Page 1 of 2

Yikes - many web sites compromised - and use exploit in IE WHICH MS HAS NOT PATCHED

Posted: Fri Jun 25, 2004 2:44 pm
by wvjohn
http://zdnet.com.com/2100-1105_2-5247187.html

according to the article they are reccomending highest security settings

Posted: Fri Jun 25, 2004 6:12 pm
by DocSilly
Just use Firefox ;) ... ok ok, it's not perfect and has it's own issues but less than IE ...

Posted: Fri Jun 25, 2004 8:47 pm
by d_b
wouldn't a firewall be helpful?

Posted: Fri Jun 25, 2004 9:18 pm
by darcy
Originally posted by d_b
wouldn't a firewall be helpful?

speakin' of which,,, i'm behind a router, and have my internet security settings still set @ medium. u reckon i should up it? what've the rest o' u peeps done?

Posted: Fri Jun 25, 2004 9:22 pm
by Busby
I got medium settings with ZA running. Medium settings should be fine as it should pop up with a window asking you to install blah blah. Your router should help protect you darcy as it would block the incoming requests usually.

Posted: Fri Jun 25, 2004 9:25 pm
by dadx2mj
I am braving it with medium security settings and the router. Hopefully MS wont drag their feet on patching this hole up.

Posted: Fri Jun 25, 2004 9:30 pm
by darcy
thanx, busby :)

thing is, once i was networked and behind a router, i disabled my lappie's built-in firewall as thought it was unnecessary. should i enable it again, or is that overkill?

Posted: Fri Jun 25, 2004 9:45 pm
by blade
i'm behind a router, and have my internet security settings still set @ medium. u reckon i should up it? what've the rest o' u peeps done?


I set mine to high. I like to play it safe. I also have a router, use kerio software firewall and have the XP firewall on too. I don't believe in 'overkill'. :d ;)


Thanks John :)

Posted: Fri Jun 25, 2004 9:51 pm
by darcy
Originally posted by blade
I set mine to high. I like to play it safe. I also have a router, use kerio software firewall and have the XP firewall on too. I don't believe in 'overkill'. :d ;)

Thanks John :)

message received! :)

Posted: Sat Jun 26, 2004 6:08 am
by DocSilly
Here some answers of my own:


Q: I'm behind a router, am I fine now?

A: Nope, it won't prevent the installation of the malware and if the trojan is calling home for action it also won't help ... though it would prevent your trojaned system from being accessible from the outside (unless you're in the DMZ).


Q: Will a firewall be helpful?

A: No and yes. A personal firewall on your PC won't prevent the installation of the malware but it should catch the trojan when it tries to access the internet. For an external firewall see first question.


Q: I'm running antivirus software, am I still at risk?

A: Yes, you're still at risk for now and it's not 100% certain that one of the next virusdefenition updates will catch the malicious code.


Q: IE is soooo great, security at high is lame, what is the minimum setting to adjust so that I'm fairly secure?

A: Sigh, some people can't be helped ;) .... make sure that at least "Active Scripting" is disabled.


Q: I'm using Mozilla/Firefox/(Opera), am I at risk?

A: Good choice and no, you're not at risk from this exploit. Mozilla/Firefox is not perfect, it is just less exploited so far. There are still some risks with this browser, especially with extensions. They don't have a verification system yet and it is easy to install one from an unknown page ... but you're pretty safe when you only install extensions from http://update.mozilla.org/ ;)

Posted: Sat Jun 26, 2004 11:10 am
by d_b
Thanks Doc. :) Now if you could only improve my connection speed. :D

Posted: Sat Jun 26, 2004 12:01 pm
by darcy
Originally posted by DocSilly
A: Sigh, some people can't be helped ;) .... make sure that at least "Active Scripting" is disabled.
this the scriptin' referred to? ~ Image
i see nothing else w/ the words "scripting"..


bw, i've enabled XP's firewall again. will this affect the transfer o' files to second system?

Posted: Sat Jun 26, 2004 5:30 pm
by DocSilly
Internet Options > Security > Internet > Custom Level

Image

Though this might break many other webpages ;)
Use Firefox/Mozilla instead ...

Posted: Sat Jun 26, 2004 5:44 pm
by darcy
ok. thank u :)

Posted: Sun Jul 04, 2004 7:19 am
by FlyingPenguin
Microsoft has released a patch for this now via Windows Update:

http://news.com.com/Microsoft+posts+wor ... ws.1002.20