Tech/Computer advice from me

IE zero-day flaw will go unpatched on Windows XP

IE zero-day flaw will go unpatched on Windows XP - PC & Tech Authority

Barely three weeks after Microsoft shut-off patching support for Windows XP and a new zero-day flaw for Internet Explorer is likely to go unpatched on the dated operating system.

In a security advisory note post published over the weekend, Microsoft revealed that the remote code execution vulnerability affects versions of Internet Explorer from 6 through to 11 - with these running on all versions of Windows from Vista to 8 and Windows Server 2003 to 2012 R2.

What's most worrying about the flaw however is that - should a user click on a malicious phishing link - it potentially allows hackers to access memory data on a user's computer or even install and delete programmes if the user has administrative user rights.

Microsoft explains more: “An attacker could host a specially crafted website that is designed to exploit this vulnerability through Internet Explorer and then convince a user to view the website.”

The Redmond software giant is now investigating and has assigned the vulnerability an official name of CVE-2014-1776.

"On completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through our monthly security update release process, or an out-of-cycle security update, depending on customer needs."

This 'appropriate action' is likely to entail patches for more recent versions of Windows and Windows Server, but the one notable absence in all this is Windows XP, which went end-of-life on April 8.

"At this time we are aware of limited, targeted attacks. We encourage customers to follow the suggested mitigations outlined in the security advisory while an update is finalised", said a spokesman.

Independent security researcher Graham Cluley said that the vulnerability will probably remain unpatched on Windows XP.

“That's not because it's immune to attack. It's because Microsoft released its last ever security patches for Windows XP on 8 April 2014,” wrote Cluley in a blog post.

“As such, this is worth saying out loud: If you are still running Windows XP you will never receive a patch for this zero-day vulnerability,” he said.


Anti-virus maker Symantec also spotted the vulnerability while FireEye - which protects against advanced persistent threats - has since blogged how the zero-day bypasses Microsoft's ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention) security protections. The firm added that NetMarketShare stats suggest that the vulnerability affects approximately a half of the browser market.

Pedro Bustamante, director of special projects at Malwarebytes, believes that companies that are yet to upgrade to Windows 7 could be targeted by spam and phishing attacks.

“The interim risk to people and businesses using IE 6 to 11, until MS pushes out a patch, is worrying,” he said in an email.

“However, there is also an ongoing problem that anyone still using XP will be completely exposed as long as they continue to use the OS, as there will never be a patch. This is worrying because it can put a significant amount of personal data at risk from highly stealthy attacks, including bank details and other private information.

“Businesses using IE should remain ultra-cautious as they will obviously hold a far greater cache of potentially sensitive information. In large organisations, the default advice of switching to another browser may be difficult to administer. Therefore, if you are running a corporate network, this is a prime opportunity to ensure all software updates are applied, anti-malware and anti-virus definitions are current and increased vigilance around spam and phishing.

All is not lost for organisations still reliant on the OS though; Microsoft has advised firms to deploy version 4.1 of The Enhanced Mitigation Experience Toolkit (EMET) as the software “helps mitigate the exploitation of this vulnerability by adding additional protection layers that make the vulnerability harder to exploit.”

Furthermore, it has advised companies to switch on IE's Enhanced Protected Mode, or set security settings to “High” to stop ActiveX controls - something anti-virus vendor ESET also advises.

“Firstly, don't panic. The known attacks at present are limited in scope and volume. Being reasonably careful about which sites you visit is in itself likely to reduce the risk. On the other hand, users shouldn't lapse into complacency,” said ESET senior research fellow David Harley in an email.

“Setting IE Active Scripting and ActiveX to prompt can be mildly irritating for a user, but it does seems to reduce the attack surface if you actually disallow it on prompt, unless you know you need it, or try disabling it altogether.

“The simplest route is to set IE security levels to 'high', or use Enhanced Protected Mode in IE versions that support it. As a way of generally decreasing the attack surface on an unsupported OS, Windows XP users should already be setting IE security level to 'high'.”
 
