Microsoft To Ship Emergency IE Patch 187
Grotendo writes "Microsoft plans to release an emergency patch for Internet Explorer very soon to counter targeted attacks and the publication of exploit code for a 'browse and you're owned' vulnerability in its flagship Web browser. The out-of-band update will be released once the company is satisfied that it has been properly tested against all affected versions of Windows. This could happen as early as this weekend." Microsoft has downplayed the seriousness of the IE zero-day, and insisted that it affects only IE6 even as security researchers close in on exploits for IE7 and IE8. Microsoft has had no comment about the firestorm that Google unleashed by directly accusing the Chinese of cyber espionage. ShadowServer has up a sobering post on the massive extent of the problem of "groups that can be referred to as the Advanced Persistent Threat."
Enough is enough! (Score:5, Informative)
Re:Enough is enough! (Score:5, Funny)
Why not just exploit their browser's security flaws and wipe their hard drive?
That way they learn their lesson about safe browsing the old fashioned way.
Re: (Score:2)
Sorry, but I need them alive! Muhahahahahahahh! Nom Nom Nom Nom!
Re:Enough is enough! (Score:5, Funny)
Pro
Cons
Counter proposal: have you tried carpet bombing a small third world country today?
Re:Enough is enough! (Score:4, Funny)
Re: (Score:2)
Re: (Score:2)
Re: (Score:2, Interesting)
Re:Enough is enough! (Score:4, Informative)
No. Chrome frame is only active if a page specifically codes for it [google.com]. Otherwise, it does nothing. An attack page would not typically include code for a workaround.
Re: (Score:2)
If you got more free CPU power than all super-computers combined, you would just throw that away?
I don’t think so... ^^
I’d go straight to cracking every important security code on the planet. Federal reserve, CIA, every intelligence agency of every important country, every military lab, every weapons remote control (especially for nukes). And then I’d start making one single demand. One that would be impossible to undo, and would change the world forever.
Meet it or you’re done.
Pff, y
Re: (Score:2)
Why not just exploit their browser's security flaws and wipe their hard drive?
That way they learn their lesson about safe browsing the old fashioned way.
Because I like my asshole at it's current diameter, and I fear that blatantly violating the law could soon be followed by someone blatantly violating said asshole...
/c echo %time% %date% >> c:\\ExecBlock
What I do is go to every machine I am asked to look at and I add this reg key (with owners permission):
_______________________________
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe] "Debugger"="cmd.exe
Re: (Score:2, Troll)
I'm uploading the IE6 No More code to my website now. There's a point where users of outdated software need to be told there's four major cost-free options, including a much updated version of IE if they want to stick with IE.
Five.
It's missing Opera, which globally has more users than Chrome, for example, and wtfpwns both IE and Firefox combined market share in certain countries. In most European countries, Opera has more users than Safari and Chrome.
While the concept is neat, the choices aren't, and they are both offensive and ignorant.
Re: (Score:2)
By "globally" do you mean "in your head"?
According to marketshare.hitslink.com, as of December 2009 Safari had 2.4% of the browser market share. Chrome had 4.63%
Over at gs.statcounter.com, as of January 10, 2010 Opera had 1.98% and Chrome had 5.88%.
Flawed stats (Score:2)
Opera is on the Wii, DS and of course many a mobile phone whose own browser sucks, but often with a fake user_agent string.
Re: (Score:2)
By "globally" do you mean "in your head"?
No, I mean "globally".
See this for an example: http://my.opera.com/haavard/blog/2010/01/02/odd-browser-stats [opera.com]
Google *themselves* claim 40 million Chrome users. Opera Mini alone has more users than Chrome, not to mention the desktop version. And yet Chrome is represented by having ten times Opera Mini's market share according to those stats sites. Right...
There's also this http://my.opera.com/dstorey/blog/2009/03/16/a-look-at-desktop-market-share-cis-edition [opera.com] this http://my.opera.com/dstorey/blog/2009/03/16/de [opera.com]
Re: (Score:2)
I love you in a completely platonic fashion.
Re: (Score:2)
Platonic? What new form of deviancy is this? Next, we'll be hearing of platonic rights, and platonic marriages, and platonic tax deductions! There should be a law!
