PDA

View Full Version : IE rupa


Equilibrium
26.11.2003., 08:47
nije mi se dalo prevodit, pa eto u originalu:

A set of five unpatched scripting vulnerabilities in Internet Explorer creates a mechanism for hackers to compromise targeted PCs.

The vulnerabilities, unearthed by Chinese security researcher Liu Die Yu, enable malicious Web sites and viruses to bypass the security zone settings in IE6. Used in combination, the flaws might be exploited to seize control of vulnerable PCs.

Proof of Concept exploits have been released by Liu Die Yu to validate his warnings.

Microsoft has yet to patch the flaws. But users can protect themselves against the flaws by disabling active scripting or by using an alternative browser.

Thomas Kristensen, CTO of security Web site Secunia, told The Register that the five distinct vulns could used in combination to install executables (viruses, Trojans and porn diallers). Secunia describes the vulnerabilities as "extremely critical".

Despite this, Kristensen warns that Microsoft is unlikely to break its newly instituted monthly release cycle to release a stand-alone IE patch unless a vulnerability was widely exploited. Pending the availability of a patch, Secunia advises all IE users to disable active scripting.

The drawback of this workaround is that with some Web sites certain functions won't work unless scripting is enabled. IE users should define any sites they need to use as trusted so that they can continue to use scripting on those sites alone, Kristensen advised.

Maky
26.11.2003., 12:22
Kad je objavljen ovaj sigurnosni propust ?, jer sam zadnji update radio prije tjedan dana i čitajući tvoj post odmah sam otišao na win update no nema nikakav critical update bar do danas do 12:30.

slafko
26.11.2003., 12:36
Secunia advises all IE users to disable active scripting. to je jedna od stvari koje radim po difoltu. bar na svojim kompovima. :)

Equilibrium
26.11.2003., 13:36
Maky kaže:
Kad je objavljen ovaj sigurnosni propust ?, jer sam zadnji update radio prije tjedan dana i čitajući tvoj post odmah sam otišao na win update no nema nikakav critical update bar do danas do 12:30.

Microsoft has yet to patch the flaws
Objavljeno na TheRegisteru jučer. Dakle, updatea još nema.

Maky
27.11.2003., 07:48
Nema ni danas update-a :confused:

finalnifantazista
28.11.2003., 20:37
Equilibrium kaže:
Secunia advises all IE users to disable active scripting.

A gdje to?

Mlaen
30.11.2003., 16:51
Broji li itko koliko je već tih zakrpi izbacio taj microsoft:zvrko:

Maky
01.12.2003., 00:35
finalnifantazista kaže:
A gdje to?

desni klik na IE, security, custom level, dolje nađeš scripring, pa active scripting > disabled :)

finalnifantazista
02.12.2003., 00:35
Maky kaže:
desni klik na IE, security, custom level, dolje nađeš scripring, pa active scripting > disabled :)

Thanks!