internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
McAfee Total Protection

Most Popular Software Downloads
Mozilla Firefox
Microsoft Office 2010
QuickTime for Windows
Adobe Reader
Mozilla Thunderbird
Winamp
Microsoft Office 2007 Service Pack
Google Earth
Adobe Flash Player
Windows Vista Service Pack 2 (Vista SP2)
CCleaner (Crap Cleaner)

Most Popular Software Articles
Windows Vista Tips: Home Networking Setup Tutorial
10 Must-Have Apps: The Free Windows Networking Toolkit
How to Make Your Internet Connection Faster, Better


Software Reviews

US Gov: Beware of IE
Agency Warns Surfers to Stop Using IE
Ryan Naraine

The U.S. government's Computer Emergency Readiness Team (US-CERT) is warning web surfers to stop using Microsoft's Internet Explorer (IE) browser.

On the heels of last week's sophisticated malware attack that targeted a known IE flaw, US-CERT updated an earlier advisory to recommend the use of alternative browsers because of "significant vulnerabilities" in technologies embedded in IE.

"There are a number of significant vulnerabilities in technologies relating to the IE domain/zone security model, the DHTML object model, MIME-type determination, and ActiveX. It is possible to reduce exposure to these vulnerabilities by using a different web browser, especially when browsing untrusted sites," US-CERT noted in a vulnerability note.

The latest US-CERT position comes at a crucial time for Microsoft, which has invested heavily to add secure browsing technologies in the coming Windows XP Service Pack 2. The software giant has spent the last few months talking up the coming IE security improvements, but the slow response to patching well-known – and sometimes "critical" – browser holes isn't sitting well with security experts.

On discussion lists and message boards, security researchers have spent a lot of time beating the "Dump IE" drum, and the US-CERT notice is sure to lend credibility to the movement away from the world's most popular browser.

US-CERT is a non-profit partnership between the Department of Homeland Security (DHS) and the public and private sectors. It was established in September 2003 to improve computer security preparedness and response to cyber attacks in the United States.

It has been more than two weeks since Microsoft confirmed the existence on an "extremely critical" IE bug, which was being used to load adware/spyware and malware on PCs without user intervention, but even though the company hinted it would go outside its monthly security update cycle to issue a fix, the flaw remains unpatched.

US-CERT researchers say the IE browser does not adequately validate the security context of a frame that has been redirected by a web server. It opens the door for an attacker to exploit the flaw by executing script in different security domains.

"By causing script to be evaluated in the Local Machine Zone, the attacker could execute arbitrary code with the privileges of the user running IE," according to the advisory.

"Functional exploit code is publicly available, and there are reports of incidents involving this vulnerability."

To protect against the flaw, IE users are urged to disable Active scripting and ActiveX controls in the Internet Zone (or any zone used by an attacker). Other temporary workarounds include the application of the Outlook e-mail security update, the use of plain-text e-mails, and the use of anti-virus software.

US-CERT also advises that surfers must get into the habit of not clicking on unsolicited URLs from e-mail, instant messages, web forums, or internet relay chat (IRC) sessions.

News courtesy of internetnews.com

June 29, 2004

Download Windows XP SP2 RC2 Now!Download

Download Mozilla Firefox Now!Download

Download Opera Now!Download

View All Web Browsers

Contents:
1. Agency Warns Surfers to Stop Using IE


Additional Articles:

  • Malware Hacker Attack Linked to Spammers
  • Malware Attack Thwarted, But Danger Lurks
  • Microsoft Issues Security Update for Trojan
  • Another IE Flaw in the Wild?
  • Microsoft Faces Angry IE Users' Questions
  • Microsoft Releases New Tool to Zap Download.Ject
  • Microsoft: Out-of-Cycle Security Patch Coming
  • 'Critical' IE Patch Released
  • MS Patch Barrage Comes with IE Fix
  • 'Drag-and-Drop' IE Flaw Persists
  • MS Patches IFRAME Vulnerability Out of Cycle
  • Microsoft Patches Three Holes, Offers Removal Tool
  • Microsoft Patch Day Plugs 3
  • Microsoft Patches 3 Critical Flaws
  • IE Workarounds for New Zero Day Exploit
  • Unpatched IE Flaw Now Exploitable
  • Microsoft Going Critical on Tuesday
  • Microsoft Crafts Critical Patches
  • Microsoft Warns on Windows, IE Flaws
  • Microsoft Patches IE, Windows, Office
  • Microsoft's Patch of a Patch Will Be Late
  • Latest IE Zero Day Has XML Designs
  • IE Vulnerability Spreads to Email
  • IE VML Exploit Growing in Severity
  • VML Exploit Patched, Questions Remain
  • PowerPoint, IE Hit by New Zero-Day Flaws



  • The Network for Technology Professionals

    Search:

    About Internet.com

    Legal Notices, Licensing, Permissions, Privacy Policy.
    Advertise | Newsletters | E-mail Offers