Yikes - many web sites compromised - and use exploit in IE WHICH MS HAS NOT PATCHED

Discussions about anything Computer Hardware Related. Overclocking, underclocking and talk about the latest or even the oldest technology. PCA Reviews feedback
User avatar
wvjohn
Posts: 9238
Joined: Wed Nov 22, 2000 7:09 am
Contact:

Yikes - many web sites compromised - and use exploit in IE WHICH MS HAS NOT PATCHED

Post by wvjohn »

http://zdnet.com.com/2100-1105_2-5247187.html

according to the article they are reccomending highest security settings
<a href="http://www.heatware.com/eval.php?id=123" target="_blank" >Heatware</a>
User avatar
DocSilly
Posts: 1558
Joined: Wed Nov 22, 2000 8:24 am
Location: Germany
Contact:

Post by DocSilly »

Just use Firefox ;) ... ok ok, it's not perfect and has it's own issues but less than IE ...
<a href="http://www.mozilla.org/products/firefox/" title="Get Firefox - Web Browsing Redefined"><img src="http://www.mozilla.org/products/firefox/buttons/takebacktheweb_small.png" width="125" height="50" border="0" alt="Get Firefox"></a> <a href="http://www.mozilla.org/products/thunderbird/" title="Get Thunderbird - Reclaim Your Inbox"><img src="http://www.mozilla.org/products/thunderbird/buttons/reclaimyourinbox_small.png" width="125" height="80" border="0" alt="Get Thunderbird"></a>
User avatar
d_b
Posts: 2617
Joined: Wed Nov 22, 2000 6:16 am
Location: Culver Indiana

Post by d_b »

wouldn't a firewall be helpful?
I'm not lazy by nature, I work very hard at being lazy.
User avatar
darcy
Posts: 6271
Joined: Tue Jun 01, 2004 9:33 pm
Location: NYC

Post by darcy »

Originally posted by d_b
wouldn't a firewall be helpful?

speakin' of which,,, i'm behind a router, and have my internet security settings still set @ medium. u reckon i should up it? what've the rest o' u peeps done?
Briquette, 1992 - 2008 ~ < Forever In Our Hearts >

Lily, 1995 - 2009 ~ < Forever In Our Hearts >

The best and most beautiful things in the world cannot be seen or even touched.
They must be felt with the heart. ~ Helen Keller.
User avatar
Busby
Golden Member
Posts: 1890
Joined: Tue Nov 28, 2000 6:25 pm
Location: Atlanta Area, GA, USA
Contact:

Post by Busby »

I got medium settings with ZA running. Medium settings should be fine as it should pop up with a window asking you to install blah blah. Your router should help protect you darcy as it would block the incoming requests usually.
<a href="mailto:busby1218@charter.net">
<img src="http://justinbusby.com:8080/signature.gif" border="0"></a>
User avatar
dadx2mj
Posts: 4359
Joined: Wed Nov 22, 2000 12:24 pm
Location: So Cal

Post by dadx2mj »

I am braving it with medium security settings and the router. Hopefully MS wont drag their feet on patching this hole up.
Image
User avatar
darcy
Posts: 6271
Joined: Tue Jun 01, 2004 9:33 pm
Location: NYC

Post by darcy »

thanx, busby :)

thing is, once i was networked and behind a router, i disabled my lappie's built-in firewall as thought it was unnecessary. should i enable it again, or is that overkill?
Briquette, 1992 - 2008 ~ < Forever In Our Hearts >

Lily, 1995 - 2009 ~ < Forever In Our Hearts >

The best and most beautiful things in the world cannot be seen or even touched.
They must be felt with the heart. ~ Helen Keller.
blade
Posts: 9113
Joined: Wed Nov 22, 2000 1:56 am
Location: LV-426
Contact:

Post by blade »

i'm behind a router, and have my internet security settings still set @ medium. u reckon i should up it? what've the rest o' u peeps done?


I set mine to high. I like to play it safe. I also have a router, use kerio software firewall and have the XP firewall on too. I don't believe in 'overkill'. :d ;)


Thanks John :)
[align=center]<img src="http://www.statgfx.com/statgfx/folding/?&username=blade&border=0,0,64&custom=21,138,255&label=79,79,255&header=149,202,255&stats=0,255,255&bgcolor=0,0,181&trans=no&template=fah_original&.jpg" alt="www.Statgfx.com" />
<img src="http://www.pcabusers.org/funnies/monkey2.gif">
<i><small>"Too much monkee business"</i></small>[/align]
User avatar
darcy
Posts: 6271
Joined: Tue Jun 01, 2004 9:33 pm
Location: NYC

Post by darcy »

Originally posted by blade
I set mine to high. I like to play it safe. I also have a router, use kerio software firewall and have the XP firewall on too. I don't believe in 'overkill'. :d ;)

Thanks John :)

message received! :)
Briquette, 1992 - 2008 ~ < Forever In Our Hearts >

Lily, 1995 - 2009 ~ < Forever In Our Hearts >

The best and most beautiful things in the world cannot be seen or even touched.
They must be felt with the heart. ~ Helen Keller.
User avatar
DocSilly
Posts: 1558
Joined: Wed Nov 22, 2000 8:24 am
Location: Germany
Contact:

Post by DocSilly »

Here some answers of my own:


Q: I'm behind a router, am I fine now?