BTW - to all you virgins out there: THANKS FOR NOTHING!!
Re: (Score:2)
Re: (Score:3, Funny)
Oh, an Opera website says it's widely used on in the former Yugoslavia!
Tell you what: Find some market share data not on an Opera website and we can talk.
What's really funny is, if you click on the first link in the story on the Opera website, do you know what it links to? (wait for it...)
That's right, the first link in the Opera article about how they have more users than Chrome links to the market share data that I sited above, which shows Chrome at more than twice Opera's market share.
In fact, the story
Re: (Score:3, Interesting)
I'm running similar code on my site, and yet many of the "visitors" are still using IE6. I suspect most of those are bots, because of the traffic pattern looking for Registration and Forum pieces.
It is sad when you can spot a bot by the UserAgent.
Re: (Score:2)
Considering how many single purpose devices I work on that still use IBM/MS DOS 3.3 I suspect IE6 will be dominant until corporations are forced to migrate to Win7/8. Big companies are spending their money on things that make them MORE money. Upgrading to IE 7/8 is NOT free and since IE6 "works" in the eyes of the boss there is no "need" to upgrade. I'm not aware of an enterprise deployment feature for FireFox or Chrome. I believe Opera may have one but I don't think it is free. Since XP and IE6 for the maj
Re: (Score:2)
That's a very good point. And all corporations will tell you that the only surfing you should be doing should be work related, so if you follow that rule, your chances of getting owned even on IE6 are pretty low.
Now I'm posting to slashdot during work hours, and I'm not even an IT guy, so you can see how followed that policy is. At least I'm on firefox.
Sheldon
Re: (Score:2)
Re: (Score:2)
You must have a lot of pull or have a competent PHB.
Most places that start to consider FF stop when they find out there is no MSI *created by* the makers of FF.
You can get GPOs and pre-built MSI for FF but again, NOT by the makers of FF.
But this will soon be moot.
When Google *does* release an MSI for Chrome, FF will not be able to get into Corps because by then it will be too late.
Wake-up Mozilla!
Re: (Score:2)
You do realize you can make your own msi's right?
Very easy, there is even free software to do it.
Re: (Score:2)
Re: (Score:3, Informative)
I'm sure corporate users who have IE6 forced upon them will appreciate it if they try to view your site.
I'm sure your response would be "well they can bring it up with their IT depar
Re: (Score:2)
That is no longer a valid excuse. The cost of upgrading to apps that support a recent version of IE should be significantly less then the cost of cleaning up after IE6.
Of course their not going to do it until it bites them in the ass over and over, which is why I am happy every time I see an IE6 user get exploited. I've spent the last year of my life re-writing applications to be browser neutral for my job, so at least some companies are getting it.
Re: (Score:2)
Tell that to YouTube.
Thankfully, next-gen webapps are going to be the death of IE6 because in another year nothing is going to support it anymore. IE7 will die at a much faster pace.
Re: (Score:2)
I don't know anyone else who uses IE and hasn't upgraded to IE8.
Re: (Score:2)
I don't know anyone else who uses IE and hasn't upgraded to IE8.
I know several companies and some university departments. IE6 intranet applications are the dumbest thing in the world, but the "If it ain't broke don't fix it" mantra doesn't consider security when gauging levels of "broke", only whether the intended purpose still works, and that's a business decision, not Infosec/IT decision.
Re: (Score:2)
Yup, my company has had to spend some cash on developers to upgrade various web apps that only work with IE6. We were warning them about this in 2007 but it took transitioning to Vista and IE7 to finally get them to cut loose with the $$$. Silly management.
Re: (Score:3, Informative)
"If it ain't broke don't fix it"
Correct. And, it's time to make the decision makers understand that it's broken. If it isn't broken enough to convince them, then LET'S BREAK IT MORE!!
Most of the rest of what I read here today is just so much whining and sniveling, from one side or the other.
Re: (Score:2)
We are looking to migrate to IE8 in the next 3 months actually. We are currently on IE7. All of our applications work in any browser now. The only main issue is testing that the IE8 push won't break any workstations.
Hindsight (Score:2)
Re: (Score:2)
If Google started saying "You can't search until you upgrade!" they'd get the clue rather quickly. Google has reason to kill off IE6... it was the weapon used to attack them in China. Your IT desk likely uses Google multiple times a day... so a Google outage would get attention rather quickly.
Re: (Score:2)
No Save IE6! It keeps us employed!
http://www.saveie6.com/ [saveie6.com]
Re: (Score:2)
I'm using IE6 right now, you insensitve clod.
Why, you ask, is an Electrical Engineer -- one who reads /., has acted as a sys admin for two start-ups, uses Linux at home (and Puppy for the kids, that's right, my 6-year-old uses Linux) and has over 25 years of programming and networking experience)-- using IE6, a browser that MS itself has said, "oh god, please ditch it"?
Because I'm at work and some of the legacy applications here require it.
Have you got a solution? I'd love to hear it because I'd get a big f
Re: (Score:2)
What's the app and why does it insist on IE6? Can it be tested on one IE8 virtual machine? If the app vendor was still around they most likely would love to sell an upgrade...
Re: (Score:2)
How about you gauge the cost of a security breach that will eventually happen against the cost of not using legacy applications.
Re: (Score:2)
Using IE6 for that app, other browser for all the rest. Unless you're prohibited from running another browser; then having sites lock IE6 off can accelerate the transition, so they're helping you in the long run.
Re: (Score:2)
I don't have admin rights and USB devices are restricted.
I had to get permission to plug in a USB-charged bike light.
Quoth the TFA (Score:3, Informative)
targeted attacks and the publication of exploit code for a 'browse and you're owned' vulnerability in its flagship Web browser
IE 6 hasn't been Microsoft's flagship browser for 4 years.
Re: (Score:2)
Re: (Score:2, Insightful)
Yep, and it's almost wrong to be asking Microsoft to patch something as old as IE6 or XP at this point. Maybe OS licenses should say "You may use this program for 5 years." instead of perpetually because you're a danger to other people's systems when you don't update to modern software.
Maybe not, but when you work at a hospital in the IT department and your patient critical applications are still relying on IE6 because the vendor who wrote it sucks and can't figure out how to make it work with an updated browser, you appreciate that Microsoft, however insistant they are on dropping that old clunker of an app, is at least trying to resolve it.
Re: (Score:2)
Do you mind sharing the name of the hospital so I can tell the ambulance driver where not to go the next time I choke on a cheesy poof?
If they're using IE6 for "critical patient apps" there's probably a good chance that they'll try to cure my blocked windpipe by putting leeches on me or trepanning me or something.
Re: (Score:2)
While your point is made and understood, there are actually a few studies showing that both leeches and trepanning (or a modern day equivalent) have some valid therapeutic uses. No, I'm not going to bother with a cite as they're from some medical journals (dead tree, father is a traditionalist) which are at home.
Re: (Score:3, Informative)
I'm sure they could get out of the contract at an unnecessary cost. MS made this mess and unfortunately we're stuck with it for awhile longer. Hopefully once the extended support is over then companies will start dumping their old stuff and upgrading.
In my opinion this shouldn't matter to mos
Re: (Score:2)
Re: (Score:2)
I am using XP and I "almost" feel guilty after reading your post.
Crap (Score:2)
Only a complete M$ dummy would pull that naive crap, there are SunOS 4 systems still running reliably in server rooms.
I just despair at your credulousness and stupidity.
Re: (Score:3, Informative)
it does, however, share the same vuln with IE7 and IE8. So maybe it's more appropriate as "microsoft's web browser" (irrespective of version) is at fault.
Re: (Score:2, Informative)
Re: (Score:2)
To be fair, IE6 can’t be defined as a browser for 4 years anyway. ;)
Re: (Score:2)
I'd say IE 8 is a different beast on the same underlying engine, like a game running on the UT III engine is different than UT III. 7, though, is just 6 with a facelift.
Countering attacks? (Score:4, Interesting)
Microsoft is not "countering the targeted attacks".
Unless of course the German and France CERT teams recommendation to ditch IE is considered one.
I have the patch details: (Score:5, Funny)
Bravo Microsoft!
Re: (Score:2)
Typical Microsoft patch. It side steps the real issue: not having Noscript pre-installed too.
Re: (Score:3, Funny)
It also sets the DNS to itself and caches anything you might have had saved in your browser history.
That way, you still seemingly visit the same sites you always do, just they never get updated, and you are completely secure from everything on the net!
IE is only good at one thing... (Score:3, Insightful)
And that is running Windows Update and it isn't that good at doing that....
Re:IE is only good at one thing... (Score:4, Interesting)
The sound of Windows update running is drilled into my mind forever.. Click.. click click click.. click. click.. click click click click click.
My mind constantly asking "what the.. i haven't clicked a damned thing"
Re: (Score:3, Insightful)
All I know is that three certain windows updates have been drilled into my Vista boot process for ever. Did someone really intentionally program an update process so that if it failed it would just try again?
Re: (Score:2)
Yes, there is. If you have a capped internet connection, downloading 100MB of updates can be annoying, but you allow it. Then you return and find out it actually consumed 300MB and it still failed to install it.
I want it to ask me before retrying!
Re: (Score:2)
Re: (Score:3, Interesting)
How many people on slashdot still run XP to avoid the bloat of Vista/7.
Quite a few I would imagine....
Re: (Score:2)
Windows 7 is actually almost as fast as XP. That's really good accounting for the numerous improvements made to the OS in the intervening 9 years. Almost every new software release requires better hardware, including Gnome and KDE.
Re: (Score:3, Insightful)
Re: (Score:2)
Read my post again. Improvements like better UI, better security, more features etc. etc. need faster hardware.
Re: (Score:2)
It depends on your definition of "better". If "better" UI is flashier, yes, it does.
And security? Really? Why would you need faster hardware for that? Oh, and don't tell me "better encryption", even my P3 can handle that.
Re: (Score:2)
Err did you fail Reasoning 101? You forget all the new features, UI and security in Windows 7 compared to Windows XP which take up lots of resources. It's the same case with almost any other software, as hardware becomes more powerful, more features are added. If you want ultimate speed, go run Windows 95 or DOS 6.22 or Windows 3.1 on modern hardware, but dont' complain when USB ports don't work.
Re: (Score:2)
Psh I don't need a video out. That's just more bloat!
Re: (Score:2)
Re: (Score:2)
And how many on slashdot are stuck with XP SP1 because SP2 causes too many problems? Of course, this means they're stuck with IE6 I believe (as opposed to upgrading to IE7 and IE8).
But, I think the key lesson is here... why don't we have ActiveX controls and Active Scripting disabled by default? IE is so popular, it is targetted. When FireFox takes IE's place as leading web browser of the world, what do you think will happen? (Maybe not to the same extent as IE.)
The Most Popular Meme (Score:2)
1. There are 3,500 Windoze api calls, POSIX < 200, Linux ~ 250, new functionality over 10 years,
2. Windoze will execute any crap base on ".ext" so it will just execute "
Re: (Score:3, Informative)
Shh, don't tell anyone...
>wuauclt /detectnow
Forces the update.exe agent to check.
Re: (Score:2)
I really enjoy that in Vista and 7, Windows Update is a standalone app. I don't have to fire up IE to grab updates.
Re: (Score:2)
You clearly haven't used IE in years, or you are just trolling. IE8 handles tabs much better than Chrome or Firefox, and unlike firefox IE is sandboxed (this exploit doesn't affect ie8 in win7), to get similar functionality in firefox you have to install noscript and individually handle every single new website you go to. The problem with IE isn't its compliance to standards or acid tests (no one cares except web developers) it is that its snail slow. The UI is atrocious but firefox really isn't any better
Re: (Score:3, Insightful)
Re: (Score:2)
Wow, big surprise, security company creates an exploit for money. That doesn't change the fact that the current 0 day doesn't affect IE8 on windows 7. Exploits are found and patched all the time in firefox, safari, and chrome. Hell in the Pwn2Own contests safari is always first to be cracked, Chrome currently has an unpatched critical vulnerability (secunia), and firefox actually has been doing quite well but still really requires noscript to be safe which cripples browsing the internet.
