internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Adobe Flash Player

Most Popular Software Downloads
Windows Vista Service Pack 2 (Vista SP2)
Mozilla Firefox 3
QuickTime for Windows
Adobe Flash Player
Windows 7
Norton Internet Security 2010
Internet Explorer 8
CCleaner (Crap Cleaner)
Winamp
Skype

Most Popular Software Articles
Windows Vista Tips: Home Networking Setup Tutorial
10 Must-Have Apps: The Free Windows Networking Toolkit
How to Make Your Internet Connection Faster, Better


Software Reviews

Microsoft Patches IE, But Security Issues Remain
Browser Security: The Bad Guys Remain One Step Ahead
Richard Adhikari

Microsoft today released a patch for the latest Internet Explorer (IE) browser vulnerability that has been in the news since last week.

However, malware authors have already begun pushing out customized variants of the flaw that the Microsoft patch may not address.

The vulnerability, rooted in IE's XML parser, lets attackers execute code on their victims' PCs.

By Saturday, at least 6,000 Web sites had been infected and the number is growing, though ascertaining the exact number is difficult. However, security experts say things will get much worse, even if users follow Microsoft's advice to install the patch immediately.

Currently, attacks have only targeted Internet Explorer 7, Christopher Budd, security response communications lead at Microsoft, said in a statement. They have not been successful against systems where the patch has been applied, according to Budd.

Microsoft is hosting two Webcasts to address customer questions about the security bulletin. The first was set for 1 p.m. PDT today and 11 a.m. PDT tomorrow in the U.S. and Canada. The Webcast will be available on demand after that.

According to researcher Rahul Mohandas on the McAfee Avert Labs blog, malware authors have already begun issuing customized version of the IE exploit with various degrees of stealth.

Come Read This

One of the most prominent techniques is where the attacker sends victims a Microsoft Word document by e-mail that contains an embedded ActiveX control triggered when the document is opened. This exploit was listed as one of the SysAdmin, Audit, Network, Security (SANS) Institute's top 20 security risks in 2007.

Victims of the latest exploit are hit by drive-by injection attacks, where they go to a compromised Web site that automatically downloads malicious code onto their Web site.

Malware authors have come up with a new twist on this, Dave Marcus, security research and communications director at McAfee Labs, told InternetNews.com. They plant an IFrame onto a legitimate site and the IFrame redirects unsuspecting visitors to the site hosting the malicious code.

An IFrame is an HTML element that lets users embed an HTML document inside another HTML document. The CBS TV network site was hit by an IFrame attack on November 11 that saw visitors redirected to a server in Russia, according to security company Finjan's MCRC blog on November 27.

"We've seen an awful lot of sites that have been compromised with the IFrame on them," Marcus said. "It's a very Web 2.0 way of spreading malware."

Attacks on the browser are expected to increase, with the browser increasingly being considered an application platform, security experts say. Mozilla's Firefox, for example, was ranked as the most vulnerable application by whitelisting vendor Bit9, although Mozilla has since issued a set of ten patches to its Firefox browser.

Experts disagree on how to prevent attacks on browsers in the future.

Microsoft should strip down IE to only the features users need, Wolfgang Kandek, chief technology officer at Qualys, told InternetNews.com. "Why does that browser, which is tightly integrated into Windows, have a very powerful library when users only need a subset of those functionalities?" he asked. "When a library offers way too many features, that opens the door for exploits."

It's all about Web 2.0

But McAfee's Marcus said stripping down IE is not the answer. "Users expect rich dynamic content in this day and age — streaming audio and video — and the browser simply reflects what they're looking for," he said. "You can't stop car theft or bank robberies, you manage the risk and you have to manage the risk of browser attacks in the same way, with layers of defense, knowing exactly what the risks of your assets are and defending them properly."

Marcus said it is difficult to pin down the exact number of infected sites because malware authors are using IFrame attacks.

The situation will only get worse over the next few weeks, Derek Manky, Fortinet's project manager, cyber security and threat research, told InternetNews.com.

"In October Microsoft issued an out of band patch for a vulnerability in the server service that was very high profile, but that flaw is still being exploited," he explained. For two to three weeks after that patch was issued malware activity was low, and now the activity has increased, Manky said.

"I expect to see the same with this IE exploit," Manky said. "In other words, the worst is yet to come."

News courtesy of internetnews.com

December 18, 2008

Download Internet Explorer Now!Download

Download Microsoft Windows Malicious Software Removal Tool Now!Download

View All Microsoft Service & Security Releases

Contents:
1. Browser Security: The Bad Guys Remain One Step Ahead


Additional Articles:

  • Internet Explorer 7: Ready for Public Consumption
  • Gates Mixes It Up with IE, Atlas
  • Microsoft Plans Patch for IE Hole
  • New IE Exploits Create Security Scramble
  • IE 7 Is 'Layout Complete'
  • IE7 Beta 2 Out of Preview
  • Microsoft to Take Third Shot at IE 7 Beta
  • IE, Firefox Users at Risk from New Flaws
  • Third IE 7 Beta Has Layout Changes
  • First Release Candidate for IE 7 Hits
  • Report: IE 7 Has the Best Anti-Phishing Filter
  • Microsoft Planning Life After IE7
  • IE 7 Is Out the Door
  • IE 7's First Security Hole
  • Another Bug Bites IE7
  • Is IE 7 Limiting Remote Access SSL-VPNs?
  • IE 7 Tops 100M Download Mark
  • Internet Explorer at Zero-Day Risk
  • Microsoft Issues IE Security Alert
  • Microsoft to Roll Back the Clock on ActiveX
  • Internet Explorer 8 Passes the 'Acid2' Test
  • Internet Explorer 8 Tries New Compatibility Solution
  • IE8 Beta Soon But Few Details Yet
  • Microsoft Admits IE Still Flawed
  • Microsoft Set to Fix IE Zero Day Flaw
  • Hackers Target IE 7 Browser Again
  • EU to Insist Windows Includes Rival Web Browsers


  • internet.commediabistro.comJusttechjobs.comGraphics.com

    Search:

    WebMediaBrands Corporate Info

    Legal Notices, Licensing, Permissions, Privacy Policy.
    Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs