Internet Explorer zero day found

Powered by SC Magazine
 

Internet Explorer 10 safe.

Updated: A zero day vulnerability has been discovered that targets Microsoft Internet Explorer and is under active attack.

The exploit was found by researcher Eric Romang on public servers operated by perpetrators behind the Chinese Nitro attacks last year that targeted the chemical industry. 

It works by dropping the file exploit.html which creates an .img and .swf file which Internet Explorer handles as Flash.

The exploit does not affect version 10 of Internet Explorer, the upcoming version of the browser which was open for testing. It works on all Microsoft operating systems.

Microsoft recommended users block ActiveX.

"Set internet and local intranet security zone settings to 'high' to block ActiveX Controls and Active Scripting in these zones," Trustworthy Computing director Yunsun Wee said in a blog post.

"Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and local intranet security zones."

These mitigations would prevent exploitation but could affect usability. Wee said trusted sites should be added to the IE Trusted Sites zone to minimise disruption.

The exploit was quickly added to Rapid 7’s penetration testing framework Metasploit. Developers there worked with contributor Romang to understand the exploit.

The vulnerable version 9 of Internet Explorer was the dominant browser in Australia, according to StatCounter, with about a quarter of users running the software.

Metasploit developer Sinn3r posted screenshots of the exploit in action.

 

Credit: Rapid 7

Copyright © SC Magazine, Australia


Internet Explorer zero day found
 
 
 
Top Stories
Tech SWAT teams kicking down the digital door
From dam engineers in Ecuador to Sydney light-rail gurus, Cardno's global CIO Karen Wagner is linking up her widespread organisation.
 
AusPost board approves Fujitsu outsourcing
End user computing to be handed over to partner.
 
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Xerocon is heading to Melbourne!
Jul 1, 2015
We're not saying Xero is our FAVOURITE or anything, but Xero's 2015 Xerocon conference is being ...
New Microsoft Office apps for Android phones
Jun 26, 2015
Microsoft's latest Office apps for Android now work on phones as well as tablets, further ...
Windows 10 UK price revealed, but don't believe everything you hear
Jun 26, 2015
Windows 10 £99 price tag for users in the UK (who presumably don't already have Win 7 Pro ...
Now Xero notifies iOS users of new transactions
Jun 24, 2015
The latest version of Xero's iPhone app includes notifications when new transactions arrive from ...
Your Essential Cloud Toolbox
Jun 22, 2015
When BIT interviewed Receipt Bank country manager Sophie Hossack, we asked for her thoughts on ...
Latest Comments
Polls
Is site blocking effective in stopping piracy?


   |   View results
Yes
  2%
 
No
  86%
 
Somewhat
  12%
TOTAL VOTES: 591

Vote