Internet Explorer zero day found

Powered by SC Magazine
 

Internet Explorer 10 safe.

Updated: A zero day vulnerability has been discovered that targets Microsoft Internet Explorer and is under active attack.

The exploit was found by researcher Eric Romang on public servers operated by perpetrators behind the Chinese Nitro attacks last year that targeted the chemical industry. 

It works by dropping the file exploit.html which creates an .img and .swf file which Internet Explorer handles as Flash.

The exploit does not affect version 10 of Internet Explorer, the upcoming version of the browser which was open for testing. It works on all Microsoft operating systems.

Microsoft recommended users block ActiveX.

"Set internet and local intranet security zone settings to 'high' to block ActiveX Controls and Active Scripting in these zones," Trustworthy Computing director Yunsun Wee said in a blog post.

"Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and local intranet security zones."

These mitigations would prevent exploitation but could affect usability. Wee said trusted sites should be added to the IE Trusted Sites zone to minimise disruption.

The exploit was quickly added to Rapid 7’s penetration testing framework Metasploit. Developers there worked with contributor Romang to understand the exploit.

The vulnerable version 9 of Internet Explorer was the dominant browser in Australia, according to StatCounter, with about a quarter of users running the software.

Metasploit developer Sinn3r posted screenshots of the exploit in action.

 

Credit: Rapid 7

Copyright © SC Magazine, Australia


Internet Explorer zero day found
 
 
 
Top Stories
ATO to kill off e-Tax
Veteran software to be replaced by more modern myTax.
 
CSC embroiled in CBA IT bribery scandal
ServiceMesh named in alleged dodgy dealing.
 
iiNet and TPG: when two cultures clash
What will happen to a customer favourite after acquisition.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Xero now includes an inventory function built-in
Mar 26, 2015
Xero has added inventory and other major new features to the latest release of its cloud ...
Apple reveals its new MacBook
Mar 13, 2015
Replacing the MacBook Air as Apple's thinnest laptop, the new MacBook comes packed with features.
Xero has released a new version of its app for the iPad
Mar 6, 2015
iPad-wielding Xero users can now take advantage of a new version of the iOS app for the cloud ...
Microsoft is offering Azure for Disaster Recovery to Australian SMBs
Feb 10, 2015
If you haven't talked to your IT provider about disaster recovery, it might be worth discussing ...
The 2015 Xero Roadshow is on: here are the locations and dates
Feb 6, 2015
The 2015 Xero Roadshow kicked off this week - see where you can attend at locations around ...
Latest Comments
Polls
Do you support the Government's data retention scheme?

   |   View results
Yes
  8%
 
No
  92%
TOTAL VOTES: 1053

Vote