<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;Re: IE Zero-Day&#x27; in forum &#x27;Security&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27863810</link>
<description></description>
<language>en</language>
<pubDate>Tue, 21 May 2013 04:03:03 EDT</pubDate>
<lastBuildDate>Tue, 21 May 2013 04:03:03 EDT</lastBuildDate>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27908459</link>
<description><![CDATA[StuartMW posted : IE is being patched Mon Jan 14th<br><br>&raquo;<A HREF="/forum/r27908401-Microsoft-Security-Bulletin-Advance-Notification-for-14th-">Microsoft Security Bulletin Advance Notification for 14th!</A><br><small>--<br>Don't feed trolls--it only makes them grow!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27908459</guid>
<pubDate>Sun, 13 Jan 2013 19:06:51 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27896860</link>
<description><![CDATA[antdude posted : <div class="bquote"><said>said by <a href="/profile/1140294" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1140294');">Blackbird</a>:</said><p>As with all software patches, from all sources, they'll roll out a patch when and if they're ready. First they have to determine the scope of the causal factors, then find fixes that don't break things, then test against all manner of system setups. Each step takes time to be done properly, and little can be accomplished by trying to do the steps in parallel.<br> </p></div>Yep, don't rush them. We don't want a buggy release.<br><small>--<br>Ant @ AQFL.net and AntFarm.ma.cx. Please do not IM/e-mail me for technical support. Use this forum or better, &raquo;<A HREF="http://community.norton.com" >community.norton.com</A> ! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27896860</guid>
<pubDate>Wed, 09 Jan 2013 20:01:02 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27895938</link>
<description><![CDATA[Blackbird posted : As with all software patches, from all sources, they'll roll out a patch when and if they're ready. First they have to determine the scope of the causal factors, then find fixes that don't break things, then test against all manner of system setups. Each step takes time to be done properly, and little can be accomplished by trying to do the steps in parallel.<br><small>--<br>“The American Republic will endure until the day Congress discovers that it can bribe the public with the public's money.” A. de Tocqueville</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27895938</guid>
<pubDate>Wed, 09 Jan 2013 15:29:34 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27895460</link>
<description><![CDATA[slajoh01 posted : Will MS ever roll out this patch in the near future for IE 8? <br><br>Thanks!!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27895460</guid>
<pubDate>Wed, 09 Jan 2013 13:28:23 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27895377</link>
<description><![CDATA[Oleg posted : Just checked Windows Updates, and 9 security updates were listed. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27895377</guid>
<pubDate>Wed, 09 Jan 2013 13:12:18 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27894896</link>
<description><![CDATA[therube posted : "... Even though a security company has revealed that it had managed to bypass Microsoft&#146;s one-click &#147;Fix it&#148; solution for Internet Explorer 8 and older, the Redmond-based software firm says that users are fully protected if they deploy the patch.<br><br>&#147;We&#146;ve reviewed the information and are working on an update, which we will make available to all customers on IE6-8 as soon as it is ready for distribution,&#148; said Dustin Childs, group manager, Microsoft Trustworthy Computing, according to ThreatPost.<br><br>&#147;In the meantime, the current Fix it, mitigations and workarounds available in Security Advisory 2794220 fully protect against all known active attacks. We also continue to encourage customers to upgrade their browsers to IE9-10, which are not affected by this issue.&#148;<br><br>While Internet Explorer 9 and Internet Explorer 10 are not affected by the issue, security vendors across the globe are confirming that more websites have been compromised in order to exploit the flaw.<br><br>&#147;The whole point of the waterhole tactic is that they believe such sites, although usually not with high numbers of users, will have interesting visitors,&#148; said Jindrich Kubec, Avast Virus Lab&#146;s director of Threat Intelligence. &#147;At least two of the sites use the same spyware binary with exactly same configuration. The rest look a bit different, but we haven&#146;t investigated it thoroughly yet.&#148;..."<br><br>&raquo;<A HREF="http://news.softpedia.com/news/Microsoft-to-Release-New-Patch-for-Internet-Explorer-8-Hack-319547.shtml" >news.softpedia.com/news/Microsof&middot;&middot;&middot;47.shtml</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27894896</guid>
<pubDate>Wed, 09 Jan 2013 11:07:25 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27891076</link>
<description><![CDATA[trparky posted : EMET would be the best bet in that kind of situation.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27891076</guid>
<pubDate>Tue, 08 Jan 2013 10:23:03 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27890385</link>
<description><![CDATA[slajoh01 posted : Where I work, we still use IE 8. What should companies urge to do in the meantime while MS decides to roll up the patch for this?<br><br>We cannot upgrade to IE 9 or 10.<br><br>And also, we not allowed to use Firefox and other browsers either.<br><br>The workarounds explained on the MS site, is to extend the Internet/Intranet Security zones to HIGH, and thats no good for the users because IE is then worthless to use....unless adding those sites in the Trusted Zones.<br><br>And also, even though if MS decides to roll out the patch on Tuesday, our IT department has to still then delay the patch deployment for about a week in order to test it with our applications. <br><br>So what should companies like this do in this case if this is a huge exploit???]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27890385</guid>
<pubDate>Tue, 08 Jan 2013 00:37:13 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27888771</link>
<description><![CDATA[chachazz posted : Internet Explorer 9 and 10 are not vulnerable to this exploit.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27888771</guid>
<pubDate>Mon, 07 Jan 2013 14:52:55 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27888756</link>
<description><![CDATA[chachazz posted : Internet Explorer zero-day exploit found on more websites.<br>&raquo;<A HREF="http://nakedsecurity.sophos.com/2013/01/07/internet-explorer-zero-day-attack-websites/" >nakedsecurity.sophos.com/2013/01&middot;&middot;&middot;ebsites/</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27888756</guid>
<pubDate>Mon, 07 Jan 2013 14:47:26 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27888744</link>
<description><![CDATA[StuartMW posted : Well regardless XP/Vista/Win7 users would be well served by installing/configuring it. Win8 I'm not sure.<br><small>--<br>Don't feed trolls--it only makes them grow!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27888744</guid>
<pubDate>Mon, 07 Jan 2013 14:45:53 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27888726</link>
<description><![CDATA[trparky posted : <b>ASLR and exploit mitigations</b><br>Address Space Layout Randomization (ASLR) was introduced in Windows Vista and is essentially a technique to mitigate the infamous &#147;Buffer Overrun&#148; vulnerabilities by randomly moving the location of code and data in memory. In Windows 8 randomization is increased in order to foil known techniques for bypassing ASLR. Other mitigations include changes to the Windows kernel and heap, including new integrity checks and randomization using a similar approach to ASLR. Internet Explorer 10 will also benefit from these changes: besides including an &#147;Enhanced Protected Mode&#148; sandbox, there will be a &#147;ForceASLR&#148; option in IE10 that can randomize all modules loaded into memory by the browser, regardless if those modules did not opt in to use ASLR protection (developers can create modules that take advantage of ASLR protection by using the optional /DYNAMICBASE flag).<br><br>EMET provides much more than that.<br><small>--<br>Tom<br><A HREF="http://on.fb.me/k8VIVy">Boycott AT&T uVerse!</a> | <A HREF="http://www.toms-world.org/blog/android">Tom's Android Blog</a> | <A HREF="http://bit.ly/RNSReP">AOKP (The Android Open Kang Project)</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27888726</guid>
<pubDate>Mon, 07 Jan 2013 14:42:39 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27888690</link>
<description><![CDATA[trparky posted : Maybe, I don't know.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27888690</guid>
<pubDate>Mon, 07 Jan 2013 14:30:05 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27888658</link>
<description><![CDATA[StuartMW posted : <div class="bquote"><said>said by <a href="/profile/161242" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=161242');">trparky</a>:</said><p>EMET does indeed work with Windows 8.</p></div>That wasn't my point BTW. I thought W8 <i>included</i> some version of EMET out of the box.<br><small>--<br>Don't feed trolls--it only makes them grow!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27888658</guid>
<pubDate>Mon, 07 Jan 2013 14:22:32 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27888607</link>
<description><![CDATA[trparky posted : EMET does indeed work with Windows 8.  I have it protecting Firefox on my Windows 8 installation.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27888607</guid>
<pubDate>Mon, 07 Jan 2013 14:07:06 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27888393</link>
<description><![CDATA[chachazz posted : <div class="bquote"><said>said by <a href="/profile/1371265" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1371265');">daveinpoway</a>:</said><p>A security researcher has found a way to bypass Microsoft's temporary "fix"n<br> </p></div> Info  posted by  Smokey Bear <A HREF="/useremail/u/1537340"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> (on page 2) <br>&raquo;<IMG  align=absmiddle style="vertical-align:middle;" TITLE="" SRC="http://i.dslr.net/silk/lock.png" border=0 width=16 height=16><A HREF="https://secure.dslreports.com/forum/r27880706-">Re: IE Zero-Day</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27888393</guid>
<pubDate>Mon, 07 Jan 2013 13:06:46 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27888308</link>
<description><![CDATA[daveinpoway posted : A security researcher has found a way to bypass Microsoft's temporary "fix":&raquo;<A HREF="http://www.computerworld.com/s/article/9235281/Researcher_sidesteps_Microsoft_fix_for_IE_zero_day?source=CTWNLE_nlt_security_2013-01-07" >www.computerworld.com/s/article/&middot;&middot;&middot;13-01-07</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27888308</guid>
<pubDate>Mon, 07 Jan 2013 12:35:44 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27887267</link>
<description><![CDATA[antdude posted : <div class="bquote"><said>said by <a href="/profile/181601" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=181601');">StuartMW</a>:</said><p><div class="bquote"><said>said by <a href="/profile/352846" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=352846');">antdude</a>:</said><p>It could be one of those out of the bound (OOTB) releases.<br> </p></div>I think you mean <a href="http://en.wikipedia.org/wiki/Out-of-band#Computing">Out Of Band</a> :p<br><br>Out Of Bounds is usually sports related :D<br> </p></div>DOH! You're right. Dang sports.<br><small>--<br>Ant @ AQFL.net and AntFarm.ma.cx. Please do not IM/e-mail me for technical support. Use this forum or better, &raquo;<A HREF="http://community.norton.com" >community.norton.com</A> ! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27887267</guid>
<pubDate>Mon, 07 Jan 2013 02:11:47 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27883162</link>
<description><![CDATA[slajoh01 posted : And do people or users know if they have been attacked from this exploit? What are the signs and symtoms?<br><br>Ok, then let me ask this to everyone.<br>For those of u here who have always have been a fan of IE or has or is still using IE as their main browser, are u considering to use another browser?<br><br>The reason I like IE, because I can lock it down using the Group Policy editor. Firefox does not have this kind of "granular" control. <br>And thats perhaps one of the reasons why System Admins prefer to use IE at most companies.<br><br>Until MS rolls out this fix or patch, I will use FF instead....in the meantime.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27883162</guid>
<pubDate>Sat, 05 Jan 2013 12:35:59 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27883117</link>
<description><![CDATA[Oleg posted : Exactly. There is no point of upgrading to IE 9 or 10. Thing is a lot of companies have a crazy policy that does not allow to go with any other browser, but freaking IE. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27883117</guid>
<pubDate>Sat, 05 Jan 2013 12:21:42 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27883048</link>
<description><![CDATA[slajoh01 posted : Why do large corporations still use IE as their main browser instead of using Firefox or Chrome if IE is that bad?<br><br>Also, If MS is not rolling out the patch on Tues, then we have two options basically. Use another browser, or upgrade to IE 9 and 10. <br><br>I am not upgrading to 9 or 10. They will have security flaws anyway...Im seriously thinking about using FF as my main browser. Im thinking of it very very much. <br><br>How about the rest of you? Are u guys willing to move to a different browser after this mess?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27883048</guid>
<pubDate>Sat, 05 Jan 2013 11:56:19 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27883011</link>
<description><![CDATA[trparky posted : Then Microsoft is wrong, I have EMET working on Windows 8 just fine.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27883011</guid>
<pubDate>Sat, 05 Jan 2013 11:46:18 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27882652</link>
<description><![CDATA[StuartMW posted : <div class="bquote"><said>said by <a href="/profile/352846" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=352846');">antdude</a>:</said><p>It could be one of those out of the bound (OOTB) releases.<br> </p></div>I think you mean <a href="http://en.wikipedia.org/wiki/Out-of-band#Computing">Out Of Band</a> :p<br><br>Out Of Bounds is usually sports related :D<br><small>--<br>Don't feed trolls--it only makes them grow!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27882652</guid>
<pubDate>Sat, 05 Jan 2013 09:02:42 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27882626</link>
<description><![CDATA[StuartMW posted : W8 has EMET (under another name?) built-in. Besides W8 comes with IE10 which isn't vulnerable.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27882626</guid>
<pubDate>Sat, 05 Jan 2013 08:43:07 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27882535</link>
<description><![CDATA[Smokey Bear posted : According to MS, EMET will not work with W8.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27882535</guid>
<pubDate>Sat, 05 Jan 2013 06:36:37 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27882497</link>
<description><![CDATA[DevilFrank posted : <div class="bquote"><said>said by <a href="/profile/1537340" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1537340');">Smokey Bear</a>:</said><p>  <BLOCKQUOTE><SMALL>said by <a href="/profile/914341" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=914341');">chachazz</a>:</SMALL><HR>You might want to take a second look at the diary published this week that is using <a href="https://isc.sans.edu/diary.html?storyid=14797"><b>EMET 3.5</b></a> as another tool to help defend your Windows systems against various attacks.<br><br>[3] &raquo;<A HREF="https://isc.sans.edu/diary.html?storyid=14797" >isc.sans.edu/diary.html?storyid=14797</A><HR></BLOCKQUOTE><br><br>Thanks  chachazz <A HREF="/useremail/u/914341"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>, valuable info in your post. The use of EMET is highly recommendable and SANS explains very well.<br> </p></div>But will it work on W8 properly? Can´t find a version for it.<br><small>--<br>Regards from Germany. Please excuse my stumbling English</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27882497</guid>
<pubDate>Sat, 05 Jan 2013 04:47:40 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27882460</link>
<description><![CDATA[Smokey Bear posted :  <BLOCKQUOTE><SMALL>said by <a href="/profile/914341" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=914341');">chachazz</a>:</SMALL><HR>You might want to take a second look at the diary published this week that is using <a href="https://isc.sans.edu/diary.html?storyid=14797"><b>EMET 3.5</b></a> as another tool to help defend your Windows systems against various attacks.<br><br>[3] &raquo;<A HREF="https://isc.sans.edu/diary.html?storyid=14797" >isc.sans.edu/diary.html?storyid=14797</A><HR></BLOCKQUOTE><br>Thanks  chachazz <A HREF="/useremail/u/914341"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>, valuable info in your post. The use of EMET is highly recommendable and SANS explains very well.<br><small>--<br><i>&raquo;<A HREF="http://bit.ly/gUqYaH" >bit.ly/gUqYaH</A> - C. Brian Smith: Think of the exclamation point as a car horn: a little goes a long way. Lay on it too hard and everyone’s going to think you’re a moron.</i></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27882460</guid>
<pubDate>Sat, 05 Jan 2013 03:34:53 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27882396</link>
<description><![CDATA[slajoh01 posted : I dont get it....Why do large corporations still use IE as their main browser instead of using Firefox or Chrome if IE is that bad?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27882396</guid>
<pubDate>Sat, 05 Jan 2013 02:25:51 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27881795</link>
<description><![CDATA[antdude posted : <div class="bquote"><said>said by <a href="/profile/1107429" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1107429');">therube</a>:</said><p><A HREF="http://news.softpedia.com/news/Symantec-Finds-the-Hackers-Behind-Microsoft-s-Latest-Zero-Day-Flaw-318338.shtml" >Symantec Finds the Hackers Behind Microsoft&#146;s Latest Zero-Day Flaw</A><br><br><A HREF="http://news.softpedia.com/news/Microsoft-Won-t-Patch-Critical-IE-Flaw-on-Tuesday-318418.shtml" >Microsoft Won&#146;t Patch Critical IE Flaw on Tuesday</A><br><br>(This coming Tuesday, that is.)<br> </p></div>It could be one of those out of the bound (OOTB) releases.<br><small>--<br>Ant @ AQFL.net and AntFarm.ma.cx. Please do not IM/e-mail me for technical support. Use this forum or better, &raquo;<A HREF="http://community.norton.com" >community.norton.com</A> ! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27881795</guid>
<pubDate>Fri, 04 Jan 2013 21:05:16 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27881648</link>
<description><![CDATA[chachazz posted : <a href="https://isc.sans.edu/diary.html?storyid=14824&rss="><b>SANS Internet Storm Center Diary</b></a> <BLOCKQUOTE><SMALL>quote:</SMALL><HR> <br>"FixIt" Patch for CVE-2012-4792 Bypassed<br>Published: 2013-01-04,<br>Last Updated: 2013-01-04 23:36:34 UTC<br>by Guy Bruneau (Version: 1)<br><br>On the 1 Jan 2013, Johannes posted a diary on a <a href="https://isc.sans.edu/diary.html?storyid=14788">Microsoft FixIt</a> made available for IE as a way of mitigating the CVE-2012-4792 zero day attack. Researchers at Exodus Intelligence reported today they have developed a new attack that bypasses the FixIt issued by Microsoft. They were able to bypass and compromised a fully-patched system using some variation of the exploit published this week.<br><br>You might want to take a second look at the diary published this week that is using <a href="https://isc.sans.edu/diary.html?storyid=14797"><b>EMET 3.5</b></a> as another tool to help defend your Windows systems against various attacks.<br><br>[1] &raquo;<A HREF="https://isc.sans.edu/diary.html?storyid=14788" >isc.sans.edu/diary.html?storyid=14788</A><br>[2] &raquo;<A HREF="http://blog.exodusintel.com/2013/01/04/bypassing-microsofts-internet-explorer-0day-fix-it-patch-for-cve-2012-4792/" >blog.exodusintel.com/2013/01/04/&middot;&middot;&middot;12-4792/</A><br>[3] &raquo;<A HREF="https://isc.sans.edu/diary.html?storyid=14797" >isc.sans.edu/diary.html?storyid=14797</A><br><br>-----------<HR></BLOCKQUOTE>&raquo;<A HREF="https://isc.sans.edu/diary.html?storyid=14824&rss=" >isc.sans.edu/diary.html?storyid=14824&rss=</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27881648</guid>
<pubDate>Fri, 04 Jan 2013 20:17:00 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27881394</link>
<description><![CDATA[siljaline posted : <ahref="http://threatpost.com/en_us/blogs/researchers-bypass-microsoft-fix-it-ie-zero-day-010413>Researchers Bypass Microsoft Fixit for IE Zero Day</a>  :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27881394</guid>
<pubDate>Fri, 04 Jan 2013 18:55:19 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27880854</link>
<description><![CDATA[chachazz posted : <div class="bquote"><said>said by <a href="/profile/1537340" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1537340');">Smokey Bear</a>:</said><p>  <br>Thanks for posting the fix-it solution  chachazz <A HREF="/useremail/u/914341"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> however it seems that security firm Exodus Intelligence has managed to bypass the fix and compromise a fully-patched system...<br><br>Info here: &raquo;<A HREF="http://blog.exodusintel.com/2013/01/04/bypassing-microsofts-internet-explorer-0day-fix-it-patch-for-cve-2012-4792/" >blog.exodusintel.com/2013/01/04/&middot;&middot;&middot;12-4792/</A><br> </p></div> Absolutely essential info.  Thank you very much  Smokey Bear <A HREF="/useremail/u/1537340"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>. Microsoft should be burning the midnight oil over this one. <br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>After posting our analysis of the current 0day in Internet Explorer which was used in a &#8220;watering hole&#8221; style attack hosted on the Council for Foreign Relations website, we decided to take a look at the Fix It patch made available by Microsoft to address the vulnerability. <br><br>After less than a day of reverse engineering, we found that we were able to bypass the fix and compromise a fully-patched system with a variation of the exploit we developed earlier this week.<br><br>We have included details on the bypass to customers of our intelligence feeds and will notify Microsoft of the issue. In practice with coordinated vulnerability disclosure, we intend to update this post with details when Microsoft has addressed the problematic patch. <HR></BLOCKQUOTE>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27880854</guid>
<pubDate>Fri, 04 Jan 2013 16:05:20 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27880841</link>
<description><![CDATA[Smokey Bear posted :  <BLOCKQUOTE><SMALL>said by siljaline :</SMALL><HR>Some slight duplication of effort never hurt anybody. Better than no information &#149; <i>voila</i><HR></BLOCKQUOTE>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27880841</guid>
<pubDate>Fri, 04 Jan 2013 16:00:40 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27880809</link>
<description><![CDATA[siljaline posted : The <ahref="http://krebsonsecurity.com/2012/12/attackers-target-internet-explorer-zero-day-flaw/>Krebs Article</a> that  redwolfe_98 <A HREF="/useremail/u/408621"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> originally posted has the <ahref="http://support.microsoft.com/kb/2794220>FixIt</a>  :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27880809</guid>
<pubDate>Fri, 04 Jan 2013 15:49:04 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27880706</link>
<description><![CDATA[Smokey Bear posted :  <BLOCKQUOTE><SMALL>said by <a href="/profile/914341" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=914341');">chachazz</a>:</SMALL><HR><a href="http://technet.microsoft.com/en-us/security/advisory/2794220"><br>Microsoft Security Advisory (2794220)</a><br>Vulnerability in Internet Explorer Could Allow Remote Code Execution<br> | Updated: Monday, December 31, 2012 <br><br>Microsoft Fix it solution, "MSHTML Shim Workaround", that prevents exploitation of this issue<br><br>See <a href="<a href="http://support.microsoft.com/kb/2794220">Microsoft Knowledge Base Article 2794220</a> to use the automated Microsoft Fix it solution to enable or disable this workaround.<br><br>Here it is : <a href="http://support.microsoft.com/kb/2794220#FixItForMe">Fix it for me - FixIt Solution</a><br> <HR></BLOCKQUOTE><br>Thanks for posting the fix-it solution  chachazz <A HREF="/useremail/u/914341"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> however it seems that security firm Exodus Intelligence has managed to bypass the fix and compromise a fully-patched system...<br><br>Info here: &raquo;<A HREF="http://blog.exodusintel.com/2013/01/04/bypassing-microsofts-internet-explorer-0day-fix-it-patch-for-cve-2012-4792/" >blog.exodusintel.com/2013/01/04/&middot;&middot;&middot;12-4792/</A><br><small>--<br><i>&raquo;<A HREF="http://bit.ly/gUqYaH" >bit.ly/gUqYaH</A> - C. Brian Smith: Think of the exclamation point as a car horn: a little goes a long way. Lay on it too hard and everyone’s going to think you’re a moron.</i></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27880706</guid>
<pubDate>Fri, 04 Jan 2013 15:22:15 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27879685</link>
<description><![CDATA[therube posted : <A HREF="http://news.softpedia.com/news/Symantec-Finds-the-Hackers-Behind-Microsoft-s-Latest-Zero-Day-Flaw-318338.shtml" >Symantec Finds the Hackers Behind Microsoft&#146;s Latest Zero-Day Flaw</A><br><br><A HREF="http://news.softpedia.com/news/Microsoft-Won-t-Patch-Critical-IE-Flaw-on-Tuesday-318418.shtml" >Microsoft Won&#146;t Patch Critical IE Flaw on Tuesday</A><br><br>(This coming Tuesday, that is.)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27879685</guid>
<pubDate>Fri, 04 Jan 2013 10:58:28 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27878278</link>
<description><![CDATA[Oleg posted : <div class="bquote"><said>said by <a href="/profile/703015" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=703015');">siljaline</a>:</said><p><div class="bquote"><said>said by <a href="/profile/910278" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=910278');">Oleg</a>:</said><p>Microsoft did it again  :p<br> </p></div> Did <u>what</u> again or are you just poking fun  :p <br> </p></div>screwed up again, in security and stability field unlike other software development companies, like Mozilla,Opera in browser industry. Microsoft did not just have one or two stability or security issues.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27878278</guid>
<pubDate>Thu, 03 Jan 2013 19:57:56 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27878176</link>
<description><![CDATA[siljaline posted : <div class="bquote"><said>said by <a href="/profile/910278" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=910278');">Oleg</a>:</said><p>Microsoft did it again  :p<br> </p></div> Did <u>what</u> again or are you just poking fun  :p ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27878176</guid>
<pubDate>Thu, 03 Jan 2013 19:24:33 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27875635</link>
