Internet Explorer browser vulnerable to hijacking

Bits, Bytes & Bootstraps

Moderator: Jedi

Locked
User avatar
canuck
I live here
Posts: 3382
Joined: 14th Feb, '08, 07:35
Mood: 109

Internet Explorer browser vulnerable to hijacking

Post by canuck » 16th Dec, '08, 06:22

SAN FRANCISCO - Users of all current versions of Microsoft Corp.'s Internet Explorer browser might be vulnerable to having their computers hijacked because of a serious security hole in the software that had yet to be fixed Monday.

The flaw lets criminals commandeer victims' machines merely by tricking them into visiting Web sites tainted with malicious programming code. As many as 10,000 sites have been compromised since last week to exploit the browser flaw, according to antivirus software maker Trend Micro Inc.

The sites are mostly Chinese and have been serving up programs that steal passwords for computer games, which can be sold for money on the black market. However, the hole is such that it could be "adopted by more financially motivated criminals for more serious mayhem — that's a big fear right now," Paul Ferguson, a Trend Micro security researcher, said Monday.

"Zero-day" vulnerabilities like this are security holes that haven't been repaired by the software makers. They're a gold mine for criminals because users have few ways to fight off attacks.

The latest vulnerability is noteworthy because Internet Explorer is the default browser for most of the world's computers. Also, while Microsoft says it has detected attacks only against version 7 of Internet Explorer, which is the most widely used edition, the company warned that other versions are also potentially vulnerable.

Microsoft said it is investigating the flaw and is considering fixing it through an emergency software patch outside of its normal monthly updates, but declined further comment. The company is telling users to employ a series of complicated workarounds to minimize the threat.

Many security experts, meanwhile, are urging Internet Explorer users to use another browser until a patch is released.

___

On the Net:

Microsoft's advisory:

http://www.microsoft.com/technet/securi ... 61051.mspx

User avatar
Fat Bob
Can't find the exit
Posts: 7964
Joined: 14th Feb, '08, 07:42
Mood: Born to Tour!
Location: Top of the world, looking down on creation

Re: Internet Explorer browser vulnerable to hijacking

Post by Fat Bob » 16th Dec, '08, 08:17

So what happens if you have decent anti-virus, spyware and firewall protection? Does this still apply?

And has anyone found a program that abuses this vulnerability yet? Or is it something that MS will fix prior to the program being run?

Anyhow, luckily we have a random-number generator with Singapore banks (either a dongle or SMS code).
"Remember that you are an Englishman, and have consequently won first prize in the lottery of life" ...Cecil Rhodes.

Poppy Appeal

User avatar
Jedi
Going Postal
Posts: 1496
Joined: 14th Feb, '08, 12:44
Mood: What evs
Location: Land Down Under

Re: Internet Explorer browser vulnerable to hijacking

Post by Jedi » 16th Dec, '08, 11:26


User avatar
Kooky
Can't find the exit
Posts: 8481
Joined: 5th Mar, '08, 13:32
Mood: Superior
Location: Ringside Seat

Re: Internet Explorer browser vulnerable to hijacking

Post by Kooky » 16th Dec, '08, 11:35

Now what we need is the real story from an IT security expert.

If only we knew one...

User avatar
SunshineAfterRain
Post Traumatic Stress
Posts: 337
Joined: 17th Feb, '08, 11:35
Mood: She is the whole world to me

Re: Internet Explorer browser vulnerable to hijacking

Post by SunshineAfterRain » 16th Dec, '08, 14:25

May I ask which version of IE are you currently using? I have installed and been using IE 8 and I have yet to receive an hackers/intruders alert from my anti-virus programmes.

Time to upgrade if you are still using IE7.
Every flower that ever bloomed, had to go through a whole lot of dirt to get there!

User avatar
Jedi
Going Postal
Posts: 1496
Joined: 14th Feb, '08, 12:44
Mood: What evs
Location: Land Down Under

Re: Internet Explorer browser vulnerable to hijacking

Post by Jedi » 17th Dec, '08, 13:59

Reminder about IE8 (from the horses mouth):
Beta software is at a stage in the development process where it is ready to be evaluated by users while still undergoing testing. Internet Explorer 8 Beta 2 is close to its final release, but you may encounter a few bugs or compatibility issues while browsing websites.

If you're okay with using a beta product, install Internet Explorer 8 Beta 2 and take it for a test drive. We think you'll agree that it's faster, safer, and easier to use than ever. If you don't like it you can easily uninstall it whenever you want.

You can find uninstall instructions at our support page for Internet Explorer 8.

We understand if you feel uncomfortable installing beta software. Check this website in the coming months to see when the "final" version of Internet Explorer 8 is available.

Locked