IE 7,8 and 9 Zero-Day Exploit

For system help, all hardware / software topics NOTE: use Coders Corner for all coders topics.

Moderators: Krom, Grendel

Post Reply
User avatar
Tunnelcat
DBB Grand Master
DBB Grand Master
Posts: 13740
Joined: Sat Mar 24, 2007 12:32 pm
Location: Pacific Northwest, U.S.A.

IE 7,8 and 9 Zero-Day Exploit

Post by Tunnelcat »

Yet another reason out of many to stick with Firefox or Chrome.

http://www.securityweek.com/new-interne ... oited-wild
Cat (n.) A bipolar creature which would as soon gouge your eyes out as it would cuddle.
User avatar
Krom
DBB Database Master
DBB Database Master
Posts: 16137
Joined: Sun Nov 29, 1998 3:01 am
Location: Camping the energy center. BTW, did you know you can have up to 100 characters in this location box?
Contact:

Re: IE 7,8 and 9 Zero-Day Exploit

Post by Krom »

A web browser has a security vulnerability, what a shocking piece of news... :P
User avatar
Isaac
DBB Artist
DBB Artist
Posts: 7737
Joined: Mon Aug 01, 2005 8:47 am
Location: 🍕

Re: IE 7,8 and 9 Zero-Day Exploit

Post by Isaac »

Screw explorer.
❉⊱•═•⊰❉⊱•═•⊰❉⊱•═•⊰❉❉⊱•═•⊰❉⊱•═•⊰❉⊱•═•⊰❉❉⊱•═•⊰❉⊱•═•⊰❉⊱•═•⊰❉
-⎽__⎽-⎻⎺⎺⎻-⎽__⎽--⎻⎺⎺⎻-★ ·:*¨༺꧁༺ :E ༻꧂༻¨*:·.★-⎽__⎽-⎻⎺⎺⎻-⎽__⎽--⎻⎺⎺⎻-
❉⊱•═•⊰❉⊱•═•⊰❉⊱•═•⊰❉❉⊱•═•⊰❉⊱•═•⊰❉⊱•═•⊰❉❉⊱•═•⊰❉⊱•═•⊰❉⊱•═•⊰❉
User avatar
TigerRaptor
DBB Fleet Admiral
DBB Fleet Admiral
Posts: 2693
Joined: Tue Feb 01, 2000 6:00 am

Re: IE 7,8 and 9 Zero-Day Exploit

Post by TigerRaptor »

Firefox - NoScript

Chrome - ScriptNo

Less B.S to worry about.
User avatar
Jeff250
DBB Master
DBB Master
Posts: 6539
Joined: Sun Sep 05, 1999 2:01 am
Location: ❄️❄️❄️

Re: IE 7,8 and 9 Zero-Day Exploit

Post by Jeff250 »

The problem with IE's security isn't that it has zero-day vulnerabilities but that you have to wait until the next patch Tuesday (at the soonest) for the fixes.
User avatar
Sirius
DBB Master
DBB Master
Posts: 5616
Joined: Fri May 28, 1999 2:01 am
Location: Bellevue, WA
Contact:

Re: IE 7,8 and 9 Zero-Day Exploit

Post by Sirius »

They issue out-of-band updates for critical vulnerabilities (Iike this one). A fix should show up in the next few days from what I was reading.

And as Krom indicated, zero-day exploits aren't a new thing (and are not unique to IE either) - the world is not ending, security practices remain the same as before; avoid dodgy sites, don't click suspicious links, and you're extremely unlikely to be attacked by this. If that's not enough for you you can disable ActiveX entirely, or use a different browser. (Other browsers don't use ActiveX, which removes one attack surface, but there are still other ways to compromise them, so you still need to apply some common sense on the internet.)

IE9 isn't my primary browser, but that has a lot less to do with security than the fact that I really want certain Firefox extensions on my home PC. ABP is indeed one. Now if only they would do some sandboxing so a single lagging Flash page didn't kneecap everything...
User avatar
Grendel
3d Pro Master
3d Pro Master
Posts: 4390
Joined: Mon Oct 28, 2002 3:01 am
Location: Corvallis OR, USA

Re: IE 7,8 and 9 Zero-Day Exploit

Post by Grendel »

User avatar
Sirius
DBB Master
DBB Master
Posts: 5616
Joined: Fri May 28, 1999 2:01 am
Location: Bellevue, WA
Contact:

Re: IE 7,8 and 9 Zero-Day Exploit

Post by Sirius »

User avatar
Top Gun
DBB Master
DBB Master
Posts: 8099
Joined: Wed Nov 13, 2002 3:01 am

Re: IE 7,8 and 9 Zero-Day Exploit

Post by Top Gun »

Hmm, guess that's why I just needed to restart.
User avatar
Tunnelcat
DBB Grand Master
DBB Grand Master
Posts: 13740
Joined: Sat Mar 24, 2007 12:32 pm
Location: Pacific Northwest, U.S.A.

