PDA

View Full Version : US-CERT warns web users to stop using Internet Explorer


Gnomercy
07-02-2004, 04:57 PM
Link (http://www.enterpriseitplanet.com/security/news/article.php/3375431)

The U.S. government's Computer Emergency Readiness Team (US-CERT) is warning Web surfers to stop using Microsoft's Internet Explorer (IE) browser.

On the heels of last week's sophisticated malware attack that targeted a known IE flaw, US-CERT updated an earlier advisory to recommend the use of alternative browsers because of ''significant vulnerabilities'' in technologies embedded in IE.

''There are a number of significant vulnerabilities in technologies relating to the IE domain/zone security model, the DHTML object model, MIME-type determination, and ActiveX. It is possible to reduce exposure to these vulnerabilities by using a different Web browser, especially when browsing untrusted sites,'' US-CERT noted in a vulnerability note.

The latest US-CERT position comes at a crucial time for Microsoft , which has invested heavily to add secure browsing technologies in the coming Windows XP Service Pack 2. The software giant has spent the last few months talking up the coming IE security improvements but the slow response to patching well-known -- and sometimes ''critical'' -- browser holes isn't sitting well with security experts.

On discussion lists and message boards, security researchers have spent a lot of time beating the ''Dump IE'' drum, and the US-CERT notice is sure to lend credibility to the movement away from the world's most popular browser.

US-CERT is a non-profit partnership between the Department of Homeland Security (DHS) and the public and private sectors. It was established in September 2003 to improve computer security preparedness and response to cyber attacks in the United States.

It has been more than two weeks since Microsoft confirmed the existence on an ''extremely critical'' IE bug, which was being used to load adware/spyware and malware on PCs without user intervention but, even though the company hinted it would go outside its monthly security update cycle to issue a fix, the flaw remains unpatched.

US-CERT researchers say the IE browser does not adequately validate the security context of a frame that has been redirected by a Web server. It opens the door for an attacker to exploit the flaw by executing script in different security domains.

''By causing script to be evaluated in the Local Machine Zone, the attacker could execute arbitrary code with the privileges of the user running IE,'' according to the advisory.

''Functional exploit code is publicly available, and there are reports of incidents involving this vulnerability.''

To protect against the flaw, IE users are urged to disable Active scripting and ActiveX controls in the Internet Zone (or any zone used by an attacker). Other temporary workarounds include the application of the Outlook e-mail security update; the use of plain-text e-mails and the use of anti-virus software.

Surfers must also get into the habit of not clicking on unsolicited URLs from e-mail, instant messages, Web forums or internet relay chat (IRC) sessions.

Gade Terbob
07-20-2004, 02:04 PM
I've recently dumped (just quit using it for browsing, it is too tightly integrated with os to delete) explorer.

The only problem I had was when clicking live links, windows insisted on open a window to find a non existant link. This occured AFTER changing default browser from explorer to firefox. If any of you have this problem, here is the solution:
Mozilla Forums (http://forums.mozillazine.org/viewtopic.php?t=91430)

I *highly* recommend FireFox, but for sure: Just say "No" to explorer.

bellgamin
07-21-2004, 03:36 AM
If you are a *fan* of Firefox browser, you are probably aware that a significant source of advice, support, & friendly comraderie is the Mozillazine Forum. That's the very forum cited by Gade in his post, just above this one.

The Mozillazine forum is privately funded & operated. It is NOT financed by the Mozilla group. Concerning this, see that forum's thread HERE (http://forums.mozillazine.org/viewtopic.php?t=97577).

The recent exponential growth in Firefox's popularity has caused the Mozillazine forum to grossly exceed its bandwidth quota, and also to strain the abilities of its one-man, volunteer administrator {Jason Kerz}. In fact the forums were "off the air" for a few days a while back, & still are operating at a restricted capacity.

I call this situation to the attention of the AOH *family* in hopes that some of you talented people might consider lending Mozillazine a hand -- either by a $$ donation, &/or by helping jason with some of the admin chores. It would be a shame if Mozillazine went under.

grace & peace to all... bellgamin

bellgamin
07-21-2004, 04:21 AM
Oh... I forgot to mention: Gade's advice to cease using Internet Explorer {IE} is right on target. In ADDITION, it's probably a good idea to check your Firewall & kill IE's permission to access the internet {see sample below}.

Why block IE? Because, even if you cease using IE for your own browsing, trojans & spyware will almost always try to piggy-back on IE's "trusted application" status when they try to call out. So it's a good ide to remove IE from trusted status altogether. If you do that, remember that Microsoft won't let you access patches unless you use IE. At such times, you must temporarily reinstate IE to trusted status, but {as soon as the patch is downloaded} revert IE to blocked status.

It's also a good idea to place explorer.exe {the exe for Windows Explorer} in blocked status, to close up a particular firewall exploit that's going around right now. Basically, explorer.exe has NO good reason for accessing the web without your SPECIFIC, ad-hoc permission to do so.

live long & prosper... bell