Why is it, whenever I try to read that article and the posts above, my Internet Explorer crashes within seconds

Go to http://ninite.com/ and tick the box next to Firefox. Download the installer to your desktop. Close IE, go to your desktop, double click the big blue N. Wait until installation completes. You are now using Firefox.

You will be asked to import your bookmarks (favorites) from other browsers, so click yes. Remove all IE icons from desktop.
 
Or Google Chrome. Although I prefer Firefox as well

I love ninite for software
 
I chose the Firefox option as that is what I use.

Not impressed with just released v29.0, but give me a day or two and everything will be back to normal.

One of my pet gripes is when someone has either the Firefox icon or Chrome icon clearly visible on their desktop, but still use IE! WTF?
 
Why is it, whenever I try to read that article and the posts above, my Internet Explorer crashes within seconds

probably a plug-in. they're 99% of the problem with IE. well, with most browsers.

as for the browser conversation - it's like every other platform/framework conversation, people have their bias and will never change their mind. use what feels most comfortable to you, don't install plug-ins or extensions, and keep it up to date. If you do that you'll be light years ahead of most all over people in terms of security, regardless of which browser you use and which one they use.

And if you don't believe me, go look up security reports.

And btw - if the security report only mentions how many issues the browser has, then it's an awful 'security report' and you should try to find another. Some of the most dangerous software out there to use are the ones that don't have enough of a user base for flaws to be found and reported, and therefore fixed.


So on to the latest vulnerability (different than the one being discussed in the thread)- the one good old Homeland Security felt compelled to come out and advise people to stop using IE for...

"The attack will not work without Adobe Flash," FireEye said. "Disabling the Flash plugin within IE will prevent the exploit from functioning."

The problem isn't IE - the problem is adobe. Yet it's being touted as another IE vulernability. Just another media firestorm on technology that shows majority of them don't have a clue. Adobe flash and reader, as well as java, are responsible for majority of malware/virus infections and it doesn't matter what browser you use if you have those plug-ins installed (kind of, the whole plug-in vs active-x issue aside) - what matters is whether you keep them up to date. This has been going on for years and people still don't get it.

And LO-****ING-L at homeland security releasing an advisory to 'encourage administrators' to set their users up with an 'alternate web browser'

YOU ARE THE REASON WE HAVE SO MANY OLD COPIES OF IE FLOATING AROUND YOU ASS HATS

Seriously, many government websites are designed specifically to only work with Internet Explorer - and an old one at that. IE 7, 8, 9, and 10 are still forcibly put in place, all of them very much out of date, because of the government and their inability to hire contractors that can design websites that don't lock you into a specific version of IE in perpetuity.

Microsoft has gone out of its way, multiple times, to push automatic updates for IE through to as many people as possible. The result was a large group of system admins bitching about how users come in and can't access any of the gov't resources they need to do their job. So we're reduced to finding obscure registry keys to block IE from auto updating.

This 'solution' is not only not an actual solution, but it's being proposed by the people that have created majority of the security problem!

What a complete joke. Who's going to pick up the tab for all the people that can't work because their gov't provided resources use a browser Homeland Security has now told people to stop using? Especially when the browser isn't the problem, it's an Active-x Plugin created and maintained by Adobe, and you can protect yourself by disabling it?

That's right, no one. So your stupid little advisory is not only ridiculously ironic and a joke, it's also completely empty and you know no one is going to follow it. Starving for PR are we?

*sigh* The ignorance by the gov't and the media is just...
 
Last edited by a moderator:
some people still need to run things like IE 9 in order to get on their online software...I see it daily with these pharmaceutical companies because everything they run just isnt compatible with newer software. Microsoft or the proprietary software companies need to come up with ways to work together safely.

and fear, do you know how to reset your IE to its defaults?
 
some people still need to run things like IE 9 in order to get on their online software...I see it daily with these pharmaceutical companies because everything they run just isnt compatible with newer software. Microsoft or the proprietary software companies need to come up with ways to work together safely.

and fear, do you know how to reset your IE to its defaults?

Yeah, those companies suffer from the same thing the government agencies do - they hired people that aren't good what they do, and are now locked into using a specific platform. This is how the top IT contracting companies work in this country - this is the result of their work. It's sad. I see it on a regular basis.

Microsoft's provided standards to help protect against being locked in. These have been around for a long time... My company makes applications that run in browsers and does so without locking into IE. It's doable. You just have to know what you're doing.

The companies that refuse to pay to replace/update their system are running a security risk and they're choosing to do so. I wonder who they'll blame if they have a data breach? I'm sure they'll find a way to shirk the responsibility, everyone else does.
 
There's one gov't resource out there that requires you to use a VPN appliance that was discontinued because of the sheer number of security holes in it. Microsoft even pushed out a patch to block it in IE at one point, because it was so unsecure. That was like 3 years ago.

Yet this is what's protecting access to this gov't resource. The manufacturers of the appliance even suggest you don't use it.

It's truly sad and pathetic the state of local/state/federal gov't IT security. I'm sure the NSA, CIA, FBI and other top federal agencies are doing alright. You can probably find some local/state agencies that have the resources and people in position with knowledge to also do things right. Unfortunately that doesn't seem to be the norm :\
 
"Microsoft has gone out of its way, multiple times, to push automatic updates for IE through to as many people as possible. The result was a large group of system admins bitching about how users come in and can't access any of the gov't resources they need to do their job. "

I fail to see how this is a recommendation for IE. It's a reactive strategy. Were one to examine the CVE and CWE databases...guarantee you IE would be a front runner among browsers!

MS security has improved a lot since the days of old. but, in our zeal to belittle gov't contractors, let's not get carried away into convincing people that IE is somehow a safer alternative to whatever they are currently using.

I need to find more detail....but the DHS post suggested that the exploit can be executed without the Adobe plug-in. The fault lies in memory management routines. and that wraps functionality in from a lot of places: coding languages, sandboxes, OS memory managers, coding practices, run-time environments.....
 
"Microsoft has gone out of its way, multiple times, to push automatic updates for IE through to as many people as possible. The result was a large group of system admins bitching about how users come in and can't access any of the gov't resources they need to do their job. "

I fail to see how this is a recommendation for IE. It's a reactive strategy. Were one to examine the CVE and CWE databases...guarantee you IE would be a front runner among browsers!

MS security has improved a lot since the days of old. but, in our zeal to belittle gov't contractors, let's not get carried away into convincing people that IE is somehow a safer alternative to whatever they are currently using.

I need to find more detail....but the DHS post suggested that the exploit can be executed without the Adobe plug-in. The fault lies in memory management routines. and that wraps functionality in from a lot of places: coding languages, sandboxes, OS memory managers, coding practices, run-time environments.....

Well - there's two vulnerabilities out right now. The one I was talking about, with the Homeland Security quote, is about the one that's with the Adobe Flash Plug-in. The other one is just on IE. My commentary was on the lunacy of someone from Homeland Security making such a statement because
a - it's not IE, it's a plug-in that's notorious for having problems, and you can easily get around it
b- you can't use majority of government resources with a browser other than IE.

It was a stupid 'announcement' to make. It gives the wrong advice on how to fix it, and even if it was the right advice it's not actionable for gov't contractors...

I'm not going to try to convince anyone to use IE.

My belittlement of gov't contractors had to do with the large scale of gov't resources that have been developed that cost a premium that force users to be locked into some archaic version of IE. It's all over the place. It's in the private sector too. It's a damned shame because I've got many customers running around with IE9, or a super out dated version of the java runtime environment, or an old adobe flash player because that's what the gov't requires because that's how the system was written.

It's a real problem and I'm hardly the only one experiencing it. Spend some time in some Sys Admin forums (not literal forums like BGO is a forum, but the more general use of the word) and you'll see for yourself.

As for MS and their track record on security... i guess we'll just disagree.
 
Last edited by a moderator:
Well - there's two vulnerabilities out right now. The one I was talking about, with the Homeland Security quote, is about the one that's with the Adobe Flash Plug-in. The other one is just on IE. My commentary was on the lunacy of someone from Homeland Security making such a statement because
a - it's not IE, it's a plug-in that's notorious for having problems, and you can easily get around it
b- you can't use majority of government resources with a browser other than IE.

It was a stupid 'announcement' to make. It gives the wrong advice on how to fix it, and even if it was the right advice it's not actionable for gov't contractors...

I'm not going to try to convince anyone to use IE.

My belittlement of gov't contractors had to do with the large scale of gov't resources that have been developed that cost a premium that force users to be locked into some archaic version of IE. It's all over the place. It's in the private sector too. It's a damned shame because I've got many customers running around with IE9, or a super out dated version of the java runtime environment, or an old adobe flash player because that's what the gov't requires because that's how the system was written.

It's a real problem and I'm hardly the only one experiencing it. Spend some time in some Sys Admin forums (not literal forums like BGO is a forum, but the more general use of the word) and you'll see for yourself.

As for MS and their track record on security... i guess we'll just disagree.

Were you working in the 80s and 90s you'd know where I'm coming from on MS products. It wasn't until the 2000s that MS got serious w/STRIDE, DREAD and some security focus. They have gotten better. The numbers, however, aren't favorable for any system that sports over 40 million lines of code. The registry itself has millions of possible configuration settings.

Government IT policy requires maximum use of COTS products. So, I'm not sure where the real burden falls. And, obviously, IT procurement is one among many competing needs. You, obviously, are very familiar with notion that there are millions upon millions of locs in libraries, .dlls, etc.

Bad design, bad coding practices, inherently insecure languages (e.g., C) lie at the heart of the problem.
 
so here's an interesting one for someone to explain:

sittin at my desk this morning. cell phone makes a very low ringing sound. my vx mail is being dialed!

I power the phone down. restart. couple mins later...vx mail is being dialed! yea...it's psswd protected. just the same. I never once activated vx mail.

hack or just a rogue setting I'm clueless about?

Android.
 
so here's an interesting one for someone to explain:

sittin at my desk this morning. cell phone makes a very low ringing sound. my vx mail is being dialed!

I power the phone down. restart. couple mins later...vx mail is being dialed! yea...it's psswd protected. just the same. I never once activated vx mail.

hack or just a rogue setting I'm clueless about?

Android.

any chance you have a broken screen? when my Galaxy S3 screen broke my phone did all sorts of weird things because it was registering weird screen presses. Including dialing 911 while locked multiple, multiple times (that was the breaking point for getting a new phone out of contract for me - I couldn't handle accidentally calling 911 anymore... they were eventually going to do something to me for it...)

i'd throw the phone in debug mode and figure out what it is otherwise. you could also think about what's changed recently and troubleshoot that way.
 
Were you working in the 80s and 90s you'd know where I'm coming from on MS products. It wasn't until the 2000s that MS got serious w/STRIDE, DREAD and some security focus. They have gotten better. The numbers, however, aren't favorable for any system that sports over 40 million lines of code. The registry itself has millions of possible configuration settings.

Government IT policy requires maximum use of COTS products. So, I'm not sure where the real burden falls. And, obviously, IT procurement is one among many competing needs. You, obviously, are very familiar with notion that there are millions upon millions of locs in libraries, .dlls, etc.

Bad design, bad coding practices, inherently insecure languages (e.g., C) lie at the heart of the problem.

I guess my disagreement is more with you saying "they've gotten better." Your history of MS going back to the 80's is spot on as far as I'm aware of.

But MS has moved on to not just be 'better' - they're industry leader in security right now and have been for a while. They're leading the global fight against spam and malicious activity as well.

There are actual security companies out there that do more than microsoft, and produce more secure competitor products than microsoft. But in terms of being a giant tech company that produces products across a wide range, and a company that isn't oriented around security, they're out front way ahead of their competition (their competition being Google, Apple, Oracle, Adobe, and some others)

Google would have easily been better than MS by now, but Google got taken over by profit-margin-increasing execs and board members and has shifted to being all about making the extra buck, and they've lost their edge as a result.
 