<description><![CDATA[Oleg posted : Microsoft did it again  :p]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27875635</guid>
<pubDate>Wed, 02 Jan 2013 23:53:04 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27875057</link>
<description><![CDATA[siljaline posted : Thanks for the link. IIRC, gadgets and sidebar are long gone by way of extenuating issues on both for a good while.<br><br>The exploit although there is a <ahref="http://support.microsoft.com/kb/2794220>FixIt</a>, the exploit is well explained <ahref="http://www.infosecurity-magazine.com/view/29996/exploited-0day-vulnerability-in-internet-explorer-discovered/><b>here</b></a>. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27875057</guid>
<pubDate>Wed, 02 Jan 2013 19:54:05 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27871962</link>
<description><![CDATA[Lagz posted : <div class="bquote"><said>said by <a href="/profile/703015" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=703015');">siljaline</a>:</said><p><small> Happy New Year </small><br>Define sidebar  :) Do you mean <ahref="http://support.microsoft.com/kb/2719662>Gadgets</a> <br> </p></div>&raquo;<A HREF="http://windows.microsoft.com/en-US/windows-vista/Windows-Sidebar-and-gadgets-overview" >windows.microsoft.com/en-US/wind&middot;&middot;&middot;overview</A><br><small>--<br>When somebody tells you nothing is impossible, ask him to dribble a football.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27871962</guid>
<pubDate>Tue, 01 Jan 2013 19:17:03 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27871895</link>
<description><![CDATA[siljaline posted : <small> Happy New Year </small><br>Define sidebar  :) Do you mean <ahref="http://support.microsoft.com/kb/2719662>Gadgets</a> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27871895</guid>
<pubDate>Tue, 01 Jan 2013 18:51:27 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27871616</link>
<description><![CDATA[Lagz posted : <div class="bquote"><said>said by <a href="/profile/161242" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=161242');">trparky</a>:</said><p>Oh shit, I think I know how this exploit may work.<br><br>There's an attack technique which is used to overwrite the Structured Exception Handler which would, in any other case, catch the Null Reference Exception and handle it cleanly so that the program would not appear to crash.<br><br>But in the case of this exploit, it would overwrite the Structured Exception Handler using either a Stack-based Buffer Overflow or Heap Spray attack.  Then, something would be used to trigger (a call to a null Object, in this case) the Exception Handler and since it's been overwritten with arbitrary code, the program would then be vulnerable to attack.<br><br>All of which EMET helps guard a program against.<br> </p></div>I wonder if flash or IE uses standard exception handlers or do they write their own? My instructor in C# told us to write our own exception handling when possible rather than throw standard exceptions, this might be why. When I was first introduced to exceptions I was like, HELL YEA I don't have to write as much code now. We had been writing our own exception handling up to that point. I wonder if they are just throwing standard exceptions if that's a result from laziness or management hurriedly wanting code pushed out the door?<br><small>--<br>When somebody tells you nothing is impossible, ask him to dribble a football.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27871616</guid>
<pubDate>Tue, 01 Jan 2013 16:19:56 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27870994</link>
<description><![CDATA[StuartMW posted : <div class="bquote"><said>said by <a href="/profile/1140294" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1140294');">Blackbird</a>:</said><p>...I finally took my Win98FE/KernelEx system off-line a couple of years ago (though I still run it at times as an isolated system for a few pieces of legacy software on it that I occasionally need).</p></div>You can probably <a href="http://technet.microsoft.com/en-us/sysinternals/ee656415.aspx">image it's HD(s)</a> and run it as a Virtual Machine (VM). Then you'd have an anchor for a (small) boat :D<br><br>I have a bunch of VM's, including some of old hardware, and use them from time to time.<br><br>The good thing about VM's is that their HD(s) are just (VHD) files. Easily backed up and copied if you want to try/test something without messing up the original. I quite often test things in VM's.<br><small>--<br>Don't feed trolls--it only makes them grow!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27870994</guid>
