Daily Talk Forum
  • Advertise
  • Search
  • Member List
  • Calendar
Hello There, Guest! Login Register
Daily Talk Forum › General Discussions › Technology, Computers and the Internet v
« Previous 1 ... 10 11 12 13 14 ... 41 Next »

Internet Explorer 6 and 8 also affected by zero-day vulnerability



Post Reply 
 
Thread Rating:
  • 0 Votes - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Threaded Mode | Linear Mode
Internet Explorer 6 and 8 also affected by zero-day vulnerability
cyrano Offline
Diamond Member
*****
Diamond Members

Posts: 3,573
Joined: May 2007
Reputation: 3
Post: #1
Internet Explorer 6 and 8 also affected by zero-day vulnerability

Source:heise online

Microsoft says Internet Explorer 5.01, 6 and 8 (beta) are also potentially susceptible to the zero-day exploit, published recently. Until now it had been assumed that only Internet Explorer 7 contained the vulnerability. However, no attacks on versions 6 and 8 have yet been observed. As a result of revising its security instructions for different versions, Microsoft has highlighted further measures users can take to defend their systems against attacks until a patch is provided.

Microsoft recommends that Data Execution Prevention (DEP) and memory protection be enabled in Internet Explorer 7 (Tools/Internet Options/Advanced/Enable memory protection...), but this can only be done in the browser itself in the 32-bit version of Vista. In the 64-bit version of Vista, DEP is automatically globally enabled. Configuring this option via browser settings is not a possibility under Windows XP. Instead, users have to activate DEP for the complete system via System/Advanced/Performance/Settings/Data Execution Prevention.
However, H. D. Moore has recently published a Metasploit module for the exploit. When tested by heise Security, this evaded Data Execution Prevention under both Windows XP SP2 and Vista, and ran injected code. In his module, Moore used the techniques published by Alexander Sotirov and Mark Dowd in mid-year.
Microsoft further recommends that the Internet zone security setting be set to "High", and that access to the oledb32.dll library be prevented. This, it says, is the most reliable protection at present. The Microsoft Security Advisory gives full instructions for each operating system.
The Internet Storm Center meanwhile reports that the exploit appears to be foisted on harmless web sites by SQL injection. Since the exploit code has been known for some days, it is likely that such attacks will shortly multiply. Administrators should keep an eye on their servers in the next few weeks and check their logs for this kind of suspicious activity.
Danish security company Secunia say in their blog, that this is not a problem with XML as at first thought, but with data binding.
12-14-2008 07:22 AM
Find all posts by this user Quote this message in a reply


« Next Oldest | Next Newest »
Post Reply 


Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  How do you connect xbox 360 to the internet? Toccara 3 2,006 07-22-2011 12:53 AM
Last Post: Ooka
  Majority of internet enquiries in UK 'Googled' forwardone 2 1,532 07-22-2011 12:47 AM
Last Post: Ooka
  Is the Internet the Secret to Happiness? forwardone 6 2,874 06-09-2011 05:04 PM
Last Post: forwardone
  Is internet marketing over? Howarde 1 1,148 06-06-2011 08:51 PM
Last Post: ItzAngel
  What is the best site for PLR for internet marketing? Lyndonn 0 772 04-28-2011 08:25 AM
Last Post: Lyndonn

  • View a Printable Version
  • Send this Thread to a Friend
  • Subscribe to this thread
Forum Jump:


User(s) browsing this thread: 1 Guest(s)

Advertise on Daily Talk Forum
  • Webmaster Forum
  • cPanel Hosting
  • SEO Directory
  • Toronto
    • Contact Us
    • Daily Talk Forum
    • Return to Top
    • Lite (Archive) Mode
    • RSS Syndication
    • Help
    • Portal
    • Membership
    • Advertise
    • Banners
    • Privacy
    • Rules

    • Review DTF at Alexa
    • Review DTF at Nortons
    • Site Map

    • Links
    • Your Link Here
    Current time: 01-26-2021, 12:57 PM Powered By MyBB, © 2002-2021 MyBB Group Theme created by Justin S