Internet Explorer is no stranger to
security vulnerabilities, but a flaw
revealed by Microsoft on Wednesday is one of the most stunning we've ever seen. The flaw affects IE6, IE7, and IE8 on
Windows XP as well as IE7 and IE8 on Vista and Windows 7 if protected mode has been disabled (though protected mode is turned on by default).
The exploit would allow a hacker to access any file on your system by forcing IE to incorrectly render data from local files, exposing it to outside parties. The flaw, which is actually several smaller security holes combined in an ingenious way, would require tricking a victim into visiting a
Web site through e-mail or IM, and then the attacker know the location and name of the file they'd wish to access. Unfortunately, many programs store sensitive data using a standardized structure that would be easy to find though guesswork.
What's your primary browser?| Internet Explorer | 7777 (42.2%) |
|---|
| Firefox | 6864 (37.3%) |
|---|
| Google Chrome | 1454 (7.9%) |
|---|
| Safari | 1271 (6.9%) |
|---|
| Other | 694 (3.8%) |
|---|
| I'm not sure | 365 (2.0%) |
|---|
If you're running Vista or Windows 7, ensure that you're running IE in protected mode, or even better -- choose a different browser. If you're still running XP and can't bring yourself to use
Firefox or
Chrome, you can lock down IE by setting the Internet and Local security zones to "High" or disabling ActiveX completely. You could also enable IE Network Protocol Lockdown, which requires editing the registry. Thankfully, Microsoft has created a "Fix it for me" link,
available here, that does the dirty work for you. [From:
Microsoft, via:
Ars Technica]
http://xml.channel.aol.com/xmlpublisher/fetch.v2.xml?option=expand_relative_urls&dataUrlNodes=uiConfig,feedConfig,entry&id=614153&pid=614152&uts=1265643760
http://cdn.channel.aol.com/cs_feed_v1_6/csfeedwrapper.swf
Search Words to Watch Out For
Always Turn Off Stolen GPS Units
It was only a matter of time before some numbskull criminal stole a GPS-equipped car or phone, but we didn't expect someone to steal live GPS units. A group of crooks in Lindenhurst, NY swiped 14 functioning GPS devices from the Town of Babylon Public Works. Understandably, authorities had no trouble tracking them down.
Security Cam Catches Tattooed Thief
We're not going to pass judgement on the type of tattoo you get, but you might want to think about what it says before you start getting into crime. Aaron Evans, a 21-year-old U.K. repeat offender, was caught stealing a car's GPS unit because the nearby CCTV captured the tattoo on his neck. It revealed his birthday and name...
Laptop Auto-Uploads Photo of Thief to the Web
This guy may be the unluckiest thief ever. Several laptops disappeared from a Vancouver, BC company; fortunately, one particular laptop was loaded with software that snapped photos when opened. The images of this guy were uploaded to Flickr. As a result, the man became a mini-Internet sensation, and he turned himself in, claiming he bought the laptop from a friend, at a local police station.
Things Not to Do After Stealing a Cell Phone
Gary Walker, an Ohio resident, stole a woman's phone while she had temporarily stepped out of her car to check a street sign. He proceeded to snap a shot of himself with the hot phone's camera. Later, when the victim went online and downloaded her data to transfer it to a new phone, Gary's mug popped up. The rest, as they say, is history.
HighTube
This 25-year-old Brit cultivator of cannabis decided to post videos -- under his real name -- of his cash crop on YouTube. English police saw the clips and he was soon tracked down and arrested.
Girl Recovers Stolen Mac By Remotely Activating Its Webcam
A White Plains, New York girl was the victim of burglary; over $5,000 worth of electronics, including iPods, a flatscreen TV, and a new Macintosh computer were stolen. A few days later, a friend noticed that the burglary victim appeared to be online, but called her to make sure. Because the stolen Mac was running Back to My Mac, the victim was able to log into the computer remotely and snap a picture of the thief. Turns out the thieves were "friends" who had visited the victim's apartment several weeks earlier.
Teen Arrested After Bragging About Arson on Security Cameras
A pregnant Los Angeles teen was arrested earlier after allegedly starting seven fires near her home. 19-year-old Amanda Gessner was caught after convenience store cameras caught her chanting, "The fire company is gonna be
mad at me!" She was certainly right about that!
Would-Be Voyeur Puts Spy Cam in Restroom, Leaves Video of Himself
An upstate New York man installed a camera in a unisex bathroom. The camera was discovered soon after installation, and police found he'd left a video of himself on the camera. Police are still looking for the man.
Forklift Tricks on YouTube
If you're going to show off your sweet forklift driving skills to your buddies, it's probably best to just do it in person. 20-year-old Australian Matthew Garry Ward uploaded a video of safety-violating forklift tricks to YouTube, and was reported to authorities after a coworker passed the video along to the boss.
Laser Pointer Shenanigans
Remember those time-sucking high school pep rallies where some loser would whip out a laser pointer and temporarily blind people in the bleachers? This 15-year-old genius from California, was arrested after shining his laser beam at a police helicopter.
Tags: ie, ie6, ie7, ie8, internet explorer, InternetExplorer, Microsoft, safety, security, top, Windows Mobile, WindowsMobile
Comments
22
Subscribe to commentsRossFeb 5th 2010 11:57PM
Those "Fix it for me" links are genius! One of the more clever things MS has done in a while :p
ChrisFeb 7th 2010 8:10PM
One word... FIREFOX
badguysnightmareFeb 8th 2010 11:38AM
Another word....APPLE
Cwwms2Feb 7th 2010 8:39PM
You think MS would either get thier act together or somebody else would get a majority of the browser share...
ramrod2Feb 7th 2010 8:52PM
GET A MAC!
hello ascaFeb 7th 2010 9:34PM
Microsoft needs to higher hackers to try and break through their products in every possible way before the release them then do the same with any updates they issue
DavisFeb 7th 2010 10:58PM
It should read, "The flaw Affects..." not "effects." Please proofread.
samFeb 8th 2010 12:04AM
oh looky, another english professor. scanning blogs. must be a slow weekend at home.
Former sailorFeb 8th 2010 9:16AM
Must be the flaw affects spellcheck.
Oh, looky, Sam is out playing, and very defensive because he has no idea what you're talking about. Go play with the other kids, Sam!
Thomas HoustonFeb 8th 2010 1:43PM
Thanks, Davis. Updated!
JuliFeb 7th 2010 11:11PM
the "updates'' that you receive , means more "updated " advertizing
yahoo032Feb 7th 2010 11:19PM
Just try google chrome once, it will blow you away
slink583Feb 7th 2010 11:37PM
DO NOT GET A MAC!!!!!!!!!!
seeandknowallFeb 8th 2010 10:13AM
Corect (sic) grammer (sic) and speling (sic), who cares, content and ideas trump at every turn. The entire idea of the internet and blogs are to convey ideas hence nomenclature such as, UR (your, you are and/or you're), IMHO (in my honest opinion), LOL (laugh out loud), etc... If you can't figure it out you're too slow to use it - stick with grammatically correct and spell checked, albeit slow and outdated, print.
BillFeb 8th 2010 11:59AM
I think we all get the content and ideas thing, but some of us still value the ability to express oneself competently. If you can't figure that out then you perhaps you should not read those posts.
sevnwolvesFeb 8th 2010 11:15AM
Yeah, get a Mac - then grab your lemming costume, put on your most smug expression, and pretend you have a computer that doesn't actually crash more than a pc.
mendaFeb 8th 2010 11:25AM
Ahh yes, just another loop hole for the scum of the world. Not to mention that a ton of people are going to jail right now for inadvertingly DL'dn child p*rn through Limewire and now "Frost". I'm wonderting if some of these "flaws" helped in that. In fact, I am pretty sure they have assisted in that! Besides, Limewire or google, some other search engines, and peer to peer file sharing program likes to install itself permantely onto your computer and RUN in the background without your knowledge. Then, next thing you know the feds are at your door and you've DL'd a bunch of stuff you didn't even know about. But, that doesn't matter, your done. They got you and the scarlet letter last a lifetime. I thinks it's pathetic that this kind of thing is happening and no one has a "responsibilty" to the guy who locked up for more years then an actual child m*lester or a violent offender. Sickening! Fix this stuff or face the consequences. People shouldn't be totally held responsible on their own when they THINK they have security on the comps.
GaryFeb 8th 2010 2:01PM
I have been enlightened about these so called "free music download" sites like Limewire and Frostwire. After I recieved a warning from my IP about possible violation of agreement and a complaint from a watchdog group that monitors music and movie downloads, I quickly removed those programs from my computer and forbade my teens from doing this anymore. These sites DON'T supply the music but only allows you to get music from someone else. I believe these sites are complicit and should be held accountable.
I'm just sayin'.
MrDoughnutFeb 8th 2010 12:42PM
On one hand the programmers and other IT people if you can call them that are foreign nationals. Most US programmers have been displaced by these ragga muffins who like to sell your info on the side or just snoop into your private stuff.
Whose to say some of these ragga muffins aren't delving into sick perverted and illegal adventures on your dime leaving the data that can be traced only to you as the fall guy or stooge.
On the other hand the American deviates are a small part of the problem with mostly foreign nationals actually out numbering them!
jebFeb 8th 2010 2:11PM
Anyone still using a PC & IE deserve all the trouble they get!!!! Fork over a couple hundred more dollars & get a MAC!!!! I did 5 years ago and will NEVER have a PC again!!! My peace of mind was worth the extra investment up front!!!