View Full Version : Zero-Day IE Exploit Takes Control of PCs


Silent Bob
11-22-2005, 11:27 AM
Zero-Day IE Exploit Takes Control of PCs

Posted by CmdrTaco (http://cmdrtaco.net/) on Tuesday November 22, @09:51AM

anethema writes "A remote IE exploit with implementations is currently in the wild (http://www.eweek.com/article2/0,1759,1891749,00.asp?kc=EWRSS03119TX1K0000594). From the article: 'Exploit code for a critical flaw in fully patched versions of Microsoft Corp.'s Internet Explorer browser has been released on the Internet, putting millions of Web surfers at risk of computer hijack attacks.' Aparently all you have to do is browse the page to be affected. There is no patch, but since it is a javascript exploit, you can work around it by disabling javascript." Read More... (http://it.slashdot.org/it/05/11/22/1352212.shtml?tid=113&tid=128&tid=172&tid=218)



See, this is why I don't use IE unless I absolutely have to.

Andrew Green
11-22-2005, 12:01 PM
The group that published the exploit said Microsoft has been aware (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1790) of the Javascript Window() vulnerability for several months but was mistakenly treating it as a low-priority denial-of-service flaw.

Which begs the question, How many other serious vulnerabilities are known about by Microsoft and being ignored?

But at least the article give good advice right at the end:

The SANS ISC's Ullrich said IE users should consider switching to Firefox of Opera.

What needs to happen is a good old fashioned toast your hard drive virus to finally show users that this stuff is happening to them, instead of them wondering why their computer is "slow" as it sends out millions of Spam messages.

Shandril
11-22-2005, 12:32 PM
Yes switching to firefox is excellent advice :). It should be mentioned at the top of the article not the bottom. People might miss it at the bottom.

BlueDragon1981
11-22-2005, 03:30 PM
I like both opera and firefox....i regulary use firefox on my laptop...and opera on my desktop...reason is opera on my laptop has a weird glitch that doesn't allow me to log into forums....I removed it and removed it from the registry...deleted it from the recycle bin and restore points are disabled....but somehow when I reinstall it finds the same settings....weird huh...works fine on the desktop...

Anyway....getting people to switch to firefox and/or opera is one of my missions lately....also switching to thunderbird etc....