Microsoft's IE Is the Most Targeted Application By Security Researchers 96
darthcamaro writes "Though Microsoft hasn't yet patched its Internet Explorer web browser in 2014, it did patch IE at least once every month in 2013. According to HP's 2013 Cyber Risk Report, more researchers tried to sell IE vulnerabilities than any other product vulnerability. 'IE is the most prevalent browser on the systems that attackers want to compromise' said Jacob West, CTO of HP's Enterprise Security Group."
Bear in mind (Score:5, Insightful)
Re: (Score:1)
Turning off scripting in the security zone breaks all web sites that use scripts and people should have CONTROL on what is allowed to run on their machines.
They do. They have CONTROL over what OS and applications they install/support/buy/use.
In a work environment it's not under their control, but it is under the control of the very same department that is responsible for system security. It's not rocket science (though getting through to the people with the budgets is often a difficult task).
Re: (Score:3)
Going back to what the summary says, IE is usually present on the systems _that haxors want to compromise_.
Corporate machines, which have IE because they are chained to legacy systems that once required it.
Corporate machiens, where access is available to much more valuable data than some grandma's Hotmail password.
Give credit where its due (Score:5, Insightful)
The low level coders on the ie team did a good job with graphics performance in IE9. Don't tar them with the same brush as the idiot management/marketing layer who think fancy features and bloat are more important than building a secure product from the ground up to start with (and I'm talking about the browser and OS)
Re: (Score:3)
Re:Give credit where its due (Score:5, Insightful)
Atleast from IE9 onwards (OK and IE8 a bit) they started to notice that standards are a good thing
No, they just stopped being able to ignore standards due to their shrinking market share.
Re: (Score:2)
IE8 is 5 years old.
The fact that people wont upgrade is maddening to any web developer.
Re: (Score:2, Interesting)
Just wait for MS to die off
You may not have to wait too long.
The news is full of stories suggesting that investors want to break Microsoft up.
Microsoft's new leadership could almost double the company's valuation by parting with a good chunk of the businesses it uses to court consumers.
Jettisoning units such as Xbox video-game consoles and the Bing search engine may be the change Microsoft needs to rejuvenate growth as it prepares to make Satya Nadella chief executive, said Schwartz Investment Counsel, which owns Microsoft shares. The world's biggest software maker should go further by also splitting off Windows and smartphones to focus on providing services to business customers, said Stifel Financial.
http://www.theage.com.au/it-pr... [theage.com.au]
Of course Slasdot won't discuss this, beacuse they're paid not to.
Re: Bear in mind (Score:1)
As a member of Slashdot, how do I collect my paycheck?
Re: (Score:2)
Re: (Score:2)
Not since IE 6.
True some GDI code might use trident for placements but IE 8 and later have lowrights privledge by default. IE has no access to the file system, system processes or threads, or anything outside %appdata in the users profile. ... however in XP this is not enabled by default due to its ancient 2001 era kernel not recognizing what a sandbox is or anything besides admin and a limited user. Another reason you should be convincing ignorant XP users to upgrade as it frankly is unsafe today.
Firefox l
Re: (Score:2)
Sorry. Anonymous Cowards work for free!
Sell Xbox unit??? (Score:4, Insightful)
Yeah , great idea - sell one of the units making a profit!
Typical short term hedgefund approach to companies - earn us some money now by selling off collateral then we'll dump your shares before they tank. Fucking parasites.
Re: (Score:3)
Typical short term hedgefund approach to companies - earn us some money now by selling off collateral then we'll dump your shares before they tank. Fucking parasites.
Noo, you're wrong. Liquidity! Trickle Down! Hookers!
Re:Bear in mind (Score:5, Informative)
Not having used IE since ver 7 I was really surprised that IE 10 and 11 are actually decent enough to use for a while when some firefox or chrome update breaks shit, but it still has its fair share of annoyances. Please allow me to enumerate a few of my annoyances with IE 11:
1. You can block flash fairly easily, but only on a site-by-site basis, and once you whitelist a site you can't remove it without removing *every other site* you've whitelisted. C'mon IE, I only want to allow flash to watch some stupid video on this site this one time...
1.a Oh yeah, flash is baked in to the browser now, but it seems to be a shitty version that stutters on streaming videos making it a crapshoot whether or not it'll be watchable.
2. There is a built-in tracking/ad blocker but again, there's no fine-grained control without really dicking around with some ... file.. somewhere. IOW it's not intuitive and it's very difficult to whitelist a particular site's ads without fucking IE's whole ad blocking program.
3. IE finally renders shit correctly, uhh, except for all the "legacy" shit that was built with workarounds for older versions of IE, like e.g. vBulletin.. And I don't "get" IE well enough to tell it how to tell the site to STFU and give me the firefox version (which renders correctly in IE BTW) since IE doesn't seem to like to play nice with user-agent strings outside of its archaic F12 devtools..
4. Fucking font rendering SUCKS. Microsoft took an enormous step backwards with their font renderer in windows 8/8.1 and it really shows in IE.
5. IE is now reliable at recovering the pages when it crashes, which is good 'cause it crashes a lot.
I'd like to interject that I sometimes use and enjoy IE now, but I just need to get this off my chest.
6. Private browsing is good, unless you want to have 2 or more private browsers open on the same site like e.g. two or more gmail accounts open simultaneously, which you can't do because the cookies are shared amongst them... Well, you can if you have one open in the standard IE and the other in private mode, BUT NO MORE.
7. it's finally reasonably secure, or at least the competition is now equally insecure.
Any more I don't choose a browser because it has features I like, I choose a browser because the competition has pissed me off, and it's an arms race to see which one can get to the bottom first... Firefox is shitty, chrome is shitty, IE is shitty but which one is going to piss me off the most today?
Re:Bear in mind (Score:4, Insightful)
Hey, thanks. what you did there is the browser equivilant of leaving a bag of burning dogshit on my doorstep.
Opera took a serious wrong turn recently
Re: (Score:2)
Re: (Score:2)
The version of Chromium I use is the same. Is there a browser which supports multiple simultaneous private sessions?
Re: (Score:2)
Anything from mosaic onwards on a multiuser operating system. That includes server versions of MS Windows accessed via remote desktop (or hacked copies of Win7 to remove the deliberate nerfing), although that's a pretty ugly hack and getting more than one on the same screen at once is an even uglier hack.
Re: (Score:2)
I think not. Multiple 'cookie sandboxes' would be nice (especially for purposes of paranoia... ignoring Evercookie and Panopticlick), but it's not happened yet.
Google turned up this [mozilla.org], but it's just Firefox's current private-browsing, given a stupid name.
Re: (Score:1)
"6. Private browsing is good, unless you want to have 2 or more private browsers open on the same site like e.g. two or more gmail accounts open simultaneously"
1. Create multiple user accounts just for running apps. /user" in the command line, or create a shortcut for each user account with a "runas .... iexplore.exe -private" in the executable setting.
2. Use "runas
3. Bask in the multi-session private browsing goodness.
Re: (Score:1)
Re: (Score:3)
Although that worked in IE 10 Microsoft, in their infinite wisdom, nerfed that feature in some IE 11 update and AFAIK they haven't surreptitiously added it back yet.
Re: (Score:2)
For the multi-session private browsing, open one private window, then go File->New Session.
Now you have two separate, private sessions. You can do this indefinitely.
The cookie sharing presumably exists because websites are broken without it.
Re: (Score:2)
Thank you!! I really appreciate this.
Re:Bear in mind (Score:4, Insightful)
IE is - so Microsoft alleged in the anti-trust trials - "An Integral Part of Microsoft Windows".
There is absolutely no (technical) reason why this should be, based on the success of competing browsers, but the mere act of close-coupling it with the OS means that there are more ways that exploits to the browser can be converted into exploits for the OS.
And, since it does come bundled directly with Windows, you can depend on people who either aren't technically-savvy enough or are simply too lazy to take the extra effort needed to secure their systems as IE users.
So in many ways, IE is the ideal target.
Re: (Score:3)
IE isn't a piece of crap, not more than any other browser (most other browsers have more security holes these days than IE has, especially due to situations like this). You're nothing but a troller who only thinks the browser he/she's using is the most secure and best browser around, well think again..
Developing a secure browser is one hell of a job, especially with freaky hackers who can think up stuff you never ever would have thought up and thought it was secure as hell.. What seems secure by design toda
Re: (Score:2)
Re: (Score:2)
Also is the low-hanging fruit. IE was designed to be both the local machine desktop environment and the access to internet, and a lot of historical vulnerabilities came from that design choice (in IE3 if you clicked on a direct access file, like a .lnk, it would be executed in the local machine, no question asked). Safari, Firefox and Chrome are more or less pure internet browsers, even in Chrome OS what matters is to work as frontend to internet.
But having an ecosystem with both security by design browse
Re: (Score:2)
Only IE and Chrome has lowrights by default. This means it can't even access your freaking filesystem, view threads/processes, or do anything outside of %appdata. This is one of the reasons why anything above IE 8 is Windows 7 only. Not because mean old MS decided it is time to upgrade but because security on XP sucks goatballs.
IE is more secure than Firefox and has less exploits if you compare the last few years since it supported process by tab, kernel level sandboxing, and now lowrights. It is not imposs
But, we just said no one use IE? (Score:1)
Re:But, we just said no one use IE? (Score:5, Insightful)
You needn't use IE for it to be useful to attackers. It is the one thing present on EVERY SINGLE system running an OS from MS, and it is the one single thing on every MS OS operated PC that is not only well suited to making connections via internet but also the one that the MS firewall routinely allows to in the default setting.
The good old "we send the user a bogus EXE in mail" isn't really good anymore because of the MS firewall and UAC. Works like a charm, though, with a bogus script abusing an IE vulnerability since IE is considered a "trusted" application by default.
Re: (Score:2)
You needn't use IE for it to be useful to attackers. It is the one thing present on EVERY SINGLE system running an OS from MS, and it is the one single thing on every MS OS operated PC that is not only well suited to making connections via internet but also the one that the MS firewall routinely allows to in the default setting.
The good old "we send the user a bogus EXE in mail" isn't really good anymore because of the MS firewall and UAC. Works like a charm, though, with a bogus script abusing an IE vulnerability since IE is considered a "trusted" application by default.
IE is by default running in protected mode, a significantly less trusted zone than the user. If you already have a script running on the user system you already have higher privileges and less sandboxing than if you try to hand it off to IE.
Re: (Score:3)
Re: (Score:2)
Which is pretty much moot in the malware swamp. It's like using insect repellent to scare off alligators instead of going in bare.
With Windows 7 and higher in lowrights mode it is very effective. You can't see or write to disk, can't view or access other processes or threads, everything is a tiny sandbox and even if you get out you have ASLR with scrambled ram so you can't pick a .dll to overflow or insert malicious code, with DEP that is another layer in case you figure out the random ram layout and to even get there you need to bypass lowrights which is stuck in your %appdata.
This not impermeable by any sense of the means but sayin
Re: (Score:2)
Malware getting in that way argues otherwise.
Re: (Score:2)
Re: (Score:2)
Re: (Score:1)
no we're saying you're using a strawman: the story you're referring to was about a certain *version* of IE that was now in the single-digit market share.
No, it wasn't: http://tech.slashdot.org/story... [slashdot.org]
Re: (Score:1)
Just a short while ago there was a Slashdot story that IE now had only single-digit market share. Which seems to be in stark contradiction to what is said in this story. Are we now saying those numbers were not really that close to reality, but we went with them anyway?
I think that story is largely overblown. Those statistics are gathered from their site (W3Schools), and their site only. All that really shows is that most users who visit W3Schools don't run IE. And that doesn't surprise me. Why would anyone that deals with web development want to use a browser which has historically not followed standards and caused so much heartache for the web development community to support? This article doesn't surprise me either. I thought the target was obvious.
Lol, 1996? (Score:1)
Has anything changed?
IE on Windows easiest to compromise .. (Score:1)
IE on Windows is the easiest system for attackers to compromise
Re: (Score:1)
'IE is the most prevalent browser on the systems that attackers want to compromise' IE on Windows is the easiest system for attackers to compromise ..
