PDA

View Full Version : Another Major IE Flaw


GWguy
12-16-2008, 11:32 AM
Major Internet Explorer security flaw found -- Newsday.com (http://www.newsday.com/business/ny-bzexplorer1216,0,789877.story)

The flaw lets criminals commandeer victims' machines merely by tricking them into visiting Web sites tainted with malicious programming code. As many as 10,000 sites have been compromised since last week to exploit the browser flaw, according to antivirus software maker Trend Micro Inc.

No doubt in my mind.... next PC is a MAC!

mainman
12-16-2008, 11:42 AM
firefox ftw..

GWguy
12-16-2008, 11:45 AM
firefox ftw..

:yay: I don't use IE unless I have to for internal corporate use....

mainman
12-16-2008, 11:48 AM
:yay: I don't use IE unless I have to for internal corporate use....
the only thing ie is good for is downloading firefox...:lol:

bfncbs1
12-16-2008, 12:01 PM
the only thing ie is good for is downloading firefox...:lol:


:yeahthat::yeahthat::yeahthat:

G1G4
12-16-2008, 02:45 PM
firefox ftw..

Firefox ftmfl

Opera ftmfw

:dye:

GWguy
12-16-2008, 02:49 PM
Firefox ftmfl

Opera ftmfw

:dye:

I tried Opera a few times, just didn't like it's "feel". Always went back to FireFox.

clevalley
12-16-2008, 08:40 PM
Firefox has had their fair share of security flaws, just not well known like IE. Either way, we are probably going to buy a site license for a program called Sandboxie - you load your program in this "shell" and if the program downloads a virus or malware - you delete the sandbox and create a new one. Nothing gets through, it is good stuff - we have been testing it for about 2 years.

Sandboxie - Sandbox software for application isolation and secure Web browsing (http://www.sandboxie.com/)

RadioPatrol
12-17-2008, 11:26 AM
:yay: I don't use IE unless I have to for internal corporate use....

Yeah that .... and Windows Updates

RadioPatrol
12-17-2008, 11:29 AM
Firefox has had their fair share of security flaws, just not well known like IE. Either way, we are probably going to buy a site license for a program called Sandboxie - you load your program in this "shell" and if the program downloads a virus or malware - you delete the sandbox and create a new one. Nothing gets through, it is good stuff - we have been testing it for about 2 years.

Sandboxie - Sandbox software for application isolation and secure Web browsing (http://www.sandboxie.com/)

I have looked at that ...

so if you surf into a compromised web site, even though your browser may download and install malware, all is self contained in the sandbox ?

chesapeakewndrs
12-17-2008, 08:04 PM
Well Microsoft already put out a patch.

bobbyb
12-18-2008, 11:29 AM
Downloaded Firefox and installed it. Runs much quicker.

clevalley
12-21-2008, 09:37 PM
I have looked at that ...

so if you surf into a compromised web site, even though your browser may download and install malware, all is self contained in the sandbox ?

You got it! You can also hook other applications into it as well. I have not really played with it, but two others in our shop knows the in's and out's. I have just came on board with it and am messing with it.

In testing, we have gone to known virus sites and have infected the browser in the sandbox - we blow the sandbox away and scan the entire machine with no virus found. Setup a new sandbox and you are off an running - really GREAT stuff. :yay:

Now, if you download an attachment and save it outside of the sandbox and run it, then your system can get compromised.

BoyGenius
12-21-2008, 10:29 PM
You got it! You can also hook other applications into it as well. I have not really played with it, but two others in our shop knows the in's and out's. I have just came on board with it and am messing with it.

In testing, we have gone to known virus sites and have infected the browser in the sandbox - we blow the sandbox away and scan the entire machine with no virus found. Setup a new sandbox and you are off an running - really GREAT stuff. :yay:

Now, if you download an attachment and save it outside of the sandbox and run it, then your system can get compromised.

If that thing literally condones off a fixed sector off the hard drive and always writes there, it should do quite well at destroying one of those new flash memory based hard drives in the high-end notebooks. I was reading their life cycle depends on the data being written to different places and MS was working on that for upcoming versions of Windows.

clevalley
12-22-2008, 04:49 PM
If that thing literally condones off a fixed sector off the hard drive and always writes there, it should do quite well at destroying one of those new flash memory based hard drives in the high-end notebooks. I was reading their life cycle depends on the data being written to different places and MS was working on that for upcoming versions of Windows.

I do not believe it vectors off the same spot every time so that would not be an issue; it would be the same as running IE outside of the sandbox... in other words, no program runs out of ram constantly, nor does it access the same "spot" every time.

FLASH Drives, Toshiba had some good write ups on them and the issues of writing are pretty much a thing of the past. There is still a life-cycle on them, but by the time the drive dies the computer will be obsolete. I have one user getting one (XP Pro) with a Flash hard drive and he will be our test case.

itsbob
12-22-2008, 05:02 PM
I do not believe it vectors off the same spot every time so that would not be an issue; it would be the same as running IE outside of the sandbox... in other words, no program runs out of ram constantly, nor does it access the same "spot" every time.

FLASH Drives, Toshiba had some good write ups on them and the issues of writing are pretty much a thing of the past. There is still a life-cycle on them, but by the time the drive dies the computer will be obsolete. I have one user getting one (XP Pro) with a Flash hard drive and he will be our test case.

I would think that flash drive would have longer longevity than a current HD. If I get the concept correct it's like memory chip that isn't volatile. Will maintain it's data store through cycles of power on and off.

The biggest pro to this is no moving parts.. no spinning platters, no read/write heads scanning the surface, no arms or motors. A LOT less to fail, and of course a lot less latency waiting for the mecahanics to catch up.

The con, is how long can a bit retain a charge, through cycles of 1 and 0?

I would bet overall, a failure rate equal to or better than a HD for the first generation, improving rapidly in succeeding generations.

BoyGenius
12-22-2008, 05:28 PM
I would think that flash drive would have longer longevity than a current HD. If I get the concept correct it's like memory chip that isn't volatile. Will maintain it's data store through cycles of power on and off.

The biggest pro to this is no moving parts.. no spinning platters, no read/write heads scanning the surface, no arms or motors. A LOT less to fail, and of course a lot less latency waiting for the mecahanics to catch up.

The con, is how long can a bit retain a charge, through cycles of 1 and 0?

I would bet overall, a failure rate equal to or better than a HD for the first generation, improving rapidly in succeeding generations.

Once these things become more affordable and larger, they're going to be the bomb!

SLC and MLC is the big thing to know right now.

AnandTech: Intel X25-M SSD: Intel Delivers One of the World's Fastest Drives (http://www.anandtech.com/cpuchipsets/intel/showdoc.aspx?i=3403&p=4)

:yahoo:

RadioPatrol
12-23-2008, 06:43 AM
Now, if you download an attachment and save it outside of the sandbox and run it, then your system can get compromised.



yeah but I can scan my downloads for Viruses .... it is the drive by crap that is annoying


SEO by vBSEO 3.1.0 ©2007, Crawlability, Inc.