Showing posts with label IE7. Show all posts
Showing posts with label IE7. Show all posts

Thursday, May 01, 2014

Out of Band Security Update for IE Zero-Day Vulnerability


Microsoft released an out-of-band security update to address the security vulnerability in Internet Explorer described in Microsoft  Security Advisory 2963983.

Of important note:  Although Windows XP is no longer supported by Microsoft, the decision was made to issue a security update for Windows XP users.

Critical:

  • MS14-021 -- Security Update for Internet Explorer (2965111) 

    This security update resolves a publicly disclosed vulnerability in Internet Explorer. The vulnerability could allow remote code execution if a user views a specially crafted webpage using an affected version of Internet Explorer. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.


    References




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...




    Sunday, April 27, 2014

    Security Advisory 2963983, IE Zero-Day Vulnerability

    Security Advisory
    Microsoft released Security Advisory 2963983 which relates to a vulnerability in Internet Explorer.

    With the vulnerability, an attacker could cause remote code execution if someone visited a malicious website with an affected browser. Generally, this would occur by an attacker convincing someone to click a link in an email or instant message.

    Although the vulnerability affects all versions of IE, at this time, Microsoft is aware of limited, targeted attacks, in which the exploit observed appears to target IE9, IE10 and IE11.


    Additional details about the exploit are available from the FireEye Blog, New Zero-Day Exploit targeting Internet Explorer Versions 9 through 11 Identified in Targeted Attacks.

    Recommendations 

    As illustrated in the "Security Research and Defense Blog" reference below, users of IE 10 and 11 should ensure they haven't disabled Enhanced Protection Mode. 

    Another option is to install the Enhanced Mitigation Experience Toolkit (EMET).  The recommended setting for EMET 4.1, available from KB Article 2458544, is automatically configured to help protect Internet Explorer. No additional steps are required.

    See the Tech Net Advisory for instructions on changing the following settings to help protect against exploitation of this vulnerability:
    • Change your settings for the Internet security zone to high to block ActiveX controls and Active Scripting
    • Change your settings to prompt before running Active Scripting or to disable Active Scripting in the Internet and Local intranet security zone. 

    References:




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Tuesday, September 17, 2013

    Security Advisory 2887505 and Microsoft Fix it

    Security Advisory
    Microsoft released Security Advisory 2887505 which relates to an issue with Internet Explorer.

    It is important to note that there are a limited number of targeted attacks which are specifically directed at Internet Explorer 8 and 9. The issue, however, could potentially affect all supported versions of IE.

    As described by Dustin Childs in the below-referenced MSRC Blog post,
    "This issue could allow remote code execution if an affected system browses to a website containing malicious content directed towards the specific browser type. This would typically occur when an attacker compromises the security of trusted websites regularly frequented, or convinces someone to click on a link in an email or instant message."

    Mitigations

    Microsoft has made available a Fix it solution for users of Internet Explorer.  Additional mitigations include the following advice, also from the MSRC Blog post:

    • Set Internet and local intranet security zone settings to "High" to block ActiveX Controls and Active Scripting in these zones
      This will help prevent exploitation but may affect usability; therefore, trusted sites should be added to the Internet Explorer Trusted Sites zone to minimize disruption.
    • Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and local intranet security zones
      This will help prevent exploitation but can affect usability, so trusted sites should be added to the Internet Explorer Trusted Sites zone to minimize disruption.
    Below are the links to both apply and uninstall the Fix it solution.  Note:  The Fix it solution applies only 32-bit versions of Internet Explorer.
     
    Apply Fix itUninstall Fix it


    Another option is to install the Enhanced Mitigation Experience Toolkit (EMET), described in the "workarounds" section of the Tech Net Advisory.

    If you have Windows Vista or Windows 7 installed, you should have updated to IE9 or IE10.  In the event you haven't, it is strongly advised that you update!

    References:




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Sunday, June 16, 2013

    Microsoft Fix it to Disable Java in Internet Explorer

    java

    Java, how we love to hate you!  Many people have uninstalled Java and do not miss it.  That is most likely because they do not have desktop applications that require Java. Unfortunately, that is not the situation for those people who use Java-dependent software programs. 

