Microsoft IE Big Security Hole

You cannot sleep and wake up in the morning without finding that your personal data or internet use is under risk, simply because the applications you are using are not safe or they are full of bugs and security holes. This is a situation for most of the PC users, or those who use their default windows applications such as Internet Explorer. Today the news about a new and serious security hole in IE and all its versions not only IE7. For more info read the full article below.

Security Fix warned readers about a newly-discovered security hole in Internet Explorer 7. I’m posting this again because Microsoft now says the flaw affects all supported versions of IE, and because security experts are warning that a large number of sites are being compromised in an effort to exploit this vulnerability and install malware on vulnerable systems.

The SANS Internet Storm Center reports that hackers are breaking into legitimate Web sites and uploading code that could install data-stealing software on the machine of a user who visits the site using Internet Explorer. SANS’s chief technology officer Johannes Ullrichestimates that thousands of sites have been seeded with this exploit to date.

For example, Web security firm Websense reports that hackers have compromised the Chinese Web site for ABIT, the maker of motherboards that power many home computers. So far, the exploits appear to be only stealing online gaming credentials, but SANS andothers warn that attackers will likely use this exploit more deftly in the coming days and weeks.

According to Microsoft’s revised security advisory, this flaw is present in every version of IE in use today, from IE5 all the way through toIE8 Beta 2.

Microsoft’s advisory includes a host of recommendations for mitigating the threat from this vulnerability. Some of the company’s suggestions did not work when I tried them on my Windows Vista system, or did not work without some tweaking that was not mentioned in the advisory.

For instance, Microsoft recommends enabling a feature called “data execution prevention,” by clicking “Tools,” “Internet Options,” then “Advanced,” and then checking the box next to that option. However, when I tried to make the changes in IE7 on Vista, I found that option grayed out. To make that change, I had to close out of IE completely, then right click on the IE icon, select “Run as Administrator,” and then alter the setting.

Microsoft also suggests shifting IE’s Internet and local Intranet security settings to “high.” No problems changing that per Microsoft’s instructions, except that few sites will load properly in IE because changing that setting disables active scripting, a feature that many Web sites use.

In addition, Microsoft says users can mitigate the threat from this flaw by de-registering the vulnerable component, a system file called “oledb32.dll”. To do this, users need to run the Windows command prompt as administrator, and type or cut-and-paste the following command:

Regsvr32.exe /u “Program Files\Common Files\System\Ole DB\oledb32.dll”

This generated an error message on my Windows Vista machine, complaining that the action could not be performed. The command worked fine on my Windows XP system.

I would advise Windows users to consider browsing the Web with anything other than Internet Explorer, at least until Microsoft issues a patch to fix this vulnerability. It is not my intention to over-hype the situation, but as we have seen time and again, attackers are usually very quick to take advantage of flaws in IE because the program is the default browser for close to 80 percent of the planet.

And don’t count on your anti-virus program to save you from these types of attacks. A scan of the exploit being served up by several of the hacked sites produced atrocious resultsVirusTotal.com reported that only four out of the 32 anti-virus programs it used to scan the malware detected it as malicious or suspicious.

Bookmark and Share

Post to Twitter Tweet This Post

0 comments ↓

There are no comments yet...Kick things off by filling out the form below.

Leave a Comment