PDA

View Full Version : Microsoft Explora Security Issue


Creature
03-07-2004, 07:04 PM
Heres one BIll GAtes dosnt want the masses to know

"Security experts are advising users stay away from IE until at least Microsoft patches yet another major security flaw.

A major security hole discovered in Microsoft's Internet Explorer last week has become a golden marketing opportunity for alternative browsers such as Mozilla and Opera that are unaffected by the flaw.

To avoid falling prey to a concerted attack aiming to steal log-on information and passwords, some security experts advised Web surfers to either turn off some Internet Explorer (IE) features or switch to another browser as the best immediate fix. Unknown attackers who had taken control of several Web servers used the flaw last week to install a remote-access program, dubbed JS.Scob.Trojan, onto the PCs of visitors to those sites.

"I hope that Microsoft will come up with a patch soon," said Johannes Ullrich, chief technology officer for the Internet Storm Center, a site that monitors network threats. "Until they do, you basically have two choices: Disable JavaScript in Internet Explorer or install another browser."

I have downloaded Firefox and have now deleted the explora icons from my pc. Another bonus is faster loading of web pages & very imortantly its free :)

http://mozilla.org/products/firefox/

Friar Tuck
04-07-2004, 06:31 AM
Great! Can I fit it to me new project bike? And where does it go exactly?

Jonnyfp
04-07-2004, 08:06 AM
Firefox installed now i will let you know how i get on.

btw the new edition of zone alarm is nice and fussy.

Creature
04-07-2004, 08:10 AM
only thing ive not been able to sort out so far is the microsoft update.

if ya didna reboot after installing - then do so

have just installed firebird - there outlook (express) package, will keep ya updated

Jonnyfp
04-07-2004, 08:47 AM
only thing ive not been able to sort out so far is the microsoft update.

if ya didna reboot after installing - then do so

have just installed firebird - there outlook (express) package, will keep ya updated

So far so good, i completely uninstalled microsoft ex just a few settings differences but everything was imported so i will keep you posted from my point of view.

MrFluffy
04-07-2004, 10:59 AM
Just for more information...

This issue isnt resolved by keeping your computer up to date with up2date, since microsoft havent been able to resolve the bug. This is why cert (a very respected independant security body) are recommending you switch FROM IE to anything else availible. Also IE has had a spate of 0day exploits which m$ been really slow about sorting out, the worst of which was the browser helper object exploit that installs itself in, then captures any form data entered into a https page and sends it off. For the unwary, this is likely to be your bank details, credit card on a online payment and other things that are sensitive in nature. You can get infected just by visiting a site with it. Theres not even a way to check if a machine is infected with it without downloading a 3rd party program (BHO demon).

IE is the typhoid mary of browsers, to go with their typhoid mary email client outlook. Most of the spam in the world is caused by hacked windows machines compromised by one of the various routes in not limited to ie and outlook acting as spam zombies.

You can put your blind faith in IE and hope, or you could try firefox, all the buttons are in the same place, it behaves in more or less the same way (except in some ways its better, tabbed browsing etc) but it doesnt have the "features" that cause all the problems and when it does theyre fixed , fast. Oh and its free too, in fact you can download the sourcecode for it, even fix it if you want and submit the fix back, add to it, change it etc. Of course you dont have to do any of these things, since its now so polished you can just install and run it without knowing whats under the bonnet or any of the ethos behind its development.
Firefox also isnt wrote by some big company, its actually wrote by lots of people around the world who dont know each other and dont get paid, just ones that had a desire for feature x or y and so wrote it in and sent back their work for everyone else to benefit from. Not one person owns it, nor can they start charging for it and take all the source away.
I got my wife to switch over a couple of weeks back, and she was so enthused she went round her parents house converting them too.

I use mozilla exclusively (linux version of firefox), but there again, I dont use windows ever except when Im absolutely forced to by corporate policy...
I do this security thing for a living you know ;)