Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 17th, 2012, 08:34 PM
Thankful Thankful is offline
Very Frequent Poster
 
Join Date: Feb 2005
Location: New York City
Posts: 2,407
Default Microsoft urges customers to install security tool

Quote:
Some security experts said computer users should avoid Internet Explorer, even if they install the EMET security tool available from Microsoft
.
http://www.nbcnews.com/technology/te...tool-1B5948322
  #2  
Old September 17th, 2012, 11:59 PM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,134
Post Re: Microsoft urges customers to install security tool

Attackers exploit unpatched Internet Explorer vulnerability
Quote:
According to a Blog post by security specialist Eric Romang, a security hole in Microsoft's Internet Explorer web browser is being used by cyber criminals to infect computers with malware. The vulnerability, which was apparently unknown and unpatched until now, seems to hinge on how IE handles <img> arrays in HTML files. So far, the attackers have only targeted versions 7 and 8 of IE on fully patched Windows XP SP3 systems; it is not yet certain whether the exploit can be used with other software combinations.
H-Online article, Ars Article

Last edited by siljaline : September 18th, 2012 at 12:34 AM.
  #3  
Old September 18th, 2012, 12:49 AM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,134
Post Re: Microsoft urges customers to install security tool

Microsoft Security Advisory (2757760)
Vulnerability in Internet Explorer Could Allow Remote Code Execution
Quote:
Microsoft is investigating public reports of a vulnerability in Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, and Internet Explorer 9. Internet Explorer 10 is not affected. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability.

A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has been deleted or has not been properly allocated. The vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer. An attacker could host a specially crafted website that is designed to exploit this vulnerability through Internet Explorer and then convince a user to view the website.

On completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through our monthly security update release process, or an out-of-cycle security update, depending on customer needs.
Advisory: http://technet.microsoft.com/en-us/s...visory/2757760
  #4  
Old September 18th, 2012, 12:59 AM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,849
Lightbulb Re: Microsoft urges customers to install security tool

@ Thankful

Thanks for the info

From one of siljaline links

Quote:
In the current attack, a specially prepared web page executes a Flash applet that uses heap spraying to distribute shellcode in the system memory. It then reloads an iframe that uses the IE vulnerability to run the shellcode. According to an analysis from security firm Alien Vault, the remote administration tool (RAT) Poison Ivy is currently being distributed in this way in order to give the attackers complete access to the infected system.

http://www.h-online.com/security/new...y-1709592.html

How to protect = Simple

Set Flash to Disable or Prompt.

Disable or Prompt iframes.

Even without the above settings, Poison Ivy etc won't Install/Run if you have for eg an AntiExe etc in place.

Why don't writers of such articles inform people about such Easily preventative measures ? Which have available for Years, even as far back as 98SE days

From the PoisonIvy PDF "Helpfile"

Quote:
The plugins (as well as the server and key logger file) are stored encrypted in ADS (Alternative Data Stream) on NTFS partitions (they are stored normally on FAT32)

A good reason for not having ADS I've always chosen to have FAT32, so no ADS here
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #5  
Old September 18th, 2012, 01:16 AM
wat0114's Avatar
wat0114 wat0114 is offline
Frequent Poster
 
Join Date: Aug 2012
Location: Canada
Posts: 729
Default Re: Microsoft urges customers to install security tool

Quote:
Originally Posted by CloneRanger
Why don't writers of such articles inform people about such Easily preventative measures ? Which have available for Years, even as far back as 98SE days

Because doing so would hurt antivirus sales
__________________
Win 7x64 Ultimate

SUA | UAC @ Max | AppLocker w/DLL enforcement | Win fw w/advanced security| EMET 3.5 | Firefox w/NS +AdBlock+ plugins | GPO restrictions | Bitlocker and Truecrypt | ShadowProtect images | IFW data backups + dual boot to XP Pro: GPO, SRP, Jetico firewall w/Process Attack filter
  #6  
Old September 18th, 2012, 02:00 AM
Cutting_Edgetech's Avatar
Cutting_Edgetech Cutting_Edgetech is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: USA
Posts: 1,727
Default Re: Microsoft urges customers to install security tool

I don't use IE, but I would be willing to bet it will never get past Appguard.
__________________
Netgear Prosecure UTM25 | Online Armor | NOD 32 | Appguard | VoodooShield | Shadow Defender 1.1.0.325
  #7  
Old September 18th, 2012, 02:00 AM
moontan's Avatar
moontan moontan is online now
Massive Poster
 
Join Date: Sep 2010
Location: Québec
Posts: 3,116
Default Re: Microsoft urges customers to install security tool

Quote:
On completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through our monthly security update release process, or an out-of-cycle security update, depending on customer needs.

maybe they should offer a link to Google Chrome instead.
__________________
| Linux Mint || NoScript || Image for Linux + BootIt Bare Metal |
  #8  
Old September 18th, 2012, 06:27 AM
The Hammer's Avatar
The Hammer The Hammer is online now
Massive Poster
 
Join Date: May 2005
Location: Toronto Canada
Posts: 5,090
Default Re: Microsoft urges customers to install security tool

There should be an update within a week according to a Toronto Sun article. http://www.torontosun.com/2012/09/18...-security-flaw
__________________
Desktop -Win 7 Home Premium 64 bit, NAT Router Firewall, Windows Firewall, Avira Antivirus Premium V13, MBAM PRO 1.75 , WOT, Win 7's System imaging. Netbook-Avira Antivirus Premium V13 , MBAM PRO 1.75, WOT.
  #9  
Old September 18th, 2012, 01:32 PM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,611
Default Re: Microsoft urges customers to install security tool

The one security tool every Windows user should know about?

http://www.zdnet.com/blog/bott/the-o...now-about/2848

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.147 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #10  
Old September 18th, 2012, 01:45 PM
moontan's Avatar
moontan moontan is online now
Massive Poster
 
Join Date: Sep 2010
Location: Québec
Posts: 3,116
Default Re: Microsoft urges customers to install security tool

Quote:
Originally Posted by Triple Helix
The one security tool every Windows user should know about?

http://www.zdnet.com/blog/bott/the-o...now-about/2848

TH

from the first post:
Quote:
Some security experts said computer users should avoid Internet Explorer, even if they install the EMET security tool available from Microsoft
__________________
| Linux Mint || NoScript || Image for Linux + BootIt Bare Metal |
  #11  
Old September 18th, 2012, 02:04 PM
Trooper's Avatar
Trooper Trooper is offline
Very Frequent Poster
 
Join Date: Jan 2005
Posts: 2,538
Default Re: Microsoft urges customers to install security tool

Quote:
Originally Posted by The Hammer
There should be an update within a week according to a Toronto Sun article. http://www.torontosun.com/2012/09/18...-security-flaw

Thanks for the info man.
__________________
This space for rent.
  #12  
Old September 18th, 2012, 02:08 PM
Aventador's Avatar
Aventador Aventador is offline
Frequent Poster
 
Join Date: Sep 2012
Posts: 420
Default Re: Microsoft urges customers to install security tool

Quote:
Originally Posted by moontan
maybe they should offer a link to Google Chrome instead.


Best reply Yet. Kudos.
__________________
"Don't Fear Malware......Be Prepared for it!"
  #13  
Old September 18th, 2012, 06:25 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,201
Default Re: Microsoft urges customers to install security tool

Quote:
MSRC
Additional information about Internet Explorer and Security Advisory 2757760
32 minutes ago
by MSRCTeam

We will release a Fix it in the next few days to address an issue in Internet Explorer, as outlined in the Security Advisory 2757760 that we released yesterday.
https://blogs.technet.com/b/msrc/?Redirected=true
  #14  
Old September 18th, 2012, 08:10 PM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: Microsoft urges customers to install security tool

Quote:
Originally Posted by Cutting_Edgetech
I don't use IE, but I would be willing to bet it will never get past Appguard.
I am willing to bet your wright.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
  #15  
Old September 18th, 2012, 08:12 PM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: Microsoft urges customers to install security tool

Comodo Dragon.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
  #16  
Old September 18th, 2012, 09:40 PM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,134
Post Re: Microsoft urges customers to install security tool

As per Ron's post, we should see a fix likely on Windows Update within the next few days. Watch this space for more information as it becomes available.
  #17  
Old September 19th, 2012, 12:00 PM
Thankful Thankful is offline
Very Frequent Poster
 
Join Date: Feb 2005
Location: New York City
Posts: 2,407
Default Re: Microsoft urges customers to install security tool

Quote:
The company said it planned to release software to protect PCs from attack within the next few days. Customers must manually install the code by visiting Microsoft's website and clicking on a link.

Microsoft did not say how long it will take to release a full update to Internet Explorer, which will automatically be loaded onto the machines of most customers. Several security researchers have said they expect the update within a week.
http://www.nbcnews.com/technology/te...orer-1B5950439
  #18  
Old September 19th, 2012, 06:40 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,201
Default Re: Microsoft urges customers to install security tool

Fix it located here. http://support.microsoft.com/kb/2757760

Also, see this. http://www.wilderssecurity.com/showthread.php?t=332574
  #19  
Old September 19th, 2012, 09:02 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,201
Default Re: Microsoft urges customers to install security tool

Quote:
More information on Security Advisory 2757760's Fix It

Today, we revised Security Advisory 2757760 with two new pieces of information:

A Fix It solution is available to address the vulnerability via an app-compat shim
The comprehensive security update will be released out-of-band on Friday.

In this blog post, we’d like to explain more about the vulnerability and explain how the Fix It solution addresses the issue. We will also provide more details about the attack landscape and provide our assessment of the effectiveness of EMET against current attacks.
https://blogs.technet.com/b/srd/arch...edirected=true
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:01 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums