Yet another serious IE security flaw, Download Ject

page previous  1, 2, 3
You are here:  SillyDog701 > Message Centre > Windows (and Microsoft talk) > [sdt=6154]
SillyDog701 Forums
Author Message
Mandrake
Moderator


Joined: 13 Sep 2002
Posts: 3882
01 Jul, 2004 6:46 am [sdp=37017]  

Here we go again, this time it's a six year old flaw in IE that has re-surfaced . . . Exclamation

Quote:

A security flaw that had been fixed in older versions of Microsoft Internet Explorer has reappeared in the latest version of the browser software.

Security company Secunia issued a bulletin warning of the flaw in versions 5.01, 5.5 and 6.0 of Internet Explorer (IE). The problem had been fixed six years ago, when it appeared in versions 3.0 and 4.0 of the IE browser.


C|Net Article

I reccommend that everyone should use a browser like FireFox or Opera, and use a Firewall to block IE from accessing the Internet.

UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7) Gecko/20040629 Firefox/0.9.1

Core i7 920 | ASUS P6T Deluxe v2 | 3TB+ HDD | 12GB Corsair DDR3 | Radeon 4890 Xfire | X-Fi Titanium Fatal1ty | Logitech Z-5500 Speakers | Dell 3008WFP | Seven RC1
Back to top profile
DJGM
diamond member


Joined: 19 Jun 2002
Posts: 4371
Location: Manchester, England, UK
01 Jul, 2004 10:47 am [sdp=37024]  

Q: What has IE got in common with a Teflon based frying pan?

A: They're both non-stick!


Honestly though, using IE is akin to hiding from an axe wielding psycho, under a patchwork quilt!

UserAgent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7) Gecko/20040618

SeaMonkey = Swiss Army Knife: It's versatile, reliable, and contains useful tools.
Windows Internet Explorer = Old Swiss Cheese: Full of holes, and it stinks!
Back to top profile website
DJGM
diamond member


Joined: 19 Jun 2002
Posts: 4371
Location: Manchester, England, UK
02 Jul, 2004 5:17 pm [sdp=37181]  

Microsoft have issued a "config change" to deal with the "Download.Ject" exploit.

More information available on Microsoft's website here . . .

Basically, MS recommend that all Windows 2000/XP/2003 users apply
this patch a.s.a.p. The update can be obtained from Windows Update.

UserAgent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7) Gecko/20040618

SeaMonkey = Swiss Army Knife: It's versatile, reliable, and contains useful tools.
Windows Internet Explorer = Old Swiss Cheese: Full of holes, and it stinks!
Back to top profile website
Antony
Site Admin


Joined: 18 Jun 2002
Posts: 12754
Location: Sydney, Australia
04 Jul, 2004 6:52 pm [sdp=37347]  

DJGM wrote:
Microsoft have issued a "config change" to deal with the "Download.Ject" exploit.

More information available on Microsoft's website here . . .
Basically, Microsoft has decided to plug the hole by turning off the ability for the ActiveX component to write to the operating system. (C|net News.com)

UserAgent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/125.2 (KHTML, like Gecko) Safari/125.8

Back to top profile website
Don_HH2K
Moderator


Joined: 09 May 2004
Posts: 4745
04 Jul, 2004 6:59 pm [sdp=37349]  

If it makes Windows more secure, then go ahead. It's not a big loss to non-IE users.

UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.4) Gecko/20030624 Netscape/7.1 (ax)
Back to top profile website
Wellander
SUSPENDED


Joined: 21 Oct 2002
Posts: 2576
04 Jul, 2004 7:11 pm [sdp=37350]  

Antony wrote:
DJGM wrote:
Microsoft have issued a "config change" to deal with the "Download.Ject" exploit.

More information available on Microsoft's website here . . .
Basically, Microsoft has decided to plug the hole by turning off the ability for the ActiveX component to write to the operating system. (C|net News.com)


Hi,
That sais good by to WIndows update.

UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.8a1) Gecko/20040520
Back to top profile
Don_HH2K
Moderator


Joined: 09 May 2004
Posts: 4745
04 Jul, 2004 7:27 pm [sdp=37353]  

Unless Microsoft develops some secret new technology that can only be accessed via command line for updates.

UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.4) Gecko/20030624 Netscape/7.1 (ax)
Back to top profile website
Mandrake
Moderator


Joined: 13 Sep 2002
Posts: 3882
04 Jul, 2004 8:33 pm [sdp=37357]  

Specifically Microsoft's configuration change blocks the ability of the ADODB.screen ActiveX component to write to the PC's hard drive. It does not disable ActiveX entirely, and WindowsUpdate still works fine.

UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7) Gecko/20040616

Core i7 920 | ASUS P6T Deluxe v2 | 3TB+ HDD | 12GB Corsair DDR3 | Radeon 4890 Xfire | X-Fi Titanium Fatal1ty | Logitech Z-5500 Speakers | Dell 3008WFP | Seven RC1
Back to top profile
Antony
Site Admin


Joined: 18 Jun 2002
Posts: 12754
Location: Sydney, Australia
05 Jul, 2004 7:51 am [sdp=37386]  

According to SecurityFocus, this vulnerability has been known for more than 9 months, it affects IE 5.5 and later on Windows 95 and later.
however, the fix is only available for Windows 2000 and above
Arrow too late, too little

Reference: Microsoft Internet Explorer ADODB.Stream Object File Installation Weakness (SecurityFocus)

SillyDog701 recommends Mac to any user who is thinking about getting a new computer.

UserAgent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en-us) AppleWebKit/125.2 (KHTML, like Gecko) Safari/125.8

Back to top profile website
DJGM
diamond member


Joined: 19 Jun 2002
Posts: 4371
Location: Manchester, England, UK
11 Jul, 2004 2:08 am DJGM speaks his mind . . . [sdp=38002]  

IMHO, for an organisation as big as Microsoft, to waste so much precious time,
pondering whether or not to issue a patch for a very serious security problem,
while a large number of computer users had their systems exploited via this
dangerous bug, is just disgraceful, and totally unacceptable.

Especially, when a comparatively tiny, independent non-profit software vendor
such as Mozilla, with far less revenue and far fewer resources at it's disposal
than Microsoft, gets their security bug fixed in less than a day and a half!

The Microsoft staffers involved with IE, should hang their heads in shame.


UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.7) Gecko/20040616

SeaMonkey = Swiss Army Knife: It's versatile, reliable, and contains useful tools.
Windows Internet Explorer = Old Swiss Cheese: Full of holes, and it stinks!
Back to top profile website
Display posts from previous:   
Reply to topic    Forum Index > Windows (and Microsoft talk) All times are CST (GMT -6)
page 3 of 3 page previous  1, 2, 3
To add your questions, comments, and for more features and more, please join SillyDog701 Message Centre. It's free! This is SillyDog 701 Message Centre (SD701 Forums).

Michael Jackson Thriller 25 iTunes

*Search | FAQ | Rules and Policies | MozInfo701 - Mozilla Information Centre | SD701 Open Directory | Message Board Map | download Netscape