Ignorent Fanboi/Astroturfer (Score:2)
2. You only need a sandbox if you have open wounds, IE6 or are Immune Compromised that ie: Windoze* IE*,
3. You don't need NoScript,
4. ACID is a database test, and has nothing to do with HTML compliance, your ass and ignorance is showing!
5. We do care about HTML compliance and a commitment to inter-operate properly since it reduces complexity and simplifies testing, both of which cost a lot of money.
Isn't it time you moved out of your mother's basement?
Re: (Score:2)
Re: (Score:2)
But only in a frame, inside Firefox [mozilla.org]. (Just disable the cookie transfer feature. That’s a really stupid idea.)
Re: (Score:2)
This is something I've never really understood. What is the rationale, if any, for making it so that the web browser updates the system? If you uninstall IE, can you still update your system?
Comment removed (Score:3, Informative)
The IE Patch (Score:5, Funny)
Do you find yourself mysteriously waking up in a back alley more than once a week?
Do you find empty HTML pages littering your desktop and you have no idea where they came from?
Do you discover new directories on your computer?
Get the IE Patch!
It comes in 4 strengths so you can be gradually weaned from the habit.
Week 1. IE 6 Patch. Internet cravings are pretty intense the first week so the IE 6 Patch is there to help you learn how to just say "NO".
Week 2. IE 7 Patch. It's easier to avoid launching IE. You still need to check Amazon or e-Bay from time to time but the edge has been honed down a bit.
Week 3. IE 8 Patch. You find it a lot easier to avoid clicking on the 'e' although you still lapse when you aren't thinking.
Week 4. Firefox. You've mastered the addiction. You're free to browse the Internet worry free. Even looking at the 'e' makes you nauseous.
Congratulations on taking the first step to breaking the IE addiction.
[John]
So glad (Score:2)
Re: (Score:2)
To little to late (Score:2)
And what's going to happen to all those "IE only" web sites the government, public schools and other agencies like to use?
Re: (Score:2)
Also, what about all of us that can't use anything other than IE6 because that's the latest version that Windows98 supports?
Re: (Score:2)
WHy are you using Windows 95? Get a linux variant. (did I miss the joke?)
Re: (Score:2)
And what's going to happen to all those "IE only" web sites the government, public schools and other agencies like to use?
They'll still exist, but the error page might get changed to:
"This page is IE only. Type '?browser=firefox' at the end of the URL to be automatically moved to the non-IE page. Safari users type '?browser=firefox' too. There are no other browsers *Jedi hand wave*."
Re: (Score:2)
"Emergency" reaction (Score:2, Informative)
"Could be here as soon as this weekend", which is still more than a week from the exploit being published. That's swell.
Anyone else grateful MSFT doesn't run the fire department?
So that's what it takes to get a patch out, MS? (Score:4, Funny)
At least two governments officially stating to avoid IE, others in fear, every single web developer on the country hating you, Google getting hacked, and every security expert on the planet laughing at you?
Wow. Just wow.
May I extrapolate from that, what it would take, to get a real Bugzilla for IE and make it follow recent standards?
My guess: Inter-dimensional time war with Lovecraft’s the old ones, lead by Cthulhu, fighting the Shrike and its army, armed with gamma ray bursts and black holes, using giant stars as ammunition.
On the other hand: That would be awesome!
I like these "Your browser is out of date" sites (Score:3, Interesting)
You're training them to download stuff from the web, from sites they don't regularly visit / don't trust, because a popup told them to.
Well done.
Re: (Score:2)
Yep... Microsoft will never shut down or not censor bing.cn [slashdot.org]... er, wait a second!
Re: (Score:2)
Ten points, m'lad, for Non Sequitur of the Day!!!
Re: (Score:3, Informative)
Re: (Score:2)
I think you might gotten trolled. But I'm not entirely sure. But yes, GMail is now SSL by default.
Re: (Score:2)
And what entity in the U.S. is protecting us from Chinese cyber attacks?
Just curious. Who would be putting us at risk by 'letting their guard down'?