Free Republic
Browse · Search
News/Activism
Topics · Post Article

New Exploit Rocks IE, Downloads Scores Of Spyware, Adware (9/19/2006)
http://www.freerepublic.com/focus/f-news/1704561/posts

(excerpt

The new exploit seems to have a connection to WebAttacker, an multi-exploit attack "kit" created by a Russian group that sells for as little as $15 to $20. ,b>"We think that this new exploit is inside a new [version of the] kit," said Sites. "If that's true, then it will end up all over the place."

Sites said he expects that the exploit will migrate to one of the so-called "iframe cash" sites -- the term comes from the iframecash.biz site -- which use affiliates to push unpatched exploits to a large number of other Web sites, some of which are legitimate addresses whose servers have been previously compromised.

"This could end up being in lots and lots of places," said Sites.

________________________________________________________________

If it does spread to legitimate addresses that have vulnerable servers, then waiting until October 10 for a patch for IE could be very risky.

1 posted on 09/20/2006 12:41:52 PM PDT by Eagle9
[ Post Reply | Private Reply | View Replies ]


To: Eagle9
Use another browser:

That is some good advice there. :)
2 posted on 09/20/2006 12:43:33 PM PDT by P-40 (Al Qaeda was working in Iraq. They were just undocumented.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

USE FIREFOX!!!!!!!!!!!!!!!.........


3 posted on 09/20/2006 12:47:31 PM PDT by Red Badger (Is Castro dead yet?........)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

Thanks for posting...


5 posted on 09/20/2006 12:50:03 PM PDT by Fury
[ Post Reply | Private Reply | To 1 | View Replies ]

To: OrangeDaisy; KayEyeDoubleDee; DollyCali
"One of the easiest ways might be to use Firefox with a plug-in to allow certain sites (such as windowsupdate.com) to transparently use MSIE to get back the ActiveX functionality without bothering the user over the choice and differences," said the Internet Storm Center in an online alert Wednesday.

Two such plug-ins (called "extensions" in Firefox parlance) that add IE functionality to Firefox are IE Tab and IE View.

If Microsoft Windows Update web site will accept Firefox with either of those two extensions, then banking and MS Exchange/Outlook Web Mail and other IE only web sites should also accept it.

6 posted on 09/20/2006 12:51:01 PM PDT by Eagle9
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

bttt


7 posted on 09/20/2006 12:52:07 PM PDT by firewalk
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9; All
Why are Mac's not affected by virus's? Is this in fact true? I am considering getting one for work and I would like your comments.

Thanks!

10 posted on 09/20/2006 1:23:34 PM PDT by HOYA97 (Hoya Saxa = What Rocks)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

Thanks for posting this. I've followed the instructions for creating the GPO and have applied it to our test network for testing.


12 posted on 09/20/2006 1:40:27 PM PDT by FReepaholic (This tagline could indicate global warming.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

Summary of all MS threads:

Blah, blah, blah, Firefox. Blah, blah, blah, MS sucks. Blah, blah, blah Mac. Blah, blah, blah why people still use is beyond me. Blah, blah, blah Linux.


15 posted on 09/20/2006 1:47:52 PM PDT by VeniVidiVici (Rabid ethnicist.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

Server 2003 is not vulnerable. PCs having a decent virus scanner or anti-spyware program are not vulnerable. I'm betting that 64 bit cpus are not vulnerable.


16 posted on 09/20/2006 1:48:48 PM PDT by js1138 (The absolute seriousness of someone who is terminally deluded.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

I use Swiftfox, a variant of Firefox for Linux. No problems here.

Regards, Ivan


22 posted on 09/20/2006 2:14:27 PM PDT by MadIvan (I aim to misbehave.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

How do you clean it out if you already have it?


31 posted on 09/20/2006 9:08:28 PM PDT by Toby06 (Hydrogen is not a fuel source. Hydrogen is an energy storage method, like a battery.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

I've been using IE7 since it was in Beta. Works great for me.


32 posted on 09/20/2006 9:09:06 PM PDT by COEXERJ145 (Free Republic is Currently Suffering a Pandemic of “Bush Derangement Syndrome.”)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9
Users who want to protect themselves now, however, do have options.

Yes they do


46 posted on 09/21/2006 8:16:39 PM PDT by montag813
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

bump


49 posted on 09/21/2006 9:09:47 PM PDT by Darnright (http://media.putfile.com/Webb-on-Allen)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

A couple of questions:

1) Re "Disable the vulnerable .dll":
What is that .dll used for, and what will be affected if it's disabled?


2) Re disabling Binary and Script Behaviors in IE6 and the following instructions:
(-- Select Tools|Internet Options in IE
-- Click the "Security" tab
-- Click "Internet," then "Custom Level"
-- In the "ActiveX controls and plug-ins" section, under "Binary and Script Behaviors," click "Disable," and then click OK.)

I don't have anything specifically called "Binary and Script Behaviors" under "Active X Controls and Plug-Ins". All I have are:
Download Signed ActiveX Controls (I already have set as Disabled)
Download Unsigned ActiveX Controls (Disabled)
Initialize and Script ActiveX Controls Not Marked as Safe (Disabled)
Run ActiveX Controls and Plug-Ins (Disabled)
Script ActiveX Controls Marked Safe for Scripting (Disabled)

Am I okay there?

Thanks for your help!


50 posted on 09/21/2006 9:25:42 PM PDT by BlessedBeGod (Benedict XVI = Terminator IV)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9

ping for later.


54 posted on 09/22/2006 4:27:41 PM PDT by JerseyHighlander
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Eagle9
Image and video hosting by TinyPic
56 posted on 09/22/2006 8:42:15 PM PDT by Wormwood (Everybody lies, but it doesn't matter because nobody listens.)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson