Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Microsoft Warns IE Users Of 'Highly Critical' Flaw

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Latest Breaking News Donate to DU
 
IDemo Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 08:35 AM
Original message
Microsoft Warns IE Users Of 'Highly Critical' Flaw
Edited on Fri Mar-24-06 09:27 AM by IDemo
March 24, 2006 2:30 a.m. EST

Yvonne Lee - All Headline News Staff Reporter

New York, New York (AHN) - Microsoft is warning about a "highly critical" flaw that could make millions of Internet Explorer users vulnerable to hackers.

The software giant plans to release a pre-patch advisory for the flaw, which is the result of a mistake in the processing of the "createTextRange()" method call applied on a radio button control.

PCMag reports that security firm Secunia Research discovered the code execution hole.

Secunia says in an alert, "This can be exploited by a malicious Web site to corrupt memory in a way that allows the program flow to be redirected to the heap."

http://www.allheadlinenews.com/articles/7002904469

edit: change subject line
Printer Friendly | Permalink |  | Top
rodeodance Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 08:38 AM
Response to Original message
1. yeeks, not another one!
Printer Friendly | Permalink |  | Top
 
Tesha Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 01:38 PM
Response to Reply #1
20. Another week, another set of Microsoft flaws.
Just as sure as the sun rising each morning...

Tesha
Printer Friendly | Permalink |  | Top
 
cantstandbush Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 08:41 AM
Response to Original message
2. I am puter illiterate. How do I get the latest info on what to do? n/t
Printer Friendly | Permalink |  | Top
 
GeorgeGist Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 09:02 AM
Response to Reply #2
3. go here
Printer Friendly | Permalink |  | Top
 
IDemo Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 09:07 AM
Response to Reply #2
4. There is no patch yet available, but you can disable active scripting
Edited on Fri Mar-24-06 09:09 AM by IDemo
In Internet Explorer, go to 'tools','internet options','security',and select 'custom level'. Scroll down towards the bottom to 'scripting','active scripting', and select 'disable'. You may need to restart IE for any changes made here to take effect.

Or, use the Firefox browser instead of IE, which is what I do!
Printer Friendly | Permalink |  | Top
 
Tandalayo_Scheisskopf Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 09:11 AM
Response to Reply #4
5. Yup.
Easiest way under the sun to avoid these IE bugs. Just don't use IE.

There are too many other non-Mickeysoft browsers out there that don't have these vulnerabilities. Firefox is the best of them, although Opera ain't far behind. Both are free.
Printer Friendly | Permalink |  | Top
 
sendero Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 11:12 AM
Response to Reply #5
12. He he...
... Opera is the best of them, but Firefox is not far behind :) :) :)
Printer Friendly | Permalink |  | Top
 
OregonBlue Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 11:49 AM
Response to Reply #4
14. Done, thanks
Printer Friendly | Permalink |  | Top
 
CountAllVotes Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 12:23 PM
Response to Reply #4
16. thanks for the tip!
Done here too!

:kick:
Printer Friendly | Permalink |  | Top
 
Tempest Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 10:35 AM
Response to Reply #2
10. The best thing you can do
Is to dump IE and go to Firefox.
Printer Friendly | Permalink |  | Top
 
fleabert Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 11:08 AM
Response to Reply #2
11. replace IE with Firefox...
Printer Friendly | Permalink |  | Top
 
jbnow Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 12:34 PM
Response to Reply #11
18. I use Firefox but lately
when I go to my mail using it it encounters a problem and closes all open Firefox down. So I've been using IE to get my mail.

Hope I can figure out my Firefox/mail issue!
Printer Friendly | Permalink |  | Top
 
ConcernedCanuk Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 03:05 PM
Response to Reply #18
25. I had problems with FireFox, so I went back to Mozilla 1.6
.
.
.

I use an Avant Browser skin on top of IE for the rare occasions I use IE - which I appear to need to do when I want to use the "Rich Text Editor" in Hotmail's "Tools" when I want to make a "fancy" e-mail - different fonts and so on

But Mozilla is my default browser, and quite happy with it

My system is only 350Mhz with Win98SE and 256MB RAM

But sings along quite nicely with Mozilla's 1.6 version

A newer (1.7) version is available now

Printer Friendly | Permalink |  | Top
 
jbnow Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 09:26 PM
Response to Reply #25
26. I didn't know there was a difference
between Mozilla and Firefox.

You can tell I am no expert. My browser says "Mozilla Firefox". I'll try to figure out the difference and see if it helps. I have only had the problem in the past week, no changes triggered it. But perhaps getting simpler will solve it.

