site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
4393
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
page: 1 · 2 · 3 · 4 · 5
AuthorAll Replies


Oleg
Bellsouth Fastaccess
Premium
join:2003-12-08
Birmingham, AL
kudos:2

reply to slajoh01

Re: IE Zero-Day

Exactly. There is no point of upgrading to IE 9 or 10. Thing is a lot of companies have a crazy policy that does not allow to go with any other browser, but freaking IE.

slajoh01

join:2005-04-23

reply to trparky
Why do large corporations still use IE as their main browser instead of using Firefox or Chrome if IE is that bad?

Also, If MS is not rolling out the patch on Tues, then we have two options basically. Use another browser, or upgrade to IE 9 and 10.

I am not upgrading to 9 or 10. They will have security flaws anyway...Im seriously thinking about using FF as my main browser. Im thinking of it very very much.

How about the rest of you? Are u guys willing to move to a different browser after this mess?



trparky
Apple... YUM
Premium,MVM
join:2000-05-24
Cleveland, OH
kudos:2

reply to StuartMW
Then Microsoft is wrong, I have EMET working on Windows 8 just fine.



StuartMW
Who Is John Galt?
Premium
join:2000-08-06
Galt's Gulch
kudos:2
Reviews:
·CenturyLink

1 edit

reply to antdude

said by antdude:

It could be one of those out of the bound (OOTB) releases.

I think you mean Out Of Band

Out Of Bounds is usually sports related
--
Don't feed trolls--it only makes them grow!


StuartMW
Who Is John Galt?
Premium
join:2000-08-06
Galt's Gulch
kudos:2

reply to Smokey Bear
W8 has EMET (under another name?) built-in. Besides W8 comes with IE10 which isn't vulnerable.



Smokey Bear
veritas odium parit
Premium
join:2008-03-15
Annie's Pub
kudos:4

reply to DevilFrank
According to MS, EMET will not work with W8.



DevilFrank

join:2003-07-13
Reviews:
·T-Com

reply to Smokey Bear

said by Smokey Bear:

said by chachazz:
You might want to take a second look at the diary published this week that is using EMET 3.5 as another tool to help defend your Windows systems against various attacks.

[3] »isc.sans.edu/diary.html?storyid=14797
Thanks chachazz See Profile, valuable info in your post. The use of EMET is highly recommendable and SANS explains very well.

But will it work on W8 properly? Can´t find a version for it.
--
Regards from Germany. Please excuse my stumbling English


Smokey Bear
veritas odium parit
Premium
join:2008-03-15
Annie's Pub
kudos:4

reply to chachazz

said by chachazz:
You might want to take a second look at the diary published this week that is using EMET 3.5 as another tool to help defend your Windows systems against various attacks.

[3] »isc.sans.edu/diary.html?storyid=14797
Thanks chachazz See Profile, valuable info in your post. The use of EMET is highly recommendable and SANS explains very well.
--
»bit.ly/gUqYaH - C. Brian Smith: Think of the exclamation point as a car horn: a little goes a long way. Lay on it too hard and everyone’s going to think you’re a moron.

slajoh01

join:2005-04-23

reply to antdude
I dont get it....Why do large corporations still use IE as their main browser instead of using Firefox or Chrome if IE is that bad?



antdude
A Ninja Ant
Premium,VIP
join:2001-03-25
United State
kudos:4
Reviews:
·RoadRunner Cable

reply to therube

It could be one of those out of the bound (OOTB) releases.
--
Ant @ AQFL.net and AntFarm.ma.cx. Please do not IM/e-mail me for technical support. Use this forum or better, »community.norton.com ! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer.


chachazz
Premium
join:2003-12-14
kudos:7

reply to Smokey Bear

SANS Internet Storm Center Diary
quote:

"FixIt" Patch for CVE-2012-4792 Bypassed
Published: 2013-01-04,
Last Updated: 2013-01-04 23:36:34 UTC
by Guy Bruneau (Version: 1)

On the 1 Jan 2013, Johannes posted a diary on a Microsoft FixIt made available for IE as a way of mitigating the CVE-2012-4792 zero day attack. Researchers at Exodus Intelligence reported today they have developed a new attack that bypasses the FixIt issued by Microsoft. They were able to bypass and compromised a fully-patched system using some variation of the exploit published this week.

