Home » Computer Security

0-day exploits for IE flaw another reason to switch to IE8

Computer infected with Trojans, Spyware or Virus? Are you getting many fake security pop-ups and warnings? Computer working really slow? Not to worry. Our website provides you with free virus removal steps and free malware removal tools to remove spyware, trojans and virus. Search this site for removal instructions and Free Spyware Removal tools.

                                

 

Download Spyware Doctor To Remove This Virus "Spyware Doctor delivers powerful protection against spyware and adware threats. Spyware Doctor is honored by many of the world’s leading PC mags, including PC World, PC Magazine, and CNET."

Download Spyware Doctor

0-day exploits for IE flaw another reason to switch to IE8

11 March 2010

Microsoft confirmed on Tuesday a new flaw affecting version 6 and 7 of its Internet Explorer web browser that could allow remote code execution. The security advisory noted that targeted attacks using the flaw were already in the wild.

This information was confirmed by McAfee, reporting that exploitation of the flaw was originating from the domain topix21century dot com over both HTTP and HTTPS. The drive-by attacks install a backdoor which connects to a command-and-control server.

Analysis by Symantec reveals that the exploit works effectively on IE6. IE7 tended to crash instead, and IE8 is, as stated in the Microsoft advisory, immune. The attack loads some malicious code, and then makes repeated changes to the HTML document eventually provoking execution of the malicious code.

The best solution is to upgrade to IE8, as one of the many improvements found in this browser also seals off the security hole. Failing that, enabling Data Execution Prevention in IE7 should provide some level of mitigation, as the current exploits do not circumvent DEP (though they could probably be combined with DEP bypass techniques). Removing access to the file iepeers.dll using either of the mechanisms described in Microsoft’s advisory prevents Internet Explorer from loading the flawed code, but may also break print and web folder functionality. Finally, disabling of scripting and ActiveX in the Internet and Local Intranet security zones should also provide protection against exploitation.

Microsoft has still made no indication whether this flaw will receive an out-of-band update, but with exploits in the wild and documented analysis of the exploit, clearly this flaw is something that needs fixing, and soon.

Read the comments on this post



More Details

 

Share/Save/Bookmark

Leave your response!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.

Spam Protection by WP-SpamFree

website statistics