Comments on: Microsoft investigates another IE flaw report
Software giant probes report of a new browser flaw that, according to its discoverer, could let attackers run malicious code on PCs.
Software giant probes report of a new browser flaw that, according to its discoverer, could let attackers run malicious code on PCs.
January 4, 2010 1:48 PM PST
January 4, 2010 1:09 PM PST
January 4, 2010 1:02 PM PST
Add headlines from CNET News to your homepage or feedreader.
More feeds available in our RSS feed index.
Related quotes
Do you not drive because you may get involved in a car accident? :)
Do you not drive because you may get involved in a car accident? :)
history has taken so much out of society's pockets, and ruined
their days off fixing more crap. The solution is not to stop using
IE, it is to STOP using Windows. Microsoft sucks, can I say it any
louder for you poor slobs that cant say "SH*T" with a
mouthful....WINDOWS SUCKS, get over your lame professions
that this OS is Ok, and that smart users "patch" their systems.
Have you not learned by now that its not going to end. Lets see,
I patched my Apple PowerBook once or twice a month, does it
get bitten weekly by bugs, viruses, worms, or trojans NOPE!!! In
this world, trojans are for when youre having "safe" fun, but for
PC losers its the sign of bad birth control, Bill Gates birthed a
"lemon" on the world. Go ahead, admit it, you bought junk.
Hahahaha. You really ought to buy a Macintosh and learn what
stability and trouble free computing is all about. Poor suckers.
Bill Gates loves you though, I am sure he's got a big present for
you this holiday, keep waiting for it, its in the mail.......;-)
You don't even have to want it. If you are buying a PC system, you are buying a license for Windows. (It's not even an OS but the LICENSE to run an OS.) You may not want it, but you're getting it. Running Linux? Too bad. You're paying for a Windows license.
something goes wrong Microsoft. If they haven't switched yet
because of viruses and other flaws (yes I think being affected by
a virus is a flaw) they won't switch because you tease them. Yes,
I am very happy with my Macintosh but from reading your
comment people might think that only jerks would buy form
Apple. Also I don't think a horrible internet browser is a reason
to change operating systems, not to say that I think people
should use Internet exploer, but their are options for people
content with their systems. Perhaps if every internt user, on
Windows, switched to a safer browser than Internet Exploer,
Microsoft might understand that their low standards are not
acceptable. As of right now MS has no reason to change how
they do things until a significant competitor appears.
All of these are far more secure than Windows. Then again, so is [insert your own joke here].
-Dave
No matter what we do nothing is safe from people who really want to exploit it.
history has taken so much out of society's pockets, and ruined
their days off fixing more crap. The solution is not to stop using
IE, it is to STOP using Windows. Microsoft sucks, can I say it any
louder for you poor slobs that cant say "SH*T" with a
mouthful....WINDOWS SUCKS, get over your lame professions
that this OS is Ok, and that smart users "patch" their systems.
Have you not learned by now that its not going to end. Lets see,
I patched my Apple PowerBook once or twice a month, does it
get bitten weekly by bugs, viruses, worms, or trojans NOPE!!! In
this world, trojans are for when youre having "safe" fun, but for
PC losers its the sign of bad birth control, Bill Gates birthed a
"lemon" on the world. Go ahead, admit it, you bought junk.
Hahahaha. You really ought to buy a Macintosh and learn what
stability and trouble free computing is all about. Poor suckers.
Bill Gates loves you though, I am sure he's got a big present for
you this holiday, keep waiting for it, its in the mail.......;-)
You don't even have to want it. If you are buying a PC system, you are buying a license for Windows. (It's not even an OS but the LICENSE to run an OS.) You may not want it, but you're getting it. Running Linux? Too bad. You're paying for a Windows license.
something goes wrong Microsoft. If they haven't switched yet
because of viruses and other flaws (yes I think being affected by
a virus is a flaw) they won't switch because you tease them. Yes,
I am very happy with my Macintosh but from reading your
comment people might think that only jerks would buy form
Apple. Also I don't think a horrible internet browser is a reason
to change operating systems, not to say that I think people
should use Internet exploer, but their are options for people
content with their systems. Perhaps if every internt user, on
Windows, switched to a safer browser than Internet Exploer,
Microsoft might understand that their low standards are not
acceptable. As of right now MS has no reason to change how
they do things until a significant competitor appears.
All of these are far more secure than Windows. Then again, so is [insert your own joke here].
-Dave
No matter what we do nothing is safe from people who really want to exploit it.
If you haven't learned by now that IE is near the root of all Windows
disasters, learn it now. Delete IE functionality (You can;t get rid of
the code due to MS's Marketing driven misdesign of the WIndows
OS) and move to a real browser.
It really doesn't take any skill or experience to make the shift.
