Exploit for Internet Explorer (get your patches)

Status
Not open for further replies.
Joined
Feb 28, 2012
Messages
339
Location
N. Virginia
From the group that found it:
Quote:
The vulnerability affects IE6 through IE11, but the attack is targeting IE9 through IE11. This zero-day bypasses both ASLR and DEP. Microsoft has assigned CVE-2014-1776 to the vulnerability and released security advisory to track this issue.

Threat actors are actively using this exploit in an ongoing campaign which we have named “Operation Clandestine Fox.” However, for many reasons, we will not provide campaign details. But we believe this is a significant zero day as the vulnerable versions represent about a quarter of the total browser market. We recommend applying a patch once available.

http://www.fireeye.com/blog/?p=5312

They missed this MSIE vulnerability for over 13 years. It has been in the code since IE 6. Where were all the 100,000+ MS employees who supposedly check their software?

The bad guys may have been using this vulnerability for over three years. The bad guys seem to be more motivated than the good guys. The researchers who discovered it claim that "threat actors" have been using this vulnerability for an unknown period.

Supposedly some 26% of desktop browsers could be affected by this. Better make sure you're getting vendor supported patches (sorry XP users?)!

Linux and OSX are completely unaffected. They don't use MSIE. Chrome was unaffected. Firefox, Safari, Konqueror, and Opera are not affected.
 
Microsoft page about it is here. Good luck w/ that mitigations section, it's pretty wordulous. Patch is in the works apparently, until then install EMET and set all security zones to High or something? Enjoy that browsing experience.
21.gif
28.gif
 
Or alternatively another reason to leave Flash turned off whenever possible. What reputable Web site still requires Flash anymore?
 
Originally Posted By: yonyon
What reputable Web site still requires Flash anymore?


Waaaaaaaaaay too many. Most are beginning to use HTML5 for media and a variety of javascript libraries for basic animations but there is still a ways to go. Gmail.com even still prompts me to allow Flash!
 
Quote:

They missed this MSIE vulnerability for over 13 years. It has been in the code since IE 6. Where were all the 100,000+ MS employees who supposedly check their software?


lol. The were trying to fix it but couldn't find where the IDEs are using metro.
 
Originally Posted By: simple_gifts
lol. The were trying to fix it but couldn't find where the IDEs are using metro.

Well played, sir. The first time I had to use VS2012, the first thing I did after starting it for the first time was go to google, and I only had to type "why is VS2" before it completed it to "why is VS2012 so ugly?"
smile.gif
 
I don't use interest explorer. The only times I use IE only if certain websites don't play well with chrome or Firefox.
 
FF and Flash turned OFF around these parts for a few years now. And two layers of good AV/ASW.

Let's face it, most computer users are just lazy and/or uneducated in these matters, and use whatever is put in front of them. Like fish in a barrel to the bad guys.
 
Originally Posted By: Volvohead
Let's face it, most computer users are just lazy and/or uneducated in these matters, and use whatever is put in front of them.


As they should be. Non-technical users should not be subject (or continue to subject themselves) to this kind of bunk. It's a never-ending treadmill of panic, confusion and suspicion that is quite profitable to those that feed on these things (not just the bad guys, but the people making the software to begin with).

Ubuntu.
 
Where are the open source detractors/ closed source proponents now?

It wasn't too far in the past where we had guys bashing open source software because of the Heartbleed exploit and the "inept" programmers.
 
Why are all the panties twisted up?

you dont have to pick one or the other..

I use both.

Oh and explain to me how the average no-tech user can watch his netflix and amazon prime on ubuntu.. .. I'm actually serious.
 
No twisted panties here... Besides, I'm a boxers kind of guy. I just think that it's funny that the open source detractors were all over the Heartbleed thing and couple short weeks later, we have a what? 15 year old vulnerability from the biggest closed source provider ever?
 
Originally Posted By: Rand
Oh and explain to me how the average no-tech user can watch his netflix and amazon prime on ubuntu.. .. I'm actually serious.

That's the fault of Netflix and Amazon. I have no problem watching WEC streaming on my Linux box. If that works without an issue, then the only reason Netflix and Amazon Prime have problems is because those companies choose to make things difficult.
 
Originally Posted By: Garak
Originally Posted By: Rand
Oh and explain to me how the average no-tech user can watch his netflix and amazon prime on ubuntu.. .. I'm actually serious.

That's the fault of Netflix and Amazon. I have no problem watching WEC streaming on my Linux box. If that works without an issue, then the only reason Netflix and Amazon Prime have problems is because those companies choose to make things difficult.


Ehh not sure I'd be so fast to condem Netflix or Amazon for having to support DRM.
 
Originally Posted By: Rand
Oh and explain to me how the average no-tech user can watch his netflix and amazon prime on ubuntu.. .. I'm actually serious.


For-profit, closed-source folks have made that one a tough one; but it can be done, even by non-techies. A quick Google search revealed several options ranging from the installation of a reverse-engineered Silverlight substitute to a PPA where someone contributed an application that works under WINE.

The short story is that it is about as easy as installing a piece of software, which is infinitely easier in Ubuntu than in Windows; and which must be done in Windows anyhow to use these services.

The downside, as usual, is that there is no official support from the closed-source, for-profit software makers for unofficial, reverse-engineered free software. They hate freedom as freedom is difficult to exploit for profit.
 
Status
Not open for further replies.
Back
Top Bottom