A: Nope, it won't prevent the installation of the malware and if the trojan is calling home for action it also won't help ... though it would prevent your trojaned system from being accessible from the outside (unless you're in the DMZ).


Q: Will a firewall be helpful?

A: No and yes. A personal firewall on your PC won't prevent the installation of the malware but it should catch the trojan when it tries to access the internet. For an external firewall see first question.


Q: I'm running antivirus software, am I still at risk?

A: Yes, you're still at risk for now and it's not 100% certain that one of the next virusdefenition updates will catch the malicious code.


Q: IE is soooo great, security at high is lame, what is the minimum setting to adjust so that I'm fairly secure?

A: Sigh, some people can't be helped ;) .... make sure that at least "Active Scripting" is disabled.


Q: I'm using Mozilla/Firefox/(Opera), am I at risk?

A: Good choice and no, you're not at risk from this exploit. Mozilla/Firefox is not perfect, it is just less exploited so far. There are still some risks with this browser, especially with extensions. They don't have a verification system yet and it is easy to install one from an unknown page ... but you're pretty safe when you only install extensions from http://update.mozilla.org/ ;)
<a href="http://www.mozilla.org/products/firefox/" title="Get Firefox - Web Browsing Redefined"><img src="http://www.mozilla.org/products/firefox/buttons/takebacktheweb_small.png" width="125" height="50" border="0" alt="Get Firefox"></a> <a href="http://www.mozilla.org/products/thunderbird/" title="Get Thunderbird - Reclaim Your Inbox"><img src="http://www.mozilla.org/products/thunderbird/buttons/reclaimyourinbox_small.png" width="125" height="80" border="0" alt="Get Thunderbird"></a>
User avatar
d_b
Posts: 2617
Joined: Wed Nov 22, 2000 6:16 am
Location: Culver Indiana

Post by d_b »

Thanks Doc. :) Now if you could only improve my connection speed. :D
I'm not lazy by nature, I work very hard at being lazy.
User avatar
darcy
Posts: 6271
Joined: Tue Jun 01, 2004 9:33 pm
Location: NYC

Post by darcy »

Originally posted by DocSilly
A: Sigh, some people can't be helped ;) .... make sure that at least "Active Scripting" is disabled.
this the scriptin' referred to? ~ Image
i see nothing else w/ the words "scripting"..


bw, i've enabled XP's firewall again. will this affect the transfer o' files to second system?
Briquette, 1992 - 2008 ~ < Forever In Our Hearts >

Lily, 1995 - 2009 ~ < Forever In Our Hearts >

The best and most beautiful things in the world cannot be seen or even touched.
They must be felt with the heart. ~ Helen Keller.
User avatar
DocSilly
Posts: 1558
Joined: Wed Nov 22, 2000 8:24 am
Location: Germany
Contact:

Post by DocSilly »

Internet Options > Security > Internet > Custom Level

Image

Though this might break many other webpages ;)
Use Firefox/Mozilla instead ...
<a href="http://www.mozilla.org/products/firefox/" title="Get Firefox - Web Browsing Redefined"><img src="http://www.mozilla.org/products/firefox/buttons/takebacktheweb_small.png" width="125" height="50" border="0" alt="Get Firefox"></a> <a href="http://www.mozilla.org/products/thunderbird/" title="Get Thunderbird - Reclaim Your Inbox"><img src="http://www.mozilla.org/products/thunderbird/buttons/reclaimyourinbox_small.png" width="125" height="80" border="0" alt="Get Thunderbird"></a>
User avatar
darcy
Posts: 6271
Joined: Tue Jun 01, 2004 9:33 pm
Location: NYC

Post by darcy »

ok. thank u :)
Briquette, 1992 - 2008 ~ < Forever In Our Hearts >

Lily, 1995 - 2009 ~ < Forever In Our Hearts >

The best and most beautiful things in the world cannot be seen or even touched.
They must be felt with the heart. ~ Helen Keller.
User avatar
FlyingPenguin
Flightless Bird
Posts: 33162
Joined: Wed Nov 22, 2000 11:13 am
Location: Central Florida
Contact:

Post by FlyingPenguin »

Microsoft has released a patch for this now via Windows Update:

http://news.com.com/Microsoft+posts+wor ... ws.1002.20
---
“The Government of Spain will not applaud those who set the world on fire just because they show up with a bucket.” - Prime Minister of Spain, Pedro Sánchez

Image
Post Reply