    Until recently, Internet Explorer was the only major browser that did not provide a way to disable Java.  The only way to completely disable Java in IE was to disable Java through the Java Control Panel, which meant re-enabling Java when using Java-dependent programs.  That is no longer true!

    Microsoft released a Microsoft Fix it solution designed to block all Java web-attack vectors through Internet Explorer.  As explained by Cristian Craioveanu in the below-linked Security Research & Defense Blog article, the Fix it solution is made up of two parts. 
    1. The Fix It uses the Windows Application Compatibility Toolkit to change the behavior of Internet Explorer at runtime to prevent Oracle’s Java Web plugins from loading.  As a result, the Java ActiveX dlls are not loaded.
    2. The second part of the Fix it clears the access control list (ACL) in the registry for the Java Network Loading Protocol (JNLP) handler which prevents Internet Explorer from automatically opening  files.  

    Instructions

    Before installing the Fix it solution, please follow the following suggestions:

    1.  Create a restore point

    2.  Back up the Registry
    3.  Apply the Fix it

    Disable the Java web-plugin

    Apply Fix it
    Restore the Java web-plugin
     
    Uninstall Fix it

    4.  Restart Internet Explorer
    For the changes to take effect, restart IE.

    To undo the changes, run Microsoft Fix it 50995 and restart IE.

    The Fix it solution has been tested by Microsoft and will work for all versions of Java from versions 5 and above.  It also works on all supported versions of Internet Explorer, whether 32- or 64-bit.


    References


    Home
    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...


    Monday, January 14, 2013

    MS13-008 Released for Security Advisory 2794220


    Microsoft released an out-of-band security update to address the issue described in  Security Advisory 2794220.

    The update is to address an issue that affects Internet Explorer versions 6, 7 and 8.  Internet Explorer versions 9 and 10 are not affected.  

    This update is critical if you have Internet Explorer versions 6, 7 or 8 installed on your computer.  Windows XP users of IE6 or IE7 should update to IE8 as soon as possible.  Windows Vista and Windows 7 users should be using IE9.

    Note:  The Advance Notice for this update to Internet Explorer versions 6-8 indicated if the Microsoft Fix it was applied, it was not necessary to uninstall it prior to updating IE. 

    The advice provided now is to disable the Fix it after updating as it is no longer required.

    Fix it


    Disable

    Fix this problem
          Microsoft Fix it 50972

    References:



    Home
    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...


    Sunday, January 13, 2013

    Advance Notification for Update to Address Security Advisory 2794220

    Security Bulletin
    On Monday, January 14, 2013, Microsoft is planning to release an out-of-band critical security update for the issue described in  Security Advisory 2794220.

    The update is to address an issue that affects Internet Explorer versions 6, 7 and 8.  Internet Explorer versions 9 and 10 are not affected. 

    Although Microsoft has seen only a limited number of customers affected by the issue, the potential exists that more could be affected.  Thus, it is advised that the update be installed as soon as possible. 

    Even with the update, if your operating system is Windows Vista or Windows 7, update to Internet Explorer 9.  For Windows XP, your system will be more secure if you update to Internet Explorer 8.

    If you applied the Fix it released in Security Advisory 2794220, it will not need to be uninstalled before applying the security update.

    References



    Home
    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...


    Saturday, December 29, 2012

    Microsoft Security Advisory 2794220

    Security Advisory
    Microsoft released Security Advisory 2794220 to address an issue that affects Internet Explorer versions 6, 7 and 8.  Internet Explorer versions 9 and 10 are not affected.

    At this time, Microsoft is aware of a very small number of targeted attacks.  This issue allows remote code execution if users browse to a malicious website with an affected browser.  Generally, this is a result of an attacker convincing someone to click a link in an email or instant message.

    Recommendations:

    Microsoft is actively working to develop a security update to address the issue.  In the meantime, please consider the following suggestions:

    1.  Update Internet Explorer -- If your operating system is Windows Vista or Windows 7, update to Internet Explorer 9.  For Windows XP, your system will be more secure if you update to Internet Explorer 8.

    2.  Update or Uninstall Java -- Current exploits of this type of vulnerability in Internet Explorer use third-party software, including Oracle’s Java, to help obtain reliable exploitation.

    Most home computer users no longer need Java.  Following are reasons why someone may need Oracle Sun Java installed on their computer:

    • Playing on-line games generally requires Java.
    • With OpenOffice, Java is needed for the items listed here
    • It used to be that Java was needed for websites to be properly displayed. However, that is generally not the case now with Flash having taken over.
    • There may be commercial programs that depend on Java. If Java is needed for a software installed on your computer, there should be a prompt for it.
    If you need Java, be sure you have uninstalled all old, vulnerable versions and have only the most recent release installed on your computer.  The current version of Java is Version 7 Update 10.
     

    3.  Install and configure EMET -- The Enhanced Mitigation Experience Toolkit was designed to help prevent hackers from gaining access to your system. It prevents exploitation by applying in-box mitigations to help protect against this and other issues and should not affect usability of websites.

    An easy guide for EMET installation and configuration is available in KB2458544.  Additional information about configuring EMET is available in the EMET User's Guide, in the following locations:
    • 32-bit systems -- C:\Program Files\EMET\EMET User's Guide.pdf
    • 64-bit systems -- C:\Program Files (x86)\EMET\EMET User's Guide.pdf
    Additional suggestions are available in the MSRC Blog post and the Security Advisory, referenced below.

    References:




    Remember - "A day without laughter is a day wasted."
    May the wind sing to you and the sun rise in your heart...

    Friday, September 21, 2012

    Microsoft MS12-063 – Critical Cumulative Security Update for Internet Explorer


    Microsoft released MS12-063, a cumulative update for Internet Explorer addressing Security Advisory 2757760 as well as four other critical-class remote code execution issues.  The update requires a restart.
      The Bulletin addresses the following issues from the Common Vulnerabilities and Exposures (CVE) list:
      Internet Explorer 10 on Windows 8 and Windows Server 2012 is not affected.  All other versions of Internet Explorer are affected

      Support

      The following additional information is provided in the Security Bulletin:

      References





      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...


      Wednesday, September 19, 2012

      Out of Band Internet Explorer Security Update

      Security Bulletin
      On Friday, September 21, 2012, Microsoft  will release MS12-063, a cumulative update for Internet Explorer addressing Security Advisory 2757760 as well as four other critical-class remote code execution issues.  The update will require a restart.

      Microsoft Fix it

      In addition, a Microsoft Fix it solution is available now for applying ahead of the update to protect your computer.

      Fix it
      EnableDisable
      Fix this problem
      Microsoft Fix it 50939
      Fix this problem
            Microsoft Fix it 50938

      (HT:  ky331)

      References





      Home
      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...


      Sunday, October 09, 2011

      How Windows PCs Get Infected with Malware

      CSIS Security Group in Denmark conducted a study of almost three months where they collected real-time data from various so-called exploit kits that Danish users were exposed to.  As described by Peter Kruse, Partner and Security Specialist at CSIS:
      "An exploit kit is a commercial hacker toolbox that is actively exploited by computer criminals who take advantage of vulnerabilities in popular software. Up to 85 % of all virus infections occur as a result of drive-by attacks automated via commercial exploit kits."

      How PCs Get Infected

      The CSIS study revealed that as much as 99.8 % of all virus/malware infections were a direct result of not updating five specific software packages.  Aside from missing Microsoft security updates, the study revealed the following out of date programs as being the most used by malware:  Java JRE (37%), Adobe Reader and Adobe Acrobat (32%), Adobe Flash (16%) and Microsoft Internet Explorer (10%).

      Third-Party Software

      Setting aside browser and operating system for the moment, what is notable from the CSIS study is the impact of third-party software, notably Java JRE, Adobe Reader and Adobe Acrobat and Adobe Flash.

      Oracle Java JRE
      When it comes to Oracle Java JRE, you may have it installed on your computer but might not even need it.  Following are reasons why someone may need Oracle Sun Java installed on their computer:
      • Playing on-line games generally requires Java.
      • With OpenOffice, Java is needed for the items listed  here . 
      • It used to be that Java was needed for websites to be properly displayed. However, that is generally not the case now with Flash having taken over.
      • There may be commercial programs that depend on Java. If Java is needed for a software installed on your computer, there should be a prompt for it.
      If the above does not apply to you, consider uninstalling Java.  In the event you discover that it is needed, you can always download the most recent version.

      Adobe Products
      Regular readers of this blog are familiar with my postings of critical updates for Adobe products.  You may not realize, however, that there have been over a dozen critical updates of Adobe products just this year between February and September.  Combined, out-dated Adobe products were the direct result of 48% of the infections in the analysis.

      Although I will continue providing updates for these products, it is advisable that you check that you have the most recent versions of Adobe products.  Personally, I switched to an alternate PDF reader some time ago.  There are a number of open source readers available from http://pdfreaders.org/.  Others include Nitro Reader and Sumatra PDF.

      Internet Explorer

      Although Internet Explorer is listed as shown in the CSIS analysis as the most affected browser, the report falls short in not breaking down the statistics by browser version.  According to the IE6 Countdown, at the end of September, 2011, 9% of the world is still using IE6.

      It is not very likely that 66% of  reported thousands of users in the analysis who had been exposed to drive-by attacks were using IE9.  Nonetheless, Denmark should be commended with only 0.7% of the users still on IE6.  The percentage still using IE7 is unknown.  Considering the high percentage of affected Windows XP computers, it would not be surprising to learn that the majority have not updated to IE8.

      References

      CSIS: This is how Windows get infected with malware
      IE6 Countdown
      Microsoft Download Center - Windows Internet Explorer 8 for Windows XP


      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...


      Thursday, August 11, 2011

      Microsoft Update Impacts WinPatrol Cookie Monitoring

      WinPatrol fans who monitor cookies in Internet Explorer will discover after installing the latest Microsoft security updates that cookies do not display as expected in WinPatrol.

      Instead of seeing the expected site or cookie name displayed, cookies are identified as alpha-numeric.txt files (i.e., HILD912G.txt).

      In testing, I intentionally started installing the security updates one-by-one, selecting Microsoft Security Bulletin MS11-057 - Critical: Cumulative Security Update for Internet Explorer (2559049) first since it applies to all three operating systems and browsers. Indeed, following a restart, I was able to confirm the change in cookie display for IE9 on Windows 7. 

      Based on feedback from WinPatrol users, this issue has been confirmed in Windows XP, Windows Vista and Windows 7 with IE8 and IE9.  (IE6 and IE7 have not been tested but will likely be impacted the same since the update applies to all versions of Internet Explorer.)

      MS11-057 is a critical security update and it is strongly advised that it be installed. Cookies are a minor issue compared to the fix in this update, which, as described in the MSRC Blog:

      "resolves five privately reported vulnerabilities and two publicly disclosed vulnerabilities in Internet Explorer. The most severe of these vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet Explorer."
      Bill Pytlovany has been advised of the situation and is actively working on a solution.  




      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...


      Friday, March 04, 2011

      Internet Explorer 6 Countdown

      Are you included among the 12 percent of people from around the world who are still using Internet Explorer 6?  Although browser statistics of visitors to Security Garden indicate only 2.6 percent use IE 6, it is long past time for those visitors to update.

      I understand that not everyone has the latest and greatest computer.  These are hard times and we all need to watch our budget.  However, there have been numerous advances in IE since version 6 was introduced ten years ago.  Forget the pretty-pretty new features.  Most significant, from my point of view, are the enhanced security features in the newer versions of Internet Explorer.

      Granted, IE9 is not compatible with Windows XP.  However, you can still upgrade to IE8. IE8 has significant built-in security features, including SmartScreen, Cross Site Scripting (XSS) Filter, Click-jacking prevention, Data Execution Prevention, InPrivate Browsing, and InPrivate Filtering.  (See Internet Explorer 8: Features/ for information about these security and safety features.)  For those who would rather upgrade in stages, if need be, you can start with IE7 (download link below) and then follow up with IE8.

      Although most of the Security Garden visitors are from the United States, United Kingdom and Canada, people from all around the world find their way here.  If you are represented by the list of actual Security Garden visitors in the list of countries below, and are also included among the 2.66 percent of my visitors who use IE6, please update today!

      Security Garden visitors from around the world:

      Australia
      Barbados
      Belgium
      Brazil
      Brunei Darussalam
      Bulgaria
      Canada
      Chile
      Croatia
      Czech Republic
      Denmark
      Dominican Republic
      Finland
      France
      Germany
      Greece
      Hong Kong
      Hungary
      India
      Indonesia
      Iraq
      Ireland
      Italy
      Japan
      Korea, Republic Of
      Libyan Arab Jamahiriya
      Lithuania 
      Macedonia
      Malaysia
      Mexico
      Netherlands
      New Zealand
      Norway
      Pakistan
      Peru 
      Philippines
      Poland
      Puerto Rico
      Romania
      Russian Federation
      Serbia
      Singapore
      South Africa
      Spain
      Sri Lanka
      Sweden
      Switzerland
      Taiwan
      United Kingdom
      United States
      Venezuela
      Vietnam



      Don't be one of these statistics:



      References:

      Clubhouse Tags: Clubhouse, Microsoft, Internet Explorer, IE6, IE7, IE8, IE9, Windows XP, Windows Vista, Windows 7, Information, Windows



      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...

      Wednesday, January 12, 2011

      Microsoft Fix it Available for Security Advisory 2488013

      Microsoft released a Microsoft Fix it solution that uses the Windows Application Compatibility Toolkit to provide protection from the vulnerability in Security Advisory 2488013, in which exploit code is available.  This workaround only applies if the MS10-090 update for Internet Explorer is installed.  If MS10-090 has not been installed on your computer, it can be obtained from here.

      Important Note:
      Prior to 10:30 PM Pacific Time, 1/11/2011, the Fix it links in the KB Article incorrectly pointed to the Fixit for KB2490606 (information provided here). If you installed the Fixit 50590 prior to that time, you should install the Fixit using the current link in KB 2488013.

      This vulnerability affects Internet Explorer 6, 7 and 8 on 32- and 64-bit Windows XP, Windows Vista and Windows 7 as well as Windows Server 2008 R2.

      Fixit solution for recursive cascading style sheets
      The Microsoft Fix it solution adds a check to check whether a cascading style sheet is about to be loaded recursively. If this is the case, the Fix it solution cancels the loading of the cascading style sheet. This Fixit solution takes advantage of a feature that is typically used for application compatibility fixes and can modify the instructions of a specific binary when it is loaded.

      To enable or disable this Fixit solution, click the Fix it button or link under the Enable heading or under the Disable heading. Click Run in the File Download dialog box, and then follow the steps in the Fix it Wizard.

      Note:  In addition to the requirement that the MS10-090 update for Internet Explorer be installed, this Fix it solution must be manually uninstalled before you apply a future Cumulative Security Update for Internet Explorer that contains a software fix for this vulnerability.

      Enable:  Microsoft Fix it 50591
      Disable: Microsoft Fix it 50592


      Additional details about the Fix it solution are available in the Security Research & Defense Blog at New workaround included in Security Advisory 2488013.









      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...

      Wednesday, December 22, 2010

      Microsoft Security Advisory 2488013


      Microsoft released Security Advisory 2488013 to address a public vulnerability in Internet Explorer 6, 7 or 8 if you visit a website hosting malicious code.  Microsoft reported that the current impact of this vulnerability is limited and they are not aware of any active attacks.

      Microsoft is closely monitoring the situation but, due to the current limited impact, has determined there is not a need for an out-of-band release.  Should that change, an update will be provided on the MSRC Blog.


      Internet Explorer Protected Mode on Windows Vista and Windows 7 helps limit the impact of the currently known proof-of-concept exploits. Protected Mode is on by default in the Internet and Restricted sites zones in Internet Explorer 7 and 8.  Protected Mode will warn you when a website attempts to install software, run or modify sensitive system components.  If you are not familiar with Protected Mode, you can learn more about it here:  What does Internet Explorer protected mode do?



      References:
      Clubhouse Tags: Clubhouse, Microsoft, Windows, Security, Advisory, Vulnerabilities, Information, Internet Explorer,



      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...

      Wednesday, November 03, 2010

      Microsoft Security Advisory 2458511 Released


      Microsoft released Security Advisory 2458511 which relates to a vulnerability in Internet Explorer that could allow remote code execution.  The vulnerability does not affect IE9 Beta but the other versions of IE are affected.

      As indicated in the MSRC Blog, the impact of this vulnerability is extremely limited.  Microsoft is not aware of any affected customers. From the report it was indicated that the exploit code was discovered on a single website which is no longer hosting the malicious code.


      It is important to note that all attack Microsoft has seen are all blocked by DEP which is enabled by default on IE8 and can also be enabled for earlier versions of IE. Additional mitigations are described in DEP, EMET protect against attacks on the latest Internet Explorer vulnerability  and the Security Advisory.

      References:

      Clubhouse Tags: Clubhouse, Microsoft, Windows, Security, Advisory, Vulnerabilities, Information, Internet Explorer,



      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...

      Tuesday, March 30, 2010

      Security Bulletin MS10-018 Released Out of Band

      Microsoft released MS10-018 out-of-band due to increases in attacks against Internet Explorer 6 and Internet Explorer 7 using the vulnerability discussed in Security Advisory 981374.

      Although Internet Explorer 8 is not affected by Security Advisory 981374, MS10-018 is a cumulative update for IE and is directed to all versions. There are nine additional vulnerabilities addressed in the cumulative update. Detailed information is available in the MSRC Blog, Security Bulletin MS10-018 Released, including a video presentation.

      References:

      Clubhouse Tags: Clubhouse, Microsoft, Windows, Security, Updates, Vulnerabilities, Information,
      Internet Explorer


      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...

      Monday, March 29, 2010

      Out-of-Band Cumulative Update for IE Scheduled

      Microsoft is releasing security update MS10-018 tomorrow, March 30, 2010, at approximately10:00 a.m. PDT (UTC-8). MS10-018 resolves Security Advisory 981374, addressing a publicly disclosed vulnerability in both IE6 and IE7. It is important to note that IE8 is not affected by the vulnerability addressed in the advisory.

      If you have yet to update to IE8, it is strongly recommended that the update be installed as soon as it is available. As stated by Jerry Bryant in Internet Explorer Cumulative Update Releasing Out-of-Band:
      "Once applied, customers are protected against the known attacks related to Security Advisory 981374. We have been monitoring this issue and have determined an out-of-band release is needed to protect customers. For customers using automatic updates, this update will automatically be applied once it is released. Additionally, because Security Bulletin MS10-18 is a cumulative update, it will also address nine other vulnerabilities in Internet Explorer that were planned for release on April 13."
      References:

      MSRC Blog: Internet Explorer Cumulative Update Releasing Out-of-Band
      TechNet: Security Advisory 981374

      Clubhouse Tags: Clubhouse, Microsoft, Windows, Security, Updates, Vulnerabilities, Information,
      Internet Explorer


      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...

      Wednesday, February 24, 2010

      How-to: Reduce Vulnerability to Drive-by Downloads

      Is your computer more vulnerable to drive-by downloads than it needs to be? The type of drive-by download I am referring to is malware that is installed from a Web site without any user intervention through the exploitation of a vulnerable software installed on the computer. That is right. Your computer can be infected merely by landing on a Web page performing drive-by downloads.

