Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 15th, 2008, 09:08 AM
HURST's Avatar
HURST HURST is offline
Very Frequent Poster
 
Join Date: Jul 2007
Posts: 1,420
Default Microsoft sees 'huge increase' in IE attacks

Quote:
Microsoft Corp. warned Saturday of a "huge increase" in attacks exploiting a critical unpatched vulnerability in Internet Explorer (IE) and said some originated from hacked pornography sites.

Other researchers confirmed that attacks were increasingly coming from compromised Web sites.

Microsoft noted the upswing in attacks on its Malware Protection Center blog late Saturday. "The trend for now is going upwards," said researchers Ziv Mador and Tareq Saade on the blog. "We saw a huge increase in the number of reports today compared to yesterday."

Hackers have been exploiting a data binding bug in IE for more than a week, according to researchers who first noted in-the-wild attack code on Chinese servers. The vulnerability, which exists in all versions of the Microsoft browser, including IE5.01, IE6, IE7 and IE8 Beta 2, has so far been exploited only by attack code that targets IE7, the most widely-used edition.



Quote:
Microsoft acknowledged that attacks have become a significant problem. "Based on our stats, since the vulnerability has gone public, roughly 0.2% of users worldwide may have been exposed to Web sites containing exploits of this latest vulnerability," Mador and Saade said. "That percentage may seem low. However, it still means that a significant number of users have been affected."

http://www.computerworld.com/action/...icleId=9123398
__________________
I SandboxIE
  #2  
Old December 15th, 2008, 11:32 AM
Rmus Rmus is offline
Exploit Analyst
 
Join Date: Mar 2005
Posts: 3,624
Default Re: Microsoft sees 'huge increase' in IE attacks

Microsoft has elaborated on the various work-around measures for this exploit until a patch is released:

Clarification on the various workarounds from the recent IE advisory
http://blogs.technet.com/swi/archive...-advisory.aspx

From the computerworld article you cited (thanks!),

Quote:
The vulnerability, which exists in all versions of the Microsoft browser, including IE5.01, IE6, IE7 and IE8 Beta 2, has so far been exploited only by attack code that targets IE7, the most widely-used edition.
This explains why using IE6, the exploit would not run on sites that I looked at. The code checks for the versions of IE and the Operating system.

Note, however, that the IE7 exploit has been seen packaged with other exploits that affect IE6, so that an unpatched IE6 would be vulnerable should one encounter a compromised website.

One of Microsoft's recommendations is to Enable DEP (data execution prevention). Another consideration, because the payload is a trojan executable file,

Quote:
If executed successfully, the script will download the binary from ht tp: //www[...]/admin/win.exe.
those with Software Restriction Policies enabled will prevent the trojan from running.


OTHER REFERENCES

0-day exploit for Internet Explorer in the wild
http://isc.sans.org/diary.html?storyid=5458

IE7 0day expanded to include IE6 and IE8(beta)
http://binarycse.com/wordpress/?p=68


----
rich
  #3  
Old December 15th, 2008, 01:40 PM
Pedro's Avatar
Pedro Pedro is offline
Massive Poster
 
Join Date: Nov 2006
Posts: 3,492
Default Re: Microsoft sees 'huge increase' in IE attacks

Waiting for Patch Tuesday? ..
  #4  
Old December 15th, 2008, 03:11 PM
ghodgson ghodgson is offline
Frequent Poster
 
Join Date: Dec 2003
Location: UK
Posts: 334
Default Re: Microsoft sees 'huge increase' in IE attacks

Another very good reason to ditch IE and go with Firefox or Opera.
__________________
Gordon
  #5  
Old December 18th, 2008, 10:00 PM
Kerodo's Avatar
Kerodo Kerodo is offline
Massive Poster
 
Join Date: Oct 2004
Posts: 5,995
Default Re: Microsoft sees 'huge increase' in IE attacks

They're all the same... they all have vulnerabilities that keep surfacing, then they patch 'em and life goes on...
__________________
If it ain't broke, you haven't tweaked it enough....

Debian 7 x64
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:02 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums