|
|
|
"This exploit can be mitigated by turning off Javascripting."
Or, you could turn off IE and use almost any other browser.
Is IE7 a problem too?
Tin |
09.19.06 - 1:09 am | #
|
|
"Is IE7 a problem?".
They're using IE6 in the screenshots. IE7 has been immune to virtually all exploits. If IE7 were vulnerable in this case you can bet they'd say so.
Anonymous |
09.19.06 - 2:12 am | #
|
|
why you're so stupid to publish this and not contacted Microsoft? Is Sunbelt è security company or just like the first cracker ?
duk |
09.19.06 - 3:29 am | #
|
|
duk, you're a moron. They wouldn't post this if they were using it. Troll.
blah |
09.19.06 - 3:53 am | #
|
|
Is there another possibility to stop the exploit working? I'm thinking of deleting or setting ACL to deny for everybody the files working for VML. But i don't know which one it could be...
Dr. Em |
09.19.06 - 6:37 am | #
|
|
Just use Firefox and the problem is not a problem......
Joe |
09.19.06 - 6:50 am | #
|
|
why not use buffer overflow protection software ?
someone |
09.19.06 - 6:56 am | #
|
|
"Just use Firefox and the problem is not a problem......"
Until the next Firefox exploit hits you 
kendo |
09.19.06 - 6:58 am | #
|
|
http://www.sys-manage.com/
englis...d_Exploits.html
kendo |
09.19.06 - 7:07 am | #
|
|
"buffer overflow protection software??"
wtf is that?
Anonymous |
09.19.06 - 7:16 am | #
|
|
Bull with a capital B.
Hey Mr Eric VP of R&D.. get a life !
AHole
Anonymous |
09.19.06 - 7:25 am | #
|
|
Let's be honest here. Everything on the web (and in business!) is optimized for IE, and in particular, IE6. Instead of just acting Holier Than Thou and spouting the Firefox religion, why not have some brains and acknowledge that for the majority of businesses out there, changing your 10's of thousands of employees from IE to Firefox overnight isn't an option. We know that every piece of software has bugs and vulnerabilities; instead of just bashing MS at every turn, try to offer something constructive for a change!
Go get a girlfriend that doesn't play D&D, it'll change your perspective on the world...
Mike
Mike |
09.19.06 - 7:53 am | #
|
|
duk,
There is nothing stupid about proclaiming loudly and proudly that software contains flaws. It's better all around for more people to know about this problem: until Microsoft get around to fixing it, everyone can just start using a proper browser instead.
With Firefox, the source code is available for everyone to look at. Yes, this means that the "bad guys" get to look for stuff they can exploit ..... but it also means that the "good guys" get to look for stuff that the "bad guys" can exploit. And since there are more good guys than there are bad guys, any potential problem that exists is more likely to be found by a good guy (and promptly fixed) than by a bad guy.
There is a lot less shame in making a mistake and learning from it, than there is in covering up a mistake.
AJS |
09.19.06 - 8:00 am | #
|
|
"Just use Firefox and the problem is not a problem......"
I'M using Firefox, but my users can't use it. Thats the problem. I hate that there is one f**** security-hole after an other, but what shall i do?
What i need is an other workaround than disabling JavaScript, because this is not an good option, too.
Dr. Em |
09.19.06 - 8:01 am | #
|
|
IE7 is not immune to all exploits. The 'Exploit A Day' project showed that ever so recently which caused a flurry of patches for IE6 and 7 to be published. IE7 is still vulnerable in alot of ways; they are fixing issues as they find them but the same basic engineering problems remain which caused all previous versions to be vulnerable as well.
Anonymous |
09.19.06 - 9:36 am | #
|
|
duk trolls "why you're so stupid to publish this and not contacted Microsoft? Is Sunbelt è security company or just like the first cracker?"
Not sure of the intelligence of the above quote. Giving notice on active exploits and possible workarounds is a far different venue than publishing previously unknown vulnerabilities for which exploits may be, in the future, developed from this knowledge. Duk must therefore be one of the botnet creators and is mad about the end user being warned of an active exploit and a possible way of preventing your computers from being infected.
martinelli |
09.19.06 - 9:51 am | #
|
|
Mike trolls "Let's be honest here. Everything on the web (and in business!) is optimized for IE, and in particular, IE6. Instead of just acting Holier Than Thou and spouting the Firefox religion, why not have some brains and acknowledge that for the majority of businesses out there, changing your 10's of thousands of employees from IE to Firefox overnight isn't an option. We know that every piece of software has bugs and vulnerabilities; instead of just bashing MS at every turn, try to offer something constructive for a change!
Go get a girlfriend that doesn't play D&D, it'll change your perspective on the world...
Mike"
Kind of funny dude, our company moved to Firefox to avoid your problems. We don't waste our life on D&D here and we don't need girlfriends because the married life demands that we be at home instead of always worrying about patching comptuers.
martinelli |
09.19.06 - 9:55 am | #
|
|
"I'M using Firefox, but my users can't use it. Thats the problem. ..."
Depends whether you value system security and data integrity, or the small workload of learning a differant system.
Ignorant users are the people who need secure systems. IE is deadly in their hand. You know the kind of user I mean, the ones who know the quickest way to make dialogs go away, so when a site asks them to install and run ActiveX things, they happily click yes.