Re: IE 7,8 and 9 Zero-Day Exploit

Post by Tunnelcat »

You guys don't even want to hear the multitude varieties of curse words that are coursing through my head about IE and Microsoft right now. :rant:

An update finally comes out and I try to install that damn thing. Well, it gets to the 99% installed point and just sits there........and sits there........and sits there. I wait for ten minutes, bupkiss. So sh*t, I try to stop the installation. No joy. I try the task manager, it won't even open. I try the 3 fingered salute and the task manager finally comes up and I stop the Windows Update process. Then I try to reboot. It hangs saying not to shut off or unplug my machine because it's installing an update. Well, sh*t again, I wait a little longer. Still no joy. So, since my machine has a BIOS controlled hard reboot button, I force a reboot. It reboots just fine, but Windows Update still comes up saying I need to install the stupid update! Fat chance! I think MS rushed this little patch out a little too soon. Anybody else have this happen? I don't even want to try on my other 2 Windows 7 machines at the moment. &$%#^@ IE9, and I don't even use it!
Cat (n.) A bipolar creature which would as soon gouge your eyes out as it would cuddle.
User avatar
Krom
DBB Database Master
DBB Database Master
Posts: 16137
Joined: Sun Nov 29, 1998 3:01 am
Location: Camping the energy center. BTW, did you know you can have up to 100 characters in this location box?
Contact:

Re: IE 7,8 and 9 Zero-Day Exploit

Post by Krom »

No, my SSD chewed that update up in a few seconds (most of which was creating a restore point) and then rebooted without issue.
User avatar
TigerRaptor
DBB Fleet Admiral
DBB Fleet Admiral
Posts: 2693
Joined: Tue Feb 01, 2000 6:00 am

Re: IE 7,8 and 9 Zero-Day Exploit

Post by TigerRaptor »

tunnelcat wrote:I don't even use it!
That is what I said to myself one day and out it went.:P :lol:
User avatar
Tunnelcat
DBB Grand Master
DBB Grand Master
Posts: 13740
Joined: Sat Mar 24, 2007 12:32 pm
Location: Pacific Northwest, U.S.A.

Re: IE 7,8 and 9 Zero-Day Exploit

Post by Tunnelcat »

Krom wrote:No, my SSD chewed that update up in a few seconds (most of which was creating a restore point) and then rebooted without issue.
If you have MSE on your system, do you disable it when you do a Windows Update????? I've never done this during past updates.

I think that's what caused my problem. When I went into the event log, besides a whole bunch of kernel errors from a forced reboot, there was one associated with MSE, specifically involving this error: Session "Microsoft Security Essentials OOBE" stopped due to the following error: 0xC000000D, which usually indicates that MSE was interrupted in progress and the file EppOobe.etl has been corrupted. Of course, that could have happened due to the forced shutdown, but who knows? So on a hunch, I then went and turned off MSE, went back to WU and had no problems installing the update this time, especially since it was already downloaded. I also had to delete that stupid .etl file so that MSE could repair it upon another reboot. Seems OK for the moment.

I also turned MSE off on another computer and that update worked without a hitch, AND it's got an even slower hard drive. If the problem is MSE, what a bunch of incompetents at Microsoft. You'd think that WU should know how to deal with MSE being active, or vice versa, during an update. :roll:
Cat (n.) A bipolar creature which would as soon gouge your eyes out as it would cuddle.
User avatar
Krom
DBB Database Master
DBB Database Master
Posts: 16137
Joined: Sun Nov 29, 1998 3:01 am
Location: Camping the energy center. BTW, did you know you can have up to 100 characters in this location box?
Contact:

Re: IE 7,8 and 9 Zero-Day Exploit

Post by Krom »

Actually I did have MSE running at the time...Forgot to uninstall it after spot checking some files. :P
User avatar
Spidey
DBB Grand Master
DBB Grand Master
Posts: 10808
Joined: Thu Jun 28, 2001 2:01 am
Location: Earth

Re: IE 7,8 and 9 Zero-Day Exploit

Post by Spidey »

It’s always advisable to turn off any security suites when installing software, but I never have any problems with WU either way.
User avatar
roid
DBB Master
DBB Master
Posts: 9996
Joined: Sun Dec 09, 2001 3:01 am
Location: Brisbane, Australia
Contact:

Re: IE 7,8 and 9 Zero-Day Exploit

Post by roid »

Installed an update to IE recently (might have been this one).
I was wondering why it's even nessesary.
The only time IE ever gets used is once on a new install - and it's to download another browser.

Can i uninstall it? i remember it being drilled deep into in past windows versions, is that still a thing?
User avatar
Isaac
DBB Artist
DBB Artist
Posts: 7737
Joined: Mon Aug 01, 2005 8:47 am
Location: 🍕

Re: IE 7,8 and 9 Zero-Day Exploit

Post by Isaac »

Isn't IE integrated with Windows' file manager?
❉⊱•═•⊰❉⊱•═•⊰❉⊱•═•⊰❉❉⊱•═•⊰❉⊱•═•⊰❉⊱•═•⊰❉❉⊱•═•⊰❉⊱•═•⊰❉⊱•═•⊰❉
-⎽__⎽-⎻⎺⎺⎻-⎽__⎽--⎻⎺⎺⎻-★ ·:*¨༺꧁༺ :E ༻꧂༻¨*:·.★-⎽__⎽-⎻⎺⎺⎻-⎽__⎽--⎻⎺⎺⎻-
❉⊱•═•⊰❉⊱•═•⊰❉⊱•═•⊰❉❉⊱•═•⊰❉⊱•═•⊰❉⊱•═•⊰❉❉⊱•═•⊰❉⊱•═•⊰❉⊱•═•⊰❉
User avatar
Foil
DBB Material Defender
DBB Material Defender
Posts: 4900
Joined: Tue Nov 23, 2004 3:31 pm
Location: Denver, Colorado, USA
Contact:

Re: IE 7,8 and 9 Zero-Day Exploit

Post by Foil »

Krom wrote:No, my SSD chewed that update up in a few seconds (most of which was creating a restore point) and then rebooted without issue.
Same here. On my son's machine (an old P4) it took about four minutes to update and reboot, but my work rig (with an SSD) did the update and reboot in less than 25s.
Post Reply