You might want to take a second look at the diary published this week that is using EMET 3.5 as another tool to help defend your Windows systems against various attacks.

[1] »isc.sans.edu/diary.html?storyid=14788
[2] »blog.exodusintel.com/2013/01/04/···12-4792/
[3] »isc.sans.edu/diary.html?storyid=14797

-----------
»isc.sans.edu/diary.html?storyid=14824&rss=


siljaline
I'm lovin' that double wide
Premium
join:2002-10-12
Montreal, QC
kudos:17

reply to Smokey Bear
Researchers Bypass Microsoft Fixit for IE Zero Day



chachazz
Premium
join:2003-12-14
kudos:7

reply to Smokey Bear

said by Smokey Bear:


Thanks for posting the fix-it solution chachazz See Profile however it seems that security firm Exodus Intelligence has managed to bypass the fix and compromise a fully-patched system...

Info here: »blog.exodusintel.com/2013/01/04/···12-4792/

Absolutely essential info. Thank you very much Smokey Bear See Profile. Microsoft should be burning the midnight oil over this one.
quote:
After posting our analysis of the current 0day in Internet Explorer which was used in a “watering hole” style attack hosted on the Council for Foreign Relations website, we decided to take a look at the Fix It patch made available by Microsoft to address the vulnerability.

After less than a day of reverse engineering, we found that we were able to bypass the fix and compromise a fully-patched system with a variation of the exploit we developed earlier this week.

We have included details on the bypass to customers of our intelligence feeds and will notify Microsoft of the issue. In practice with coordinated vulnerability disclosure, we intend to update this post with details when Microsoft has addressed the problematic patch.


Smokey Bear
veritas odium parit
Premium
join:2008-03-15
Annie's Pub
kudos:4

reply to siljaline

said by siljaline :
Some slight duplication of effort never hurt anybody. Better than no information • voila


siljaline
I'm lovin' that double wide
Premium
join:2002-10-12
Montreal, QC
kudos:17
Reviews:
·Bell Sympatico

reply to Smokey Bear
The Krebs Article that redwolfe_98 See Profile originally posted has the FixIt



Smokey Bear
veritas odium parit
Premium
join:2008-03-15
Annie's Pub
kudos:4

reply to chachazz

said by chachazz:

Microsoft Security Advisory (2794220)

Vulnerability in Internet Explorer Could Allow Remote Code Execution
| Updated: Monday, December 31, 2012

Microsoft Fix it solution, "MSHTML Shim Workaround", that prevents exploitation of this issue

See Microsoft Knowledge Base Article 2794220 to use the automated Microsoft Fix it solution to enable or disable this workaround.

Here it is : Fix it for me - FixIt Solution

Thanks for posting the fix-it solution chachazz See Profile however it seems that security firm Exodus Intelligence has managed to bypass the fix and compromise a fully-patched system...

Info here: »blog.exodusintel.com/2013/01/04/···12-4792/
--
»bit.ly/gUqYaH - C. Brian Smith: Think of the exclamation point as a car horn: a little goes a long way. Lay on it too hard and everyone’s going to think you’re a moron.


therube

join:2004-11-11
Randallstown, MD

reply to redwolfe_98
Symantec Finds the Hackers Behind Microsoft’s Latest Zero-Day Flaw

Microsoft Won’t Patch Critical IE Flaw on Tuesday

(This coming Tuesday, that is.)



Oleg
Bellsouth Fastaccess
Premium
join:2003-12-08
Birmingham, AL
kudos:2

reply to siljaline

said by siljaline:

said by Oleg:

Microsoft did it again

Did what again or are you just poking fun

screwed up again, in security and stability field unlike other software development companies, like Mozilla,Opera in browser industry. Microsoft did not just have one or two stability or security issues.


siljaline
I'm lovin' that double wide
Premium
join:2002-10-12
Montreal, QC
kudos:17
Reviews:
·Bell Sympatico

reply to Oleg

said by Oleg:

Microsoft did it again

Did what again or are you just poking fun


Oleg
Bellsouth Fastaccess
Premium
join:2003-12-08
Birmingham, AL
kudos:2

reply to redwolfe_98
Microsoft did it again

page: 1 · 2 · 3 · 4 · 5

Sunday, 19-May 21:19:13 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 13.5 years online © 1999-2013 dslreports.com.
Most commented news this week
Hot Topics