<pubDate>Tue, 01 Jan 2013 11:20:24 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27870898</link>
<description><![CDATA[Blackbird posted : <div class="bquote"><said>said by <a href="/profile/1075487" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1075487');">goalieskates</a>:</said><p>... If somebody doesn't want to go to a higher version browser and can live with Win98 or WinXP, more power to them.   </p></div>That is the challenge, though... living with them. In the case of Win98, not only can't one find secure browsers that will run under the OS, they can't even find current anti-malware software that will run. Nearly all of what one finds that will run (if they look really hard) is outdated ("vintage") and riddled with bugs or security holes. The only thing in one's favor is that the number of exploits targeting your OS is slowly declining - especially new zero-days. It's the main reason I finally took my Win98FE/KernelEx system off-line a couple of years ago (though I still run it at times as an isolated system for a few pieces of legacy software on it that I occasionally need).<br><small>--<br>&#147;The American Republic will endure until the day Congress discovers that it can bribe the public with the public's money.&#148; A. de Tocqueville</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27870898</guid>
<pubDate>Tue, 01 Jan 2013 10:23:13 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27870791</link>
<description><![CDATA[StuartMW posted : Win 3.1 and IE 3.01 forever! :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27870791</guid>
<pubDate>Tue, 01 Jan 2013 08:30:16 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27870789</link>
<description><![CDATA[goalieskates posted : <div class="bquote"><said>said by <a href="/profile/777093" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=777093');">Dustyn</a>:</said><p>People using Internet Explorer 9-10 are not impacted... So in this instance, newer is better. However, I'm only referencing this particular vulnerability. For Microsoft to also patch IE6 is a step backwards from their own abandon IE6 campaign.<br> </p></div>It is, but the whole campaign is silly anyway. As long as the newer versions of IE are up to snuff, it really doesn't matter what other people choose to run. More to the point, people who run IE6 haven't upgraded their Windows, either - which hurts revenue and is really what that's all about.<br><br>We went to the moon without benefit of IE and Windows. If somebody doesn't want to go to a higher version browser and can live with Win98 or WinXP, more power to them.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27870789</guid>
<pubDate>Tue, 01 Jan 2013 08:28:46 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27870079</link>
<description><![CDATA[Dustyn posted : <div class="bquote"><said>said by <a href="/profile/1075487" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1075487');">goalieskates</a>:</said><p><div class="bquote"><said>said by <a href="/profile/777093" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=777093');">Dustyn</a>:</said><p>Who the hell cares if IE6 is vulnerable?<br>Microsoft has to stop patching IE6 or people will continue to use it.<br>&raquo;<A HREF="http://www.ie6countdown.com/" >www.ie6countdown.com/</A><br> </p></div>And the newer versions aren't?<br> </p></div>People using Internet Explorer 9-10 are not impacted... So in this instance, newer is better. However, I'm only referencing this particular vulnerability. For Microsoft to also patch IE6 is a step backwards from their own abandon IE6 campaign.<br><small>--<br>Remember that cool hidden "<b>Graffiti Wall</b>" here on BBR? After the name change I became the "owner", so to speak as it became: <A HREF="http://www.dslreports.com/forum/wall"><b>Dustyn's Wall</b></a> &raquo;<A HREF="/forum/remark,19180829">[Serious] RIP</A><br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27870079</guid>
<pubDate>Mon, 31 Dec 2012 20:28:14 EDT</pubDate>
</item>

<item>
<title>Re: IE Zero-Day</title>
<link>http://www.dslreports.com/forum/Re-IE-ZeroDay-27870065</link>
<description><![CDATA[Sindows 7 posted : <div class="bquote"><said>said by <a href="/profile/703015" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=703015');">siljaline</a>:</said><p>MS FixIt available at this MS KB. <br>&raquo;<A HREF="http://support.microsoft.com/kb/2794220" >support.microsoft.com/kb/2794220</A><br> </p></div>I'm surprised it didn't say to disable Internet Explorer along with the Sidebar.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-IE-ZeroDay-27870065</guid>
<pubDate>Mon, 31 Dec 2012 20:21:37 EDT</pubDate>
</item>

</channel>
</rss>
