IE security flaw!!

  • Thread starter Deleted member 4644
  • Start date

bersl2

Golden Member
Aug 2, 2004
1,617
0
0
From the ZDNet article:
Security researchers said the IE vulnerability has been known for the past six months, but had previously been seen as a conduit for denial-of-service attacks rather than the remote execution of code. DOS attacks, which attempt to crash a system by flooding it with data, are typically considered less-severe security risks.

"The vulnerability itself has been known about for a while, but it was only a problem for a denial-of-service attack that would sometimes cause IE to crash," said Johannes Ullrich, chief research officer for the Sans Institute. "Up until now, no one knew how to mark the code and find it in memory to execute a remote code attack...."

Because the flaw was initially believed to involve only a potential DOS attack, Microsoft never issued a patch for the problem, Ullrich said. He added it is not yet known whether Microsoft will spin out a patch for the flaw immediately or wait for its monthly patch cycle.

Ouch.
 

Hyperblaze

Lifer
May 31, 2001
10,027
1
81
Originally posted by: bersl2
From the ZDNet article:
Security researchers said the IE vulnerability has been known for the past six months, but had previously been seen as a conduit for denial-of-service attacks rather than the remote execution of code. DOS attacks, which attempt to crash a system by flooding it with data, are typically considered less-severe security risks.

"The vulnerability itself has been known about for a while, but it was only a problem for a denial-of-service attack that would sometimes cause IE to crash," said Johannes Ullrich, chief research officer for the Sans Institute. "Up until now, no one knew how to mark the code and find it in memory to execute a remote code attack...."

Because the flaw was initially believed to involve only a potential DOS attack, Microsoft never issued a patch for the problem, Ullrich said. He added it is not yet known whether Microsoft will spin out a patch for the flaw immediately or wait for its monthly patch cycle.

Ouch.

Suprised?
 

bersl2

Golden Member
Aug 2, 2004
1,617
0
0
Originally posted by: Hyperblaze
Originally posted by: bersl2
From the ZDNet article:
Security researchers said the IE vulnerability has been known for the past six months, but had previously been seen as a conduit for denial-of-service attacks rather than the remote execution of code. DOS attacks, which attempt to crash a system by flooding it with data, are typically considered less-severe security risks.

"The vulnerability itself has been known about for a while, but it was only a problem for a denial-of-service attack that would sometimes cause IE to crash," said Johannes Ullrich, chief research officer for the Sans Institute. "Up until now, no one knew how to mark the code and find it in memory to execute a remote code attack...."

Because the flaw was initially believed to involve only a potential DOS attack, Microsoft never issued a patch for the problem, Ullrich said. He added it is not yet known whether Microsoft will spin out a patch for the flaw immediately or wait for its monthly patch cycle.

Ouch.

Suprised?

No, just drawing attention to the fact of "same old same-old". :evil:
 

Newfie

Senior member
Jun 15, 2005
817
0
76
wow, IE has another security problem? damn the 2000 others fail in comparsion to this one
 

xtknight

Elite Member
Oct 15, 2004
12,974
0
71
Woohoo. Another reason to use Opera. Doesn't do a damn thing to Opera 9. Must mean it's more multi-threaded because it doesn't freeze at all either.

Tried to buffer-overrun IE and freezes Mozilla FireFox for a second and then displays big message boxes of Chinese-esque characters then just stops then CPU is at 0% again...

But none of the browsers open calc.exe for me. I also have DEP enabled for all applications.

Upon further observation, all it does is max out the memory for the FireFox.exe process. I'm disappointed. None of my browsers opened calc.exe. :laugh:
 

The Linuxator

Banned
Jun 13, 2005
3,121
1
0
Originally posted by: astrosfan90
I thought IE was one giant security flaw...people still use it?


Yes seriously, whoever knows about alternatives (i.e firefox, opera, Konqueror, Mozilla...etc) and still uses IE deserves all the viruses that the Cyber world has to offer, why because he / she is asking for it.
 

Rilex

Senior member
Sep 18, 2005
447
0
0
This is no worse than the Mozilla Foundation sitting on security issues for over 6 months, or Sendmail not releasing a patch for a known issue for over a decade.

It seems most major software companies/organizations end up falling into the above pattern.
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
Originally posted by: The Linuxator
Originally posted by: astrosfan90
I thought IE was one giant security flaw...people still use it?

Yes seriously, whoever knows about alternatives (i.e firefox, opera, Konqueror, Mozilla...etc) and still uses IE deserves all the viruses that the Cyber world has to offer, why because he / she is asking for it.

Actually as of late Firefox has had more security issues than IE (IMHO IE is thru alot of it's growing pains, while FF still has a way to go). So, such a general statement about users getting what they deserve is baseless.

Bill

 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |