Internet Explorer zero day found

Powered by SC Magazine
 

Internet Explorer 10 safe.

Updated: A zero day vulnerability has been discovered that targets Microsoft Internet Explorer and is under active attack.

The exploit was found by researcher Eric Romang on public servers operated by perpetrators behind the Chinese Nitro attacks last year that targeted the chemical industry. 

It works by dropping the file exploit.html which creates an .img and .swf file which Internet Explorer handles as Flash.

The exploit does not affect version 10 of Internet Explorer, the upcoming version of the browser which was open for testing. It works on all Microsoft operating systems.

Microsoft recommended users block ActiveX.

"Set internet and local intranet security zone settings to 'high' to block ActiveX Controls and Active Scripting in these zones," Trustworthy Computing director Yunsun Wee said in a blog post.

"Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and local intranet security zones."

These mitigations would prevent exploitation but could affect usability. Wee said trusted sites should be added to the IE Trusted Sites zone to minimise disruption.

The exploit was quickly added to Rapid 7’s penetration testing framework Metasploit. Developers there worked with contributor Romang to understand the exploit.

The vulnerable version 9 of Internet Explorer was the dominant browser in Australia, according to StatCounter, with about a quarter of users running the software.

Metasploit developer Sinn3r posted screenshots of the exploit in action.

 

Credit: Rapid 7

Copyright © SC Magazine, Australia


Internet Explorer zero day found
 
 
 
Top Stories
Qantas checks in with cloud computing
Impressed with results of public cloud bake-off.
 
Is the legacy of shared services holding WA back?
Auditor-General explains wariness towards central control.
 
Defence renews IBM contract for $264 million
Awards another closed extension.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Carpet cleaner faces court over online testimonials
Jul 4, 2014
The ACCC has initiated proceedings against A Whistle (1979) Pty Ltd, the franchisor of Electrodry...
You can now get 15GB of free online storage using Microsoft OneDrive
Jun 25, 2014
Cloud storage has reached both the capacity and price where it's a viable alternative to local ...
Another clever trick you can perform with Xero
Jun 25, 2014
Here is another way to reach out to particular subsets of your customers using Xero.
Have a phone, tablet and laptop?
Jun 20, 2014
This new Telstra pre-paid 4G mobile hotspot might be useful if you regularly need to use fast ...
This scam isn't going away
Jun 19, 2014
The Australian Competition and Consumer Commission is warning small business people to beware of ...
Latest Comments
Polls
What is delaying adoption of public cloud in your organisation?







   |   View results
Lock-in concerns
  21%
 
Application integration concerns
  3%
 
Security and compliance concerns
  32%
 
Unreliable network infrastructure
  9%
 
Data sovereignty concerns
  25%
 
Lack of stakeholder support
  4%
 
Protecting on-premise IT jobs
  4%
 
Difficulty transitioning CapEx budget into OpEx
  3%
TOTAL VOTES: 491

Vote