Slashdot Log In
Zero-Day IE Exploit In the Wild
Posted by
kdawson
on Mon Sep 18, 2006 09:26 PM
from the now-delivering-spyware-to-a-pc-near-you dept.
from the now-delivering-spyware-to-a-pc-near-you dept.
Eric Sites writes to tell us that a new zero-day IE exploit has been found in the wild. It looks to be a bug in VML in IE. The Sunbelt blog notes, "This exploit can be mitigated by turning off Javascripting."
Related Stories
[+]
Zero-Day Team Launches with Emergency IE Patch 157 comments
Holy Mother of Thor writes to mention an eWeek article about a third-party patch for Internet Explorer. A dark horse security group formed after the WMF attacks in late 2005, the ZERT (Zero Day Emergency Response Team) has released a patch to attempt to slow the malware attacks on Windows. From the article: "'It is clear that we are dealing with an underground group of people who are writing exploits for profits. They are waiting for Patch Tuesday to pass, then it becomes Exploit Wednesday. We're seeing these zero-days in the wild, timed precisely to guarantee at least an entire month to spread,' Stewart said in an interview with eWEEK. Stewart, who is volunteering his reverse-engineering skills and time to ZERT in his private capacity, wrote an early version of the VML (Vector Markup Language) patch the group released Sept. 22 and worked closely with others to fine-tune the update to minimize potential glitches."
[+]
IT: Microsoft Patches VML Vulnerability 130 comments
Uncle Rummy writes, "Microsoft has quietly released an official patch for the zero-day VML vulnerability. The patch was publicly available yesterday, But Microsoft has just added it to the Security Bulletin Index." Eight days from time of first report to patch is pretty fast for Microsoft, and is almost two weeks ahead of their normal patch schedule. This security flaw was being aggressively exploited out in the wild.
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
Whatever (Score:2, Funny)
Re:The power of Open Source (Score:5, Informative)
-uso.
Parent
Sorry, has to be done... (Score:5, Funny)
Re: (Score:2)
Zonk? Are you kidding me? (Score:3, Interesting)
Re: (Score:3, Insightful)
Wow, nice resolution! (Score:2)
I'm certain that most Internet Explorer users don't write JavaScript.
No surprise (Score:5, Insightful)
Re: (Score:2)
They could just adopt Firefox if they wanted to, but they won't because it's Not Invented Here.
Re: (Score:3, Interesting)
This is not necessarily a smart idea.
If you simply start afresh, chances are that you're going to end up with all the same exploits all over again.
They either need to do a full security audit of the code (unlikley for microsoft), or they need to start afresh *and* write it in a language/toolkit that is impossible/much hard
Re: (Score:3, Interesting)
I don't think that's true any more. This time it would be reasonable for Microsoft to rewrite their browser in C#.Net, which theoretically provides the kind of sandboxing protection that prevents buffer overflows.
But would that address evil Java/J/Ecma Scripts? Image file exploits? Any of the vulnerabilities that are actually rooted in the Win32 APIs and the NT kernel?
easier solution (Score:5, Insightful)
It can also be mitigated by using firefox.
Re: (Score:3, Funny)
Screw that! I'm going back to "telnet www.google.com 80"
And I'll do that within a VMware image running from a Live CD.
Re: (Score:2, Interesting)
I suppose now is as good a time as any to ask a question.
I still use IE as my default browser, simply because it loads *fast*. I don't have a brand new system, but when I click the little blue E, I have a browser window inside 2-3 seconds. When I click the little orange fox it often takes up to 8-10 seconds before the window has opened and loaded. I use 'about:blank' for the homepage in both browsers.
Are there any ways to reduce the time to load firefox? I'd even be fine with starting Fir
Re: (Score:2)
Re: (Score:2)
There is a folder in your Start Menu labelled "Startup" (or something similar). Drag a copy of the Firefox shortcut into that folder. It will now load when windows loads. Don't close it.
If you're worried about taskbar pollution... well, you're using the wrong OS. (Or the wrong window manager, anyhow, but my experience is that certain basic assumptions about how Windows works are so deeply embedded into the Windows en
Re:easier solution (Score:5, Informative)
The Firefox Tweak Guide [tweakfactor.com] has many options for about:config and other tips for improving your specific experience.
Firefox Preloader [sourceforge.net] will make Firefox load more quickly by making Firefox do the same thing Internet Explorer does. Firefox will use system resources before being specifically called. The application will remain resident in memory like IE does, waiting for you to click the little fox. In this way, IE loads faster but slows overall system performance.
How to use UPX to speed it up a little [techsupportalert.com] is what this article can tell you. Probably not the best way to go about it, but I have implemented this method on my HTPC.
It is VERY important to realize that the few seconds you wait around for the initial loading of Firefox are quickly surpassed by the lag you experience while using Microsoft's Explorer. Firefox ignores many advertisements right off the showroom floor, but can be configured to show NEARLY NO ADS AT ALL. FlashBlock, [mozilla.org] AdBlock, [mozilla.org] and NoScript [mozilla.org] will make your browsing much faster and cleaner.
Using Firefox, especially with these and other add-ons, will make your browsing incredibly secure. Explorer is left in the dust in comparison.
So the trade-off you seem to have made is this: A few seconds at load time in exhange for a combined several minutes waiting for ads to be displayed, just so you can fall victim to the shiny! new! IE exploit that seems to get barfed all over Slashdot once a week. This while using an underdeveloped, overpriced, practically featureless browser that has no database of expansions. Unless you are using the Vista beta (7 beta) you aren't even using tabs! Do you choose to commut on a horse? HOW DID YOU EVER SURVIVE THE PERMIAN MASS EXTINCTION? [wikipedia.org] BAH! Why did I bother?
Parent
Re:easier solution (Score:5, Informative)
The behavior now is a little confusing... the first time you click the shortcut, it will not open a window. Instead, it will make a Firefox icon appear in the tray. This confuses the holy fuck out of my wife (rightfully). However, subsequent clicks on the icon will give you instant Firefox. To make it cleaner, you can put a copy of the shortcut in your Startup folder. I don't do this because I hate startup programs :)
Parent
Re:easier solution (Score:5, Informative)
There is a utility [sourceforge.net] which will allow you to also preload Firefox in memory on Windows. Of course, this does not give you the ability to unload IE from memory (decoupling IE from Windows, to any degree, is problematic at best).
Of course, how much an extra 6-7 seconds of load time will impact you would depend on usage. Personally I often leave the same instance of Firefox running for days at a time and leave it minimized on a virtual desktop when it is not in use, but if I were really worried about this on a Linux box then I would use prelink [gentoo.org].
Parent
Let's help users move away from IE. (Score:3, Insightful)
It's rare these days to find a public site that depends only on IE. Most banking sites, which were really the only holdovers, have realized that Firefox support is necessary.
The only reason I can think of is ignorance. But even then, most people likely know somebody who could help them install Firefox or Opera for the first time. Maybe each one of us should pledge to tell one other person who isn't aware of the alternatives about them. Make a pact with that person: if they are pleased with their new browser, or it keeps their Windows system free of malware, have them tell one new person about Firefox or Opera.
Very rapidly, many people will be able to find out about the alternatives, and it'll benefit us all. Us geeks won't have to help relatives and friends with their malware-infested systems. Those users won't have to ask us to help them, or in the worst case, call the Geek Squad or otherwise bring theirs systems in for expensive and inconvenient "decontaminations" (often performed by fools). Plus the private data of those users is far more safe. In short, we all benefit.
Re: (Score:2)
I've tried to switch users from IE to FF. It's been more successful with the ex-Netscape users, 'cause I can sell it and T-bird as a direct upgrade. Some people need Outhouse's calendaring features, and some people just can't cope with certain webshites not being compatible with FF, and other people just think tha
Re:Let's help users move away from IE. (Score:4, Insightful)
People start with IE because it's the Windows default.
People stay with IE either becasue:
If they don't care, why should we? It's their computer that they're leaving vulnerable, after all. Besides, Firefox is starting to lose it's most difinitive advantage over IE - as it's popularity is increasing, so is the number of security vulnerabilities found, rivaling and even surpassing IE month to month.
Any differences in "speed" are pretty much a wash, too. Internet Explorer definitely starts faster, but it's integrated with the shell. Firefox uses an ungodly amount of memory and leaks it like a sieve. IE7 waits until it has the page 99% rendered before actually drawing it; Firefox will start drawing immediately, piece-by-piece as the site's downloaded. (Both, in total, seem to take the same amount of time.) ActiveX is known for being full of holes, but at least they try to sandbox it - Firefox extentions just blindly run native code.
Point is that as the differences between the browsers are diminishing - Firefox has forced IE to innovate and comply with standards and more and more pages are designed for Firefox and non-IE browsers. But, the security differences between the two are diminishing, and IE7s interface is cleaner and snappier now, IMHO.
Save the digivangelism for something more important than "Firefox isn't Microsoft." In Vista especially, IE is next to bulletproof - a reworked Windows kernel runs it within a virtual machine of sorts - and IE+Aero Glass has a much cleaner and prettyfuler interface. Use your browser of choice, but with alternatives and a little healthy competition forcing some new life into the browser world, there's fewer reasons to pick one over the other.
Parent
Re:Let's help users move away from IE. (Score:5, Insightful)
why should we get our friends to fix the brakes on their, car? afterall, it's their car, right?
Parent
I *only* use IE to run Javascript and ActiveX (Score:5, Interesting)
If I *didn't* need to be doing something dangerous and stupid, I'd be using some version of Mozilla instead of IE. Sigh.
Yes, I know IE has its security zone thingies that give me a way to restrict it, but it's still annoying.
Moo (Score:5, Funny)
Posted by Chacham [slashdot.org] on 10:45 PM -- Monday September 18 2006
from the zero-day-is-overused dept.
[ Slashdot ] [ Teenagers ] [ Slow News Day ]
Chacham [slashdot.org] writes to tell us that an old zero-day Slashdot [slashdot.org] exploit has been found again and again and again. It looks to be a bug in all browsers. This comment notes, "The bug is in the Submit Story [slashdot.org] link, which is apparently easy available in the side bar."
No patch has been released. Story posters are standing by.
IE expliots (Score:2)
IE on VM (Score:3, Informative)
It seems like we're getting to a point where probably the only safe way to be surfing is by using a browser on a sandboxed virtual machine environment.
I'm not trying to point my finger only at Internet Explorer, but with security holes that can allow code execution, that's pretty scary. (And another case of buffer overrun? Maybe they ought to rewrite IE as managed code [microsoft.com], but that's another topic all together.)
IE7? (Score:2)
My two cents... (Score:3, Informative)
Re:My two cents... (Score:4, Insightful)
What you propose would require people to add the likes of Slashdot and Hotmail to the 'Trusted Sites' zone to function correctly. This effectively gives such sites far more access than you would probably like, much more than without playing with your 'zones' at all.
thats a daft proposal.
Parent
Re:My two cents... (Score:4, Informative)
Slashdot, no. Slashdot works fine without Javascript.
You don't have to pour a bunch of sites into the Trusted sites category. Only the ones that you are positive are safe and constantly use that REQUIRE javascript.
Parent
No need to worry! (Score:5, Funny)
Oh, okay... (Score:5, Interesting)
One acronym: AJAX.
Looking at a variety of server logs for websites I'm currently in charge of, I see that Internet Explorer, even among the "geek" crowd, still has a very strong foothold in the browser market. I've worked closely with customers of my own and even after explaining the threat to them, they continue to use IE.
Thanks to Web2.0 (and various other forms of propganda), Asynchronous JavaScript and XML (AJAX) has all but taken over the Internet. Now, with a bug such as this, the AJAX-driven sites are in trouble (assuming every IE user does turn off JS).
I'm not about to start a "Browser War" with this entry, but I have to say; IE is a very volitile threat, and an Open Source replacement would more than benefit the well-being of the Internet as we know it. Pick your poison - Firefox, Mozilla, Opera, Lynx, wget - they're all superior to IE in the sense that they are not an integral portion of the operating system, thus they pose less risk to the security of said OS.
Rather than disable JavaScript in every IE install in the world, take the time to replace IE with something far less dangerous and educate the user on the dangers of using IE over the replacement.
Re:Oh, okay... (Score:4, Funny)
Dude, you must be one master coder - you've got an AJAX framework that will work with wget?
Parent
Safe browsing (Score:3, Interesting)
"mitigated by turning off Javascripting..." (Score:3, Informative)
Why do people even bother to give advice that is basically impossible to follow?
It's not my fault that so many of the websites I want to use now rely on Javascript, but the fact is they do.
Saying "This exploit can be mitigated by turning off Javascripting" is true, but as about as useful as saying "the risks of plane crashes can be mitigated by not flying."
"This exploit can be mitigated by turning off Java (Score:3, Funny)
. . . and you can avoid >99% of car accidents by not turning on the engine, but then the car isn't very useful, is it.
Re: (Score:3, Insightful)
No, you need to blame Javascript too. (Score:5, Informative)
Javascript was designed to be lightweight, friendly, and convenient, and almost anything related to security was later bandaids applied to the gaping wounds. It's possible and easy to write perfectly safe Javascript, but that's unfortunately totally irrelevant because it's possible to write Evil Javascript as well - so anybody who wants to run your "Safe" Javascript has to leave Javascript turned on for the Evil Javascripters as well.
IE does theoretically have a "security zone" mechanism that lets you identify trusted sites, so you can theoretically allow it to run purportedly-safe Javascript from people you trust while not running it from people you don't trust, but that's an annoying hassle. It'd be much safer if they'd built "WimpyScript", designed to be absolutely safe even if all it lets you do is make stuff flash decoratively when you wave a mouse at it; I guess CSS is as close as we get to that. PDF used to be safe, back when all it would do would be display static black or colored marks on virtual paper, but now it's helpfully willing to open web pages and run programs on your PC too.
Parent
Re:No, you need to blame Javascript too. (Score:4, Insightful)
Parent
Re: (Score:3, Insightful)
They wouldn't have been damned if they didn't, they just would have had to compete on merits instead of pushing product.
ActiveX is what really kicked Netscapes ass because that is what the masses liked, not IE's implementation of JS.
Re:No, you need to blame Javascript too. (Score:5, Insightful)
Uh, no, what "kicked Netscape's ass" is that
In a word, what killed netscape is that MSIE was, at the time, a much better browser than Navigator
Parent
Re: (Score:3, Insightful)
There is no such thing as "100% secure".
Re:No, you need to blame Javascript too. (Score:4, Funny)
http://old.zone-h.org/advisories/read/id=8276 [zone-h.org]
https://rhn.redhat.com/errata/RHSA-2003-029.html [redhat.com]
I'd suggest telnet to port 80, typing in GET commands, and reading the HTML. But then someone would embed the nam-shub of Enki [wikipedia.org] and you'd be even worse off.
Parent
Re: (Score:2)
Re: (Score:3, Funny)
$ telnet slashdot.org 80
Trying 66.35.250.150...
Connected to slashdot.org.
Escape character is '^]'.
GET / HTTP/1.1
Host: slashdot.org
User-agent: none
It even makes it easier to read the Futurama quotes in the headers!
Re:Two browsers... (Score:4, Funny)
Parent
Re:You know... (Score:4, Informative)
Parent
Re:I thought ... (Score:5, Informative)
In exploit terms, n-day means the number of days after a fix is released for the problem exploited by the attack. Most notable worms of the past have been n >= 1 (often much more) attacks - either someone deduces the flaw based on the patch release or the flaw was already known but only guardedly used in order to do high level target attacks while it was still unknown to the public.
Zero day refers to attacks that are released before the flaw is publically known. It's based on the specific flaw, not the application in general. Zero day attacks are nasty on two fronts - first, no one has specific protection or detection available for it, second, as mentioned, they are sometimes used on very specific targets. There was a recent string of what appears to be industrial espionage where very specific people have been sent MS Office attachments with previously unknown exploits in them.
Parent
Re:Why disable javascript? Change to firefox ... (Score:5, Informative)
Parent