Thanks
Printer Friendly | Permalink |  | Top
 
fleabert Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 09:50 PM
Response to Reply #18
27. get on firefox support- email or IM - and they should be able to help
they are awesome. anytime someone else uses my computer and unwittingly uses IE, I get a virus or a hijacker- every single time. Thankfully, I have good virus protection, etc... I will never open IE again!
Printer Friendly | Permalink |  | Top
 
Moderator DU Moderator Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 09:14 AM
Response to Original message
6. Please change your subject line to read
Microsoft Warns IE Users Of 'Highly Critical' Flaw

Per LBN rules subject lines must match the article title
http://www.democraticunderground.com/discuss/duboard.php?az=view_all&address=102x87249

Printer Friendly | Permalink |  | Top
 
onehandle Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 09:25 AM
Response to Original message
7. Just another day living with Windows.
Apple (99% Blue) iMacs and Mac Minis at Costco (also 99% Blue)
Printer Friendly | Permalink |  | Top
 
melm00se Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 09:54 AM
Response to Original message
8. mozilla
mozilla mozilla is our cry

www.mozilla.com
Printer Friendly | Permalink |  | Top
 
fshrink Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 02:03 PM
Response to Reply #8
22. Better, safer, smarter, hands down.
Printer Friendly | Permalink |  | Top
 
sakabatou Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 10:04 AM
Response to Original message
9. Which makes Firefox so much better.
Printer Friendly | Permalink |  | Top
 
tammywammy Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 11:56 AM
Response to Reply #9
15. I second that!
I love love love Firefox! :loveya:
Printer Friendly | Permalink |  | Top
 
CountAllVotes Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 11:37 AM
Response to Original message
13. One thing you CAN do is to disable "AutoComplete"
AutoComplete is a feature in Microsoft Internet Explorer.

If you are using Microsoft Internet Explorer 5.0 or higher on a Windows platform your information and PINs may automatically fill in. This is a feature of this browser version that works much like the later versions of Microsoft Word where the application automatically complete words that you have typed before and use frequently. It is strongly recommend that you disable it when accessing sites that contain sensitive or confidential data.

To disable the AutoComplete feature for version 5.0 and higher:

Go to the Tools menu option of your browser and select Internet Options.
A dialog box will appear with six tabs across the top, click on the Content tab.
Click on the "AutoComplete" button in the Personal Information section at the bottom.
A dialogue box called "AutoComplete Settings" will appear, deselect the "User name and password on forms" checkbox and click on the "Clear Passwords" button.
Click OK to save your settings.
Click OK on the "Internet Options" window.
For more information about this feature refer to Microsoft's support site for Internet Explorer at support.microsoft.com/support/ie/

The above instructions do work but warning, you better have your user ID's and passwords written down and saved somewhere (I have mine printed out)!

:kick:


Printer Friendly | Permalink |  | Top
 
Room101 Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 12:31 PM
Response to Original message
17. Firefox is the best
Edited on Fri Mar-24-06 12:32 PM by Room101
IE reminds me of vhs and Firefox is the new dvd.
Printer Friendly | Permalink |  | Top
 
no name no slogan Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 12:49 PM
Response to Original message
19. OOOOPS! So much for "dynamic web applications"
"createTextRange()" is used all the time in many web apps. It would be very easy to exploit this flaw.

Jeez, MS has had some sort of text editing built into IE since version 4. You'd think they'd have caught that by now.
Printer Friendly | Permalink |  | Top
 
pinniped Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 01:52 PM
Response to Original message
21. They should just ditch Internet Exploder and start from scratch.
Edited on Fri Mar-24-06 01:53 PM by pinniped
IE has had enough bad press over the years.

IE2 can have a fresh start.

IE has more security patches than my Polo patch shirt.
Printer Friendly | Permalink |  | Top
 
BushOut06 Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 02:23 PM
Response to Original message
23. What if you have IE but don't use it?
Ever since I got Firefox, I haven't really used IE. But I still have it, in case I need it for something that Firefox can't do (some websites won't work on Firefox). If I don't use IE, am I still vulnerable?
Printer Friendly | Permalink |  | Top
 
melm00se Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Mar-24-06 02:28 PM
Response to Reply #23
24. as long as
the application isn't running, you are safe. Just make sure that you have been a good person and updated your operating system like you are supposed to.

Other options for browsers are:

http://www.alternativebrowseralliance.com/browsers.html


Printer Friendly | Permalink |  | Top
 
Commie Pinko Dirtbag Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-27-06 12:55 PM
Response to Original message
28. Where's Nomad559?
He's the one who usually posts news of browser bugs. O8)
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri Apr 26th 2024, 08:55 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Latest Breaking News Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC