Author Topic: IE exploits now seen worldwide!  (Read 27043 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
IE exploits now seen worldwide!
« on: December 13, 2008, 11:21:25 PM »
Hi malware fighters,

The number of exploits for a recent  hole in Internet Explorer is growing rapidly, and now also hits Internet Explorer 6 and the beta version of IE 8. Through the hole attackers install password stealers together with key-loggers. Microsoft warns that "surfing in a secure matter" alone won't help, because the exploits could also land on legit websites. "During previous months we have seen an increase in SQL-injection attacks", according to Microsoft's av-analyst Tareq Saade. His advice is to update all security software. The Microsoft av scanners is detecting the exploits recently detected (Does avast do also?) http://blogs.technet.com/mmpc/archive/2008/12/11/limited-exploitation-of-microsoft-security-advisory-961051.aspx

Exploits have been seen to appear all over the world, like is shown in the picture I have attached, but attackers use Chinese domains as a rule. Following webpages could have exploits: 7.hxm, I7.hxm, ie07.hxm, msxml.hxm en ss.hxm.  (hxm=htm),

polonus
« Last Edit: December 13, 2008, 11:23:09 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: IE exploits now seen worldwide!
« Reply #1 on: December 14, 2008, 01:07:30 AM »
Hi malware fighters,

This I saw from the Secunia discussion of the recent exploits for IE6, IE7, IE8 beta:
Quote
To clarify three common incorrect assumptions about this vulnerability:

Assumption: Only Internet Explorer 7 is vulnerable.
Correction: No, at least Internet Explorer 6 is also affected, but not by the public exploits that are currently available. According to Microsoft's updated advisory, IE 5.01 is also affected. We have not confirmed this yet, but it seems plausible.

Assumption: The core problem is related to XML processing.
Correction: No, it's related to data binding. Working exploits can be created nicely without using XML.

Assumption: Setting the security level to "High" for the "Internet" security zone or disabling "Active Scripting" support protects me against attacks.
Correction: Technically no. It is still possible to trigger the vulnerability. However, it does make exploitation trickier as it protects against attacks using scripting.


polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

samuelvirucide

  • Guest
Re: IE exploits now seen worldwide!
« Reply #2 on: December 14, 2008, 03:29:05 AM »
 ;D Hi polonus

 better to throw or don t use internet explorer because a lot of people don t care what kind of web browser they are using. A lot of them as long they connect to internet they are satisfied. not knowing they are using a more vulnerable browser.They don t heed with this kind of warning!!!!By the way thanks to your info warning  :D

Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: IE exploits now seen worldwide!
« Reply #3 on: December 14, 2008, 07:19:50 AM »
Thanks for the heads-up polonus.
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!

Offline alanrf

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3870
  • Just an avast user
Re: IE exploits now seen worldwide!
« Reply #4 on: December 14, 2008, 07:32:31 AM »
Given other rather emotional threads in the browser wars ... let me just say (however futile the effort may be) that the vast majority of IE users who are going to their everyday websites will be just fine using IE.  It is those who venture down dark alleyways of the Internet (as well as real life) who need to be much more concerned about the risks of doing so.

Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: IE exploits now seen worldwide!
« Reply #5 on: December 14, 2008, 07:37:37 AM »
Given other rather emotional threads in the browser wars ... let me just say (however futile the effort may be) that the vast majority of IE users who are going to their everyday websites will be just fine using IE.  It is those who venture down dark alleyways of the Internet (as well as real life) who need to be much more concerned about the risks of doing so.


Agreed alanrf, Since hearing about this I and my Wife have been staying on sites we know we can trust.
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!

Offline alanrf

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3870
  • Just an avast user
Re: IE exploits now seen worldwide!
« Reply #6 on: December 14, 2008, 07:44:23 AM »
Before anyone tells us that the the well-known and respected sites are not infallible.  We know.  We use the tools we have, we do our best to be careful.  Beyond that you might as well say that the Internet should not be used ... if you do ... well, be prepared to be trampled into the dust by the hordes who ignore you.   

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: IE exploits now seen worldwide!
« Reply #7 on: December 14, 2008, 08:04:20 AM »
Before anyone tells us that the the well-known and respected sites are not infallible.  We know.  We use the tools we have, we do our best to be careful.  Beyond that you might as well say that the Internet should not be used ... if you do ... well, be prepared to be trampled into the dust by the hordes who ignore you.   

Polonus already did, in the article, but apparently you two missed it.  ;)

Quote
Microsoft warns that "surfing in a secure matter" alone won't help, because the exploits could also land on legit websites.
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline alanrf

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3870
  • Just an avast user
Re: IE exploits now seen worldwide!
« Reply #8 on: December 14, 2008, 08:10:12 AM »
Frank,

I do not wish to appear pushy.  However you have been asked this question before and you have not responded except with the circuitous response you just gave. 

WHAT IS YOUR SUGGESTION TO THE PROBLEM?  You criticized Bob for trying to be above it all ... are you trying to fly beneath it all?   





Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: IE exploits now seen worldwide!
« Reply #9 on: December 14, 2008, 08:19:31 AM »
Before anyone tells us that the the well-known and respected sites are not infallible.  We know.  We use the tools we have, we do our best to be careful.  Beyond that you might as well say that the Internet should not be used ... if you do ... well, be prepared to be trampled into the dust by the hordes who ignore you.   

Polonus already did, in the article, but apparently you two missed it.  ;)

Quote
Microsoft warns that "surfing in a secure matter" alone won't help, because the exploits could also land on legit websites.


I didn't miss it, One of my tools:  http://www.sandboxie.com/

"Secure Web Browsing: Running your Web browser under the protection of Sandboxie means that all malicious software downloaded by the browser is trapped in the sandbox and can be discarded trivially"
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: IE exploits now seen worldwide!
« Reply #10 on: December 14, 2008, 12:35:32 PM »
Frank,

I do not wish to appear pushy.  However you have been asked this question before and you have not responded except with the circuitous response you just gave. 

WHAT IS YOUR SUGGESTION TO THE PROBLEM?  You criticized Bob for trying to be above it all ... are you trying to fly beneath it all?   

Well, I thought everybody knew my position, because I've repeated it often enough, but I've added a post to make it absolutely clear in the thread you mention.
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: IE exploits now seen worldwide!
« Reply #11 on: December 14, 2008, 12:36:48 PM »
More on the IE hole here:

http://voices.washingtonpost.com/securityfix/2008/12/microsoft_big_security_hole_in.html

Seems AV detection is not so good.  :-\
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: IE exploits now seen worldwide!
« Reply #12 on: December 14, 2008, 01:18:40 PM »
Hi FwF and others,

What a gaping hole inside all versions of the IE browsers has to do with "browser wars" is beyond me!

Why users don't care a hoot is just demonstrating that they are just following the line and consensus. "I have blue e so I should click it, no matter what. Didn't  know or care that anything else existed." Well such an attitude I can fully understand, if you never heard anything else. A little discussion can just change all these insights. What I cannot understand is that when something apparently is wrong with Internet Explorer's security and it has not been fully patched and there are only semi-work-arounds, "some" react as being stung by a wasp, yes and reactions are sometimes "irrational" even.

A browser is a browser, be it IE, Opera, SRWareIron, Flock, whatever. What do you do when you have a serious vulnerability in a program like a MediaPlayer? You change it for another less vulnerable kind of player, wait until a new version comes out and/or upgrade or wait until it is patched, or go on about your business and take the risks for granted. It is your choice- it is a free world.
Why all of a sudden this gets different when a browser should be involved?

polonus

P.S. Where you should not go using IE: http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20081210
Snort-rules to detect the exploit: http://www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/CURRENT_EVENTS/CURRENT_IE_0Day
« Last Edit: December 14, 2008, 01:55:47 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48562
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: IE exploits now seen worldwide!
« Reply #13 on: December 14, 2008, 09:18:03 PM »
Unfortunately FWF has been bashing IE and Microsoft for so long that he has lost sight of the fact:
It is the most widely used browser and operating system in the world.

Bashing the browser and the operating system or any one who uses one or both doesn't cure anything.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Jtaylor83

  • Guest
Re: IE exploits now seen worldwide!
« Reply #14 on: December 14, 2008, 10:06:15 PM »
Looks like everyone will be forced to buy a Mac. Apple has yet to win again.

On Second thought, these exploits can also infiltrate the stock markets globally, causing the global economy to crash instantly.

For those who have Firefox with NoScript, what if these exploits manage to bypass NoScript?