      In Stopping Stealthy Downloads, Brian Krebs provided statistics from Dasient indicating that "in the fourth quarter of 2009, roughly 5.5 million Web pages contained software designed to foist unwanted installs on visitors". Although, as explained by Brian, there is a government-funded research group that is preparing to release a new free tool designed to block drive-by downloads, what can you do until "BLADE" (Block All Drive-By Download Exploits) is available?

      I hope Security Garden readers will recognize what they can do to help reduce their vulnerability to drive-by downloads after reviewing the statistics provided in the graphs by BLADE’s evaluation lab.

      The first graph illustrates the browser infection rate per drive-by exploit. We can see at a glance that IE6 is far more susceptible to drive-by downloads than other browsers. The surprise, however, and one I was not expecting, is the high numbers for IE7 compared to Firefox 3 and IE8.



      Now, dear readers, here is the big surprise. The BLADE lab provided information on the vulnerable applications most targeted in drive-by attacks. Surprise: Adobe and Oracle SunJava far exceed the figures of Internet Explorer.




      The lesson from this information is obvious and one members of the security community have been harping at for a long time: Microsoft security updates are only one piece of the puzzle. It is also critical that other software be kept up to date. To reduce the vulnerability to drive-by downloads, use an up-to-date browser and ensure that other vendor software is also up-to-date.

      Update/Upgrade your browser:
      Adobe Products:

      If you use Adobe products, be certain you have the most recent versions. Go to http://www.adobe.com/ to get the latest versions. Also, if you downloaded either Adobe Reader or Adobe Flash Player for Windows prior to the release of Adobe Security Bulletin APSB10-08, released February 23, 2010, see the instructions here.

      Oracle SunJava:

      With Java, it is extremely important to check that old, vulnerable installations are no longer resident on your computer. Go to Add or Remove programs and uninstall any item listing J2SE or Java Runtime Environment in the name. Unfortunately, not every version of Java will begin with "Java" so be sure to read each entry in the list. Other versions may begin with JDK, JRE or SDK.

      The latest version of Java SE is available from here. Select the JRE version and pay attention when installing the update, unchecking any pre-checked toolbar and/or software options presented with the update. They are not part of the software update and are completely optional.



      References
      :

      Graphs from BLADE Malicious URL Analysis




      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...

      Thursday, January 14, 2010

      Microsoft Security Advisory 979352 Released

      Microsoft determined that Internet Explorer was one of the vectors used in targeted and sophisticated attacks against Google and possibly other corporate networks. According to Threat Level at Wired.com, Adobe was impacted and it appears that at least 34 companies were breached.

      Following are the mitigating factors in Microsoft Security Advisory 979352:
      • Protected Mode in Internet Explorer on Windows Vista and later Windows operating systems limits the impact of the vulnerability.

      • In a Web-based attack scenario, an attacker could host a Web site that contains a Web page that is used to exploit this vulnerability. In addition, compromised Web sites and Web sites that accept or host user-provided content or advertisements could contain specially crafted content that could exploit this vulnerability. In all cases, however, an attacker would have no way to force users to visit these Web sites. Instead, an attacker would have to convince users to visit the Web site, typically by getting them to click a link in an e-mail message or Instant Messenger message that takes users to the attacker’s Web site.

      • An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.

      • By default, Internet Explorer on Windows Server 2003 and Windows Server 2008 runs in a restricted mode that is known as Enhanced Security Configuration. This mode sets the security level for the Internet zone to High. This is a mitigating factor for Web sites that you have not added to the Internet Explorer Trusted sites zone.

      • By default, all supported versions of Microsoft Outlook, Microsoft Outlook Express, and Windows Mail open HTML e-mail messages in the Restricted sites zone. The Restricted sites zone helps mitigate attacks that could try to exploit this vulnerability by preventing Active Scripting and ActiveX controls from being used when reading HTML e-mail messages. However, if a user clicks a link in an e-mail message, the user could still be vulnerable to exploitation of this vulnerability through the Web-based attack scenario.

      References
      :

      Clubhouse Tags: Clubhouse, Microsoft, Windows, Security, Adobe, Vulnerabilities, Information


      Remember - "A day without laughter is a day wasted."
      May the wind sing to you and the sun rise in your heart...