Thursday, September 28, 2006 8:59 AM cmosby

SANS - Internet Storm Center - MSIE: One patched, one pops up again (setslice)

MSIE: One patched, one pops up again (setslice) (NEW)

Published: 2006-09-28,
Last Updated: 2006-09-28 02:08:55 UTC by Swa Frantzen (Version: 1)

If you remember the month of browser bugs series of exploits back in July, there was a denial of service there that appears to have code execution after all. Coincidence or not, it got publicly released after the out of cycle Microsoft patch for MSIE.

So: No, surfing with MSIE is still not safe.

References

Defenses

  • Use an alternate browser (yeah, we sound like a broken record). But diversity really helps make the bad guys' job harder.
  • Disable ActiveX (take care: windowsupdate needs it, so you need to trust those sites)
  • Set the killbit:
    {844F4806-E8A8-11d2-9652-00C04FC30871}
    [unconfirmed at this point it's the right killbit, so proceed with caution]
  • Keep antivirus signatures up to date.
  • Keep an eye out for a patch from Microsoft.
  • ...
--
Swa Frantzen -- Section 66

SANS - Internet Storm Center - Cooperative Cyber Threat Monitor And Alert System.

Filed under: , ,

Comments

No Comments