As for the big IE vulnerability everyone was asking about, ehre's the breakdown we've come up with and what we're doing about it.

The vulnerability exists in an archaic rendering library that is not really used by most websites these days, but has been kept around in Internet Explorer for backward comparability purposes (shocker!) To exploit the vulnerability you need to make/alter a website to target that archaic rendering library to force IE to actually use it, and then you exploit the library to gain access to the memory on the machine.

Microsoft has not yet released a fix.

You can however run the following commands from an elevated command prompt:
regsvr32.exe /u /s "%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll"
regsvr32.exe /u /s "%CommonProgramFiles(x86)%\Microsoft Shared\VGX\vgx.dll"

You do not need the second command if you're on a 32 bit machine.

This will unregister the library in question. So now you can't be exploited. The down side is that if you use a site that is targeting that old rendering library, the site will not work. Whether or not that is an impact for you depends on what websites you use. I'm willing to bet for majority of people this is not an issue - we're convinced enough we're pushing this change out to all of our customers, and we're pretty confident there will be no issues because of it.

When microsoft releases and update that should fix the problem. There is no public ETA on that as far as I'm aware.

Happy interweb surfing!
 
I guess my disagreement is more with you saying "they've gotten better." Your history of MS going back to the 80's is spot on as far as I'm aware of.

But MS has moved on to not just be 'better' - they're industry leader in security right now and have been for a while. They're leading the global fight against spam and malicious activity as well.

There are actual security companies out there that do more than microsoft, and produce more secure competitor products than microsoft. But in terms of being a giant tech company that produces products across a wide range, and a company that isn't oriented around security, they're out front way ahead of their competition (their competition being Google, Apple, Oracle, Adobe, and some others)

Google would have easily been better than MS by now, but Google got taken over by profit-margin-increasing execs and board members and has shifted to being all about making the extra buck, and they've lost their edge as a result.

ok! no disrespect...but we'll just pretend patch Tuesday never happens each month.

we can also discuss at another time what you mean by way ahead!

the foundation of the dang OS has always been vulnerable by not taking advantage of Intel architecture that allows for segregation into 4 security domains. the NT core forever has been a vulnerable user mode/system mode dichotomy. hackers have been exploiting this architecture forever. granted, most attacks these days have moved from the OS up to the application layer.

MS security has gotten better - especially after the professional community began lampooning them and companies started losing big money in hacks. the leading OS? well.....no matter how you cut it..MAC has fewer hacks each year. again, were you to perform counts in CVE or CWE...you would find, I am sure, MS products leading the pack..if for no other reason than the shere volume of code. more secure, btw, than SELinux?
 
Why would we pretend patch tuesday never happens? It's the biggest part that supports my argument...

looking at the # of vulnerabilities found and patched is not a good metric. it's too simple and leaves too much out.....

Apple has a track record of configuring their devices to lie about security implementations in place on the device in order to connect to services that require those security implementations. Because actually implementing the security was too hard to them, so they figured it was better to just lie about it.

You sure they're better than microsoft? You sure the lack of listed vulnerabilities is because they're better at security? Is that a claim you really want to stick to?

Because most legit criticism I've seen is that Apple hasn't had the market share to warrant the attention.

Look at the last few years... the rise in mac vulnerabilities. look at how Apple's responded. look at the iOS problems.

if I were starting a tech company today, i sure as shit wouldn't model my security model after apple. they lost a lot of credibility when they configured their iOS platform to lie about its security features. they've lost even more in the wake of increasing number of malicious software targeting mac - their response was to deny it and pretend it wasn't happening...

i'd definitely consider modeling it after microsoft.
 

Users Who Are Viewing This Thread (Total: 1, Members: 0, Guests: 1)

Help Users

You haven't joined any rooms.

    You haven't joined any rooms.
    Top