Author Topic: New vulnerability in IE  (Read 19785 times)

0 Members and 1 Guest are viewing this topic.

Online bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48553
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: New vulnerability in IE
« Reply #30 on: March 25, 2006, 03:27:43 PM »
That makes absolutely no sense. ??? The latest IE 7 Beta is the only version of IE that is NOT affected by this vulnerability? Not to mention IE 7's interface is 100 times better than IE 6, you can easily uninstall it if you don't want it.
Have to agree with that statement.
If you use an IE based browser like I do, it also makes it safer.  :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

neal62

  • Guest
Re: New vulnerability in IE
« Reply #31 on: March 25, 2006, 05:47:01 PM »
tednelly,

Lol, yes me thinks they haven't had enough practice either. Practice does make perfect in alot of situations.  ;D
« Last Edit: March 25, 2006, 05:48:37 PM by neal63 »

CharleyO

  • Guest
Re: New vulnerability in IE
« Reply #32 on: March 25, 2006, 07:21:31 PM »
That makes absolutely no sense. ??? The latest IE 7 Beta is the only version of IE that is NOT affected by this vulnerability? Not to mention IE 7's interface is 100 times better than IE 6, you can easily uninstall it if you don't want it.


Along with Bob, I have to say that if you are using IE or any browser based on IE then it would certainly be best to update to IE7 Beta2 version 5335.5 which I did the next day after that version release.    :)

I would not say that IE7's interface is 100 times better but it is certainly better by some degree. And as Mastertech says, it is easily uninstalled should you want to do so. Actually, I have done that with the latest build and then re-installed it to fix a minor glitch with an add-in for the browser.    :)


***

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: New vulnerability in IE
« Reply #33 on: March 25, 2006, 11:51:17 PM »
Hi CharleyO,

One thing we must conclude, and that is to the benefit of all.
Always update and always patch continuously. That is one of the basic secrets. Then a great help is to surf with normal users'rights, and to reduce the users' rights for processes with a program like ShareEnum. very informative program to see where your policies are wrong. Only allow scripts when you really cannot do without it also helps a lot towards safe browsing, whatever type of browser you may use. The final conclusion for me burns down to this "a browser is as secure as the owner who uses it". Period.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Mastertech

  • Guest
Re: New vulnerability in IE
« Reply #34 on: March 26, 2006, 01:58:34 AM »
Normal User accounts for any power user are practically useless and not a realistic solution. They are also completely unnecessary with the proper security policies.

CharleyO

  • Guest
Re: New vulnerability in IE
« Reply #35 on: March 26, 2006, 03:01:39 AM »
***

Yes, I agree with you on all of the above, Polonus. I get many prompts about scripts & ActiveX because I want to know before rather than after something happens.
Quote
The final conclusion for me burns down to this "a browser is as secure as the owner who uses it". Period.
Nothing truer can be said about any browser than the statement above. It is, after all is said and done, up to the browser owner/user to be as secure and as safe as is possible.


***

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: New vulnerability in IE
« Reply #36 on: March 26, 2006, 09:39:01 PM »
Microsoft mulls rushing out IE patch

Quote
Microsoft may rush out a security update for Internet Explorer to fix a flaw that is now being exploited to attack Windows systems, security companies say.

Computer code that demonstrates how a hacker can use the flaw to take over a PC was released onto the Net on Thursday. At least two such exploits were made public, and one has now been adapted to attack systems, Monty IJzerman, the manager of security content at McAfee, said on Friday.

"This exploit code is being used in the wild in malware," or malicious software, IJzerman said. "I expect other attacks to be prepared and to be out there over the next few days."

In a security advisory issued Thursday, Microsoft said it will address the vulnerability in a security update, but did not say when that patch would be delivered. Its next "Patch Tuesday" bundle of fixes is scheduled for April 11. On Friday, however, Microsoft indicated that a security patch might be released outside of the regular cycle.

"It is on the table," said Stephen Toulouse, a program manager in Microsoft's Security Response Center. "Every time any kind of exploitation is going on, it is on the table."

The flaw is the third to hit Microsoft this week. It has to do with how Internet Explorer handles the "createTextRange()" tag in Web pages. A hacker could take advantage of it to gain control over a vulnerable PC by crafting a specially coded Web site, Microsoft said.

McAfee found that a Web site is using the IE vulnerability to sneak malicious code onto vulnerable Windows PCs, IJzerman said. The company has updated its security software to protect against that code, which IJzerman could only describe as something related to spyware.

http://news.com.com/Microsoft+mulls+rushing+out+IE+patch/2100-7349_3-6053961.html?tag=cd.top
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: New vulnerability in IE
« Reply #37 on: March 29, 2006, 12:02:12 AM »
Hi FwF,

Read here: http://www.2-spyware.com/news/post71.html

Time for some measures.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!