Web Browsers, Email and the Operating System itself are all on the front line, if they aren't secure your in real trouble.
Read the studies, read the security reports, FireFox may not be perfect but they are better than IE.
(from an Ex. IE user, now a FireFox user)
Anon |
09.19.06 - 10:19 am | #
|
|
Firefox 1.5.0.7 is still vulnerable to Michal Zalewski flaw
test here:
»lcamtuf.coredump.cx/ffoxdie.html
Michal |
09.19.06 - 10:48 am | #
|
|
IT IS ABSOLUTELY UNBELIEVABLE THAT THESE IDIOTS ARE STILL USING INTERNET EXPLORER AND ARE TOO STUPID TO SETUP THEIR CLIENT NETWORKS TO USE LINUX.
ON AN FRESH INSTALL OF XP THE USER IS STILL ADMINISTRATOR - THAT IS THE REAL SECURITY ASSAULT BY THESE MICROSOFT TERRORISTS!!! THESE BILL GATIES IDIOTS COST MILLIONS OFF DOLLARS.
uggaman |
09.19.06 - 11:06 am | #
|
|
TrackBack:
http://www.pcmag.com/article2/
0,...,2017499,00.asp
Trackback |
09.19.06 - 11:11 am | #
|
|
uggaman... shouting is not necessary (or turn off caps lock either would be fine)
The problem with doing a forced migration to linux in a corporation is the lack of software and hardware manufacturers that support a linux operating system. Also the default administrator username can be changed on a windows CD very easily using nLite. On a properly secured network the only thing at risk is the firewall (a hardware one).
archos |
09.19.06 - 11:17 am | #
|
|
And now here the affecting file: Vgx.dll
http://www.microsoft.com/technet...ory/
925568.mspx
Dr. Em |
09.20.06 - 3:04 am | #
|
|
Hi,
Open Start menu > Run and type:
regsvr32 /u "%CommonProgramFiles%Microsoft SharedVGXvgx.dll"
This should unregister vgx.dll and fix the problem in some way.
Feky |
Homepage |
09.20.06 - 8:24 am | #
|
|
Hey, Eric. I can't seem to get away from you!
Ziff-Davis picked up on your blog posting:
http://news.zdnet.com/2100-1009_...tml?
tag=nl.e589
John in Florida |
09.20.06 - 8:34 am | #
|
|
"Go get a girlfriend that doesn't play D&D, it'll change your perspective on the world..."
"girlfriend" and "D&D" in the same sentence? that does not compute... 
Shaun |
09.20.06 - 11:34 am | #
|
|
I liked the "Coming from a porn website". I guess now that employee can say to his boss - "Hey, i'm looking for zero-day attacks" 
Kirill |
Homepage |
09.21.06 - 5:26 pm | #
|
|
Great news
I hope everybody read this article
thanks
forex |
Homepage |
02.09.07 - 3:09 pm | #
|
|
So, you say you found one "hole" totally by accident while looking for quite another?
Dr.X |
02.28.07 - 6:31 am | #
|
|
I agree that being with Firefox, the source code is available for everyone to look at. Yes, this means that the "bad guys" get to look for stuff they can exploit ..... but it also means that the "good guys" get to look for stuff that the "bad guys" can exploit.Even at its no different story either. And since there are more good guys than there are bad guys, any potential problem that exists is more likely to be found by a good guy (and promptly fixed) than by a bad guy.That's how the system story works.
alex |
Homepage |
06.19.07 - 6:54 am | #
|
|
Ignorant users are the people who need secure systems. IE is deadly in their hand. You know the kind of user I mean, the ones who know the quickest way to make dialogs go away, so when a site asks them to install and run ActiveX things, they happily click yes.And even at http://www.webdesigningcompany.net
Web Browsers, Email and the Operating System itself are all on the front line, if they aren't secure your in real trouble
alex |
Homepage |
06.19.07 - 6:56 am | #
|
|
Firefox should be the answer to this problem. It seems to be ahead of IE at all times.
Vanuatu |
Homepage |
08.16.07 - 10:26 pm | #
|
|
I do not agree. Microsoft is Microsoft.
Web Site Design |
Homepage |
08.27.07 - 8:47 am | #
|
|
I use firefox but with one toolbar to see websites like IE web browser, is this a problem?
webkool |
Homepage |
11.18.07 - 5:40 pm | #
|
|
This particular vulnerability is patched. So go ahead and get your machine fully patched and you won't be affected by it.
I've seen Firefox exploits used as well in the past. It's important to keep both browsers updated...
Alex Eckelberry |
11.18.07 - 6:01 pm | #
|
|
Microsoft isn't what it used to beeeee. People, you have to know that every IE including 7.0 is vulnerable to hack atacks. They so many problems, that only Service Pack can fiy them. Be safe...
Fighter |
Homepage |
12.26.07 - 5:17 pm | #
|
|
Micro$oft .. every day worst.
sec |
Homepage |
01.09.08 - 10:50 am | #
|
|
Microsoft if great no one can beat MicroSoft.
mani |
Homepage |
12.15.08 - 1:55 am | #
|
|
|
Commenting by HaloScan
|