Internet Explorer Exploit

By Stix1972, 22 November, 2009, 7 Comments
Grizzly Groundswell

If you use an older version of IE explorer, you need to update it now.   There is another exploit on IE older version , IE 6 and IE 7.

A new exploit targeting Internet Explorer was published to the BugTraq mailing list yesterday. Symantec has conducted further tests and confirmed that it affects Internet Explorer versions 6 and 7 as well. The exploit currently exhibits signs of poor reliability, but we expect that a fully-functional reliable exploit will be available in the near future.  When this happens, attackers will have the ability to insert the exploit into Web sites, infecting potential visitors.  For an attacker to launch a successful attack, they must lure victims to their malicious Web page or a Web site they have compromised. In both cases, the attack requires JavaScript to exploit Internet Explorer.

The exploit targets a vulnerability in the way Internet Explorer uses cascading style sheet (CSS) information. CSS is used in many Web pages to define the presentation of the sites’ content. Symantec currently detects the exploit with the Bloodhound.Exploit.129 antivirus signature and is working on new signatures now. Symantec IPS protection also currently detects this exploit with signatures HTTP Microsoft IE Generic Heap Spray BO and HTTP Malicious Javascript Heap Spray BO. A new IPS signature, HTTP IE Style Heap Spray BO, has also been created for this specific exploit. To minimize the chances of being affected by this issue, Internet Explorer users should ensure their antivirus definitions are up to date, disable JavaScript and only visit Web sites they trust until fixes are available from Microsoft.  (Symatec)

Or change your web browser to FireFox, Opera, Chrome or many others that are safer than IE Explorer.

  • Share/Bookmark
WGGRN Merchandise Become a Host on WGGRN.com WGGRN Merchandise Grizzly Temerity private Registration ADVERTISE with us! You Deserve The Reach GrizzlyTemerity$1.99domains GrizzlyTemerity domains Do You Have an Ear for Music? - Support WGGRN.com on Live365 Shelly&CompoComeOnHomeAmerica!500x
Line Break

Author: Stix1972 (21 Articles)

Doug is the owner of Stix Blog. He has also contributed to Grizzly Groundswell, Heading Right, Snooper Report, Modern Conservative. He is also the Managing Editor for Technology at 73 Wire. And can be found on twitter at stix1972. You can also leave me a voice mail at (618) 688-2156

7 Responses {+}
Leave a Reply