For a number of years Safari on OSX has been the easiest system for hackers to compromise in Pwn2Own.
http://www.zdnet.com/blog/secu... [zdnet.com]
http://arstechnica.com/apple/2... [arstechnica.com]
Re: (Score:1)
Easiest to compromise? Or on the computer that they most wanted to win? The fist contestant to pwn a system gets to own it - that's the point of the contest - and Safari happened to be on the most expensive computer, so the contestants targeted it first to improve their chances at getting the best prize.
I love this arguments that pops up to explain the poor results for Safari and OSX in Pwn2Own. They winner also win 20.000 USD, but obviously they went for the hardest target, risking their win and those $20k by not taking the easiest route, because they sooo wanted the shiny Macbook.. Not to mind that Charlie Miller, amongst others, have gone in great detail in interviews on why Safari on OSX is easiest to compromise, but those are details lost on many.
Too many still using old versions (Score:1)
Its clear that IE 10 and IE 11 improved on security. But with so many still using XP and even some using Vista. Both of which cannot run either IE10 or IE11. Microsoft has created a large group of Windows users who simply cannot use a secure IE. The fact enterprise is a big part of XP users also means they are most likely using IE8 or IE9 rather then a more secure and modern browser like Firefox or Chrome. I am not a IE hater but think for many reasons including security. Microsoft should disconnect IE from
Where does it say old versions (Score:1)
Its clear that IE 10 and IE 11 improved on security.
Its not clear at all. In fact there is nothing in the article that suggests older versions being the problem. It is a disgrace how Microsoft treats its customers.
Re: (Score:2)
Its clear that IE 10 and IE 11 improved on security. But with so many still using XP and even some using Vista. Both of which cannot run either IE10 or IE11. Microsoft has created a large group of Windows users who simply cannot use a secure IE. The fact enterprise is a big part of XP users also means they are most likely using IE8 or IE9 rather then a more secure and modern browser like Firefox or Chrome. I am not a IE hater but think for many reasons including security. Microsoft should disconnect IE from the OS. Or simply retire IE altogether.
This is going to change in the next couple of years. I work for a very large company stuck on XP. The costs we pay to support and secure XP are exorbitantly high and increasing. We plan to switch to Windows 7 this year. Of course, this date will almost certainly slip, but it will probably be done by the end of 2015.
If the numbers are compelling enough to make us switch, they are undoubtedly compelling to other corporate XP users as well.
"Security researchers" (Score:5, Insightful)
Re: (Score:3)
Yup, if they are trying to sell the vulnerabilities then they are not researchers at all, but scum.
Calling them researchers is Slashdots way of making them out to be the good guys.
Re: (Score:3)
What you have to remember about crackers whether black or white hat is that while they're usually highly intelligent, they're also still mentally rather juvenile. Being called a "researcher" gives these immature basement dwelling mushrooms the gravitas they'd otherwise never achieve.
Re: (Score:2)
Neither does developing small programs or algorithms or 101 other intellectually stimulating tasks. The difference being they don't involve breaking into someone else's computer. Just because someone wants to practice their lockpicking skills, it doesn't give them the right to try to break into my house while doing it regardless of whether they steal anything.
Re: (Score:2)
"Yeah, except small programs or algorithms for their own sake are boring"
Oh right, and finding exploits for their own sake arn't?
"Think before you open your dick holster"
I doubt you'd even know how to use one.
Other shock revalations..... (Score:3)
...from the feckingobvious department, that yellow disc in the sky is the sun. Slow news day or something guys?
And this line shows the real problem (Score:2)
'IE is the most prevalent browser on the systems that attackers want to compromise' said Jacob West, CTO of HP's Enterprise Security Group."
Supposedly, Chrome is now the most popular browser going. If Windows is the majority desktop (and it is), then chrome must be the most prevalent browser on it.
So, why attack IE? Ease of breaking into.
Re: (Score:2)
The way I interpreted it was that an assumed profile of someone using IE is that of a less-knowledgeable user (so one that would be more susceptible to not noticing something "bad" happening to their computer).
IE is not a browser (Score:2)
Re: (Score:1)