Microsoft : How to survive with a 1000lb gorilla.

Updated: 9/10/03; 11:57:05 AM.

 

Looking for a Story? Check:
 
 


 
Work:
 

Archives:
 
 
 
 
 
 
 
 

Great Sites:
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 


Subscribe to "Microsoft" in Radio UserLand.

Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.

Comments by: YACCS

« chicago blogs »

 

 

Wednesday, September 10, 2003



Microsoft Patch Doesn't Work

Critical Flaw Still Exists and is Being Exploited

http://www.secunia.com/advisories/9580/

Internet Explorer determines whether an object is safe when it interprets the file extension specified in the "Object Data" tag. This allows a malicious person to specify a "safe" file with eg. a ".html" extension in "Object Data", which causes Internet Explorer to interpret it as a "safe" file. However, when the file is retrieved by Internet Explorer the "Content-Type" header determines how the file will be treated. This allows an executable file like a ".hta" file to be treated as a "safe" file and be executed silently without restrictions.

NOTE: Further information has been released by http-equiv, proving that the patch from Microsoft is not adequate. Refer to solution section.

Secunia has constructed a vulnerability test, which can be used to check if you are affected by this issue: http://www.secunia.com/MS03-032/

Read the rest of this article at Secunia

My God, it just never ends.

This unending parade of security flaws will never stop. Between ActiveX, Microsoft-hacked Java, and HTA scripting, Internet Explorer is nothing but a collection of security flaws that loads web pages as an afterthought. Now they can't even do a proper job of patching the vulnerabilities they know that exist.

Remember Surferbar which I discussed last week? Security experts have discovered that Surferbar is exploiting one of the flaws discussed in Secunia's article to install itself. We have reason to believe that two other malware distributors also might be using, or at least testing it.

If you are using Internet Explorer as your primary browser, you are most likely vulnerable to this flaw. You can find out for sure by taking this test.

Do you want to know how to be completely safe from these security flaws? Do you want to know how to be 100% safe from driveby malware that installs right through the browser? The answer is very simple: use a real browser, not a web browsing extension tied to a Microsoft operating system.
http://texturizer.net/firebird/
http://www.opera.com/

I'm not being sarcastic. I am dead serious. Internet Explorer is not safe, except for when the most draconian precautions are taken. It is a bare bones, featureless browser that doesn't even provide tabbed browsing. I guarantee you, if you switch to Mozilla Firebird and use it for a while you will never want to use Internet Explorer again. Read all about Firebird at the official help site and decide for yourself.

Links:

http://www.secunia.com/MS03-032/ :: Secunia's vulnerability test
http://www.spywareinfo.net/sep3,2003#surferbar :: Surferbar: A Nasty New Hijacker

[Via Spywareinfo Newsletter



categories: Microsoft
Other Stories according to Google: Short-Media Forums - Microsoft IE Patch doesn ' t work ; MS03-032 | Patch for 'critical' IE vulnerability doesn ' t work : Experts: | Security firm: IE patch does not work : ZDNet Australia: IT | Patch for 'critical' IE vulnerability doesn ' t work : Experts : | When USB Connection Doesn ' t Work with WINDOWS 98 Second Edition | When USB Connection Doesn ’ t Work with WINDOWS 98 Second Edition | BigBlueBall Forums - Somebody please help!! Nega patch doesn ' t | dBforums - Security patch send via email from Microsoft doesn ' t | Security firm: IE patch does not work | CNET News.com


11:46:31 AM    


© Copyright 2003 Earl Bockenfeld.



Click here to visit the Radio UserLand website.

 



September 2003
Sun Mon Tue Wed Thu Fri Sat
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30        
Nov   Oct

Story Categories:

Blogging

Body

Digital Media

Heart

Humor

Internet

Microsoft

Mind

Miscelleous

Politics

Outrages

Security

Software

Soul

Userland

Top 10 hits for spyware adware on..
Google
1.Spychecker - download anti- spyware and privacy related freeware ...
2.Adware , Spyware and Advertising Trojans - Info & Removal ...
3.Spyware Watch (UK) - spyware , adware , stealware - stay aware!!!
4.Spyware Watch (UK) - spyware , adware , stealware - stay aware!!!
5.Spyware Watch (UK) - spyware , adware , stealware - stay aware!!!
6.Spyware Watch (UK) - spyware , adware , stealware - stay aware!!!
7.Spyware Watch (UK) - spyware , adware , stealware - stay aware!!!
8.PC Hell: Spyware and Adware Removal Help
9.Adware and Spyware Information and removal tutorials. Free ...
10.BulletProofSoft Home Page - MP3 to WAV converter, MP3 converter, ...

Help link 9/10/03; 11:46:56 AM.