Well..... my fellow brothers.... it is bad.... really bad.... you do not have to be connected to the internet for what i have been seeeing lately.... but the worst part about it.. when i think back to my years as an admin on an enterprise level MAN county behavioral health and a & d nework.....for three years with 300 users.... I remember seeing all of the same symptoms and "comprimises" which have come to a head lately.... back then... It was just because I did not recognize what I do today through years of experience on a major network.... whereas before my first thousand help calls, the scope to which my configuration of an OS has changed dramatically....
The following is only a partial list of programs which upon bootup and install....(and literally from power on even before the OS boots fully)which are not only defective and require a fix to be downloaded, but also installed in a time sensitive maner depending on the level of sofistication of your programmer...
1. Fat16 & 32 Partitions - no file level security
2. d-com services enabled upon startup with command priveleges set to Everybody buy default
3.Indexing Services enabled by default
4.Several services designed for remote configuration by administrators which alow a SYSTEM logon to execute and change priveleges locally or remotely...
5. IE6 by default allowing for third party installs with out prompting
6. Windows Update - gets redirected to a local file so that the desired remote code gets a potential execution with the default install of XP sp3 allowing for automatic updates...
7.Remote assistance enabled by default
8. Norton Scheduler gets incremented with jobs upon the installation of the program in order to update the file definitions for the new program for yet another potential opportunity for external code execution.
9. Propriatery protocols... i notice this upon the review of a packet capture in which i did not see any activity on the nic,switch,router,or modem... but yet I was gettin tons of packets in though the capture... well my capture program did not recognize the protocol... but it alomost seemed like a dirivitive of the old token ring protocol.....
9. default registry values set ready for remote or network configuration.... if you don't review the complete set of security polocied these too provide for an additional potenital instance.
So basically without me haveing to type the detail instructions which I have developed to achieve a secure instal..
If you can imagine having all these extra steps for completing a system install or repair... and worse if you are not aware of the urgency and order of the exploits... any one of these could initate a process which would not only take administrative priveleges but backup the entire contents of your hard drive to a remote network server but alow for a remote network user to remotely enable a mic or pc cam.... and had been so since at least 2002......
Don't forget to thank the quag for all the work he put into solving this problem....O' what problem.....
hhahah
The Quag
If you haven't learned by now that IE is near the root of all Windows
disasters, learn it now. Delete IE functionality (You can;t get rid of
the code due to MS's Marketing driven misdesign of the WIndows
OS) and move to a real browser.
It really doesn't take any skill or experience to make the shift.
Well..... my fellow brothers.... it is bad.... really bad.... you do not have to be connected to the internet for what i have been seeeing lately.... but the worst part about it.. when i think back to my years as an admin on an enterprise level MAN county behavioral health and a & d nework.....for three years with 300 users.... I remember seeing all of the same symptoms and "comprimises" which have come to a head lately.... back then... It was just because I did not recognize what I do today through years of experience on a major network.... whereas before my first thousand help calls, the scope to which my configuration of an OS has changed dramatically....
The following is only a partial list of programs which upon bootup and install....(and literally from power on even before the OS boots fully)which are not only defective and require a fix to be downloaded, but also installed in a time sensitive maner depending on the level of sofistication of your programmer...
1. Fat16 & 32 Partitions - no file level security
2. d-com services enabled upon startup with command priveleges set to Everybody buy default
3.Indexing Services enabled by default
4.Several services designed for remote configuration by administrators which alow a SYSTEM logon to execute and change priveleges locally or remotely...
5. IE6 by default allowing for third party installs with out prompting
6. Windows Update - gets redirected to a local file so that the desired remote code gets a potential execution with the default install of XP sp3 allowing for automatic updates...
7.Remote assistance enabled by default
8. Norton Scheduler gets incremented with jobs upon the installation of the program in order to update the file definitions for the new program for yet another potential opportunity for external code execution.
9. Propriatery protocols... i notice this upon the review of a packet capture in which i did not see any activity on the nic,switch,router,or modem... but yet I was gettin tons of packets in though the capture... well my capture program did not recognize the protocol... but it alomost seemed like a dirivitive of the old token ring protocol.....
9. default registry values set ready for remote or network configuration.... if you don't review the complete set of security polocied these too provide for an additional potenital instance.
So basically without me haveing to type the detail instructions which I have developed to achieve a secure instal..
If you can imagine having all these extra steps for completing a system install or repair... and worse if you are not aware of the urgency and order of the exploits... any one of these could initate a process which would not only take administrative priveleges but backup the entire contents of your hard drive to a remote network server but alow for a remote network user to remotely enable a mic or pc cam.... and had been so since at least 2002......
Don't forget to thank the quag for all the work he put into solving this problem....O' what problem.....
hhahah
The Quag
Usually its been "this exploit could allow an attacker to take complete control of your computer"
Security is improving.
<end sarcasm>
Usually its been "this exploit could allow an attacker to take complete control of your computer"
Security is improving.
<end sarcasm>
- I can provide them with a bunch of screenshots...
- by fred dunn August 31, 2005 10:02 AM PDT
- of IE crashing, So what.
- Like this Reply to this comment
-
(56 Comments)