Internet or computers is bound to introduce technical issues pretty soon. One of the earliest that novice web site owners encounter is FTP, which is an acronym for File Transfer Protocol. Seeing it spelled out, it's easy to see why those in the know quickly move......
en.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site