Advertisement

There's no such thing as a stupid question, but they're the easiest to answer.
Login
Search

Advertisement

General Security General Security
Search Search
Search for:
Tech Support Guy Forums > > >

Solved: New security exploit for IE 7, 8 and 9!


(!)

TOGG's Avatar
Member with 5,580 posts.
THREAD STARTER
 
Join Date: Apr 2002
Location: Birmingham, England
17-Sep-2012, 01:06 PM #1
Solved: New security exploit for IE 7, 8 and 9!
Details here; http://isc.sans.edu/index.html Probably no need for excessive panic (yet), as these threats can sometimes be seriously exaggerated.

I took the advice to use something other than IE many years ago (back in the days of IE 5.5 and 6 and the 'Love bug' worm and other similar delights)!.
__________________
Nothing matters very much, and few things matter at all.

Lord Balfour 1848-1930
dvk01's Avatar
dvk01   (Derek) dvk01 is offline dvk01 is authorized to help remove malware.
Moderator & Malware Removal Specialist with 42,933 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
18-Sep-2012, 10:42 AM #2
http://thespykiller.co.uk/blog/0-day...rnet-explorer/

This is serious and can potentially enable your computer to be completely taken over

following the suggested advise to install & configure EMET will protect you agaist this & just about all other possible exploits
Phantom010's Avatar
Phantom010 has a Photo Album
Computer Specs
Trusted Advisor with 30,444 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
18-Sep-2012, 10:54 AM #3
Will EMET work well with Java to prevent Java Exploits?
dvk01's Avatar
dvk01   (Derek) dvk01 is offline dvk01 is authorized to help remove malware.
Moderator & Malware Removal Specialist with 42,933 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
18-Sep-2012, 11:15 AM #4
I am not certain on that, you can add java to EMET so any exploits in the java program itself will be protected against, BUT as the java exploits tend to attack IE & other browsers, adding all browsers to EMET is a more certain way
I also add ALL office programs to EMET

The normal method of using plugins like Java & Flash to attack IE/FF or chrome should be blocked by adding the browsers to EMET.
That doesn't mean that you don't need to update the plugins. You DO

Many of the exploits using the plugins are because the plugins are allowed or designed to perform certain tasks and updates generally block or remove the code that has allowed those functions to run, that weren't envisaged or intended when Java or flash was made.
__________________
Derek Microsoft MVP/Windows - Security | Thespykiller
Find out all about the European Wild Hedgehog, what you can do to save it from extinction Hedgehog Rescue
Phantom010's Avatar
Phantom010 has a Photo Album
Computer Specs
Trusted Advisor with 30,444 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
18-Sep-2012, 11:39 AM #5
OK, thanks!
dvk01's Avatar
dvk01   (Derek) dvk01 is offline dvk01 is authorized to help remove malware.
Moderator & Malware Removal Specialist with 42,933 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
18-Sep-2012, 01:35 PM #6
I am led to believe that this particualr exploit requires Java on Vista & W7 but not on XP
so one good work around on Vista/W7 is uninstall Java unless you have an absolute need for it to be installed

Unfortunately if you are using XP then at this time the best workaround is NOT to use IE but to use chrome or Firefox, however, it has not been confirmed but is widely believed that a similar exploit that works on other browsers is in the pipleline, if it hasn't already been released
__________________
Derek Microsoft MVP/Windows - Security | Thespykiller
Find out all about the European Wild Hedgehog, what you can do to save it from extinction Hedgehog Rescue
Phantom010's Avatar
Phantom010 has a Photo Album
Computer Specs
Trusted Advisor with 30,444 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
18-Sep-2012, 01:59 PM #7
Does the EMET_Notifier need to auto load with Windows and sit in the systray, since it's only a notifier? Is the feature absolutely necessary?

Last edited by Phantom010; 18-Sep-2012 at 02:05 PM..
dvk01's Avatar
dvk01   (Derek) dvk01 is offline dvk01 is authorized to help remove malware.
Moderator & Malware Removal Specialist with 42,933 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
18-Sep-2012, 02:18 PM #8
I believe so , but I will ask
dvk01's Avatar
dvk01   (Derek) dvk01 is offline dvk01 is authorized to help remove malware.
Moderator & Malware Removal Specialist with 42,933 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
18-Sep-2012, 02:43 PM #9
yes it does need to be running , at least to alert you that Emet has done something to protect you, like stopping an exploit
http://social.technet.microsoft.com/...8-049c61ff4928
Phantom010's Avatar
Phantom010 has a Photo Album
Computer Specs
Trusted Advisor with 30,444 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
18-Sep-2012, 03:04 PM #10
It needs to be there if you wish to see the alerts, but removing EMET_Notifier is not going to prevent the program from blocking exploits, right?
dvk01's Avatar
dvk01   (Derek) dvk01 is offline dvk01 is authorized to help remove malware.
Moderator & Malware Removal Specialist with 42,933 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
18-Sep-2012, 03:13 PM #11
I don't believe so , but stopping notifier also stops the logging, so you have no way of knowing what it stopped or whether it was a genuine attack or exploit or whether it just stopped a legitimate program from running

Obviously it is your choice, but I would keep it running for my peace of mind
Unfortunately all tools like EMET work on behaviour so there will be some false alarms & it will almost certainly stop legitimate processes at some time. I have seen several comments that Skype can get blocked and fail to open when emet is enabled for it ( on some computers)
That is the reason for the notifier alerting that it has done something, otherwise you forget it might be responsible & curse and swear when a program crashes and start allsorts of trouble shooting
__________________
Derek Microsoft MVP/Windows - Security | Thespykiller
Find out all about the European Wild Hedgehog, what you can do to save it from extinction Hedgehog Rescue
Phantom010's Avatar
Phantom010 has a Photo Album
Computer Specs
Trusted Advisor with 30,444 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
18-Sep-2012, 03:35 PM #12
Good point, thanks!
Phantom010's Avatar
Phantom010 has a Photo Album
Computer Specs
Trusted Advisor with 30,444 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
19-Sep-2012, 08:59 AM #13
Getting a few too many false positives while running IE8. DEP prompts while using TSG! They crash IE8. Maybe that's why I had never heard of EMET before...

Last edited by Phantom010; 19-Sep-2012 at 09:08 AM..
dvk01's Avatar
dvk01   (Derek) dvk01 is offline dvk01 is authorized to help remove malware.
Moderator & Malware Removal Specialist with 42,933 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
19-Sep-2012, 11:59 AM #14
latest news from Microsoft
Quote:
We will release a Fix it in the next few days to address an issue in Internet Explorer, as outlined in the Security Advisory 2757760 that we released yesterday.

While we have only seen a few attempts to exploit the issue, impacting an extremely limited number of people, we are taking this proactive step to help ensure Internet Explorer customers are protected and able to safely browse online.


The Fix it is an easy-to-use, one-click, full-strength solution any Internet Explorer user can install. It will not affect your ability to browse the Web, and it will provide full protection against this issue until an update is available. It won’t require a reboot of your computer.


This Fix it will be available for everyone to download and install within the next few days. Until then, we encourage folks to review the advisory and follow the other mitigations listed there.
http://blogs.technet.com/b/msrc/arch...edirected=true
hewee's Avatar
Computer Specs
Member with 54,345 posts.
 
Join Date: Oct 2001
Location: *Random People Pleaser***Sacra
20-Sep-2012, 01:03 AM #15
Quote:
Originally Posted by TOGG View Post
Details here; http://isc.sans.edu/index.html Probably no need for excessive panic (yet), as these threats can sometimes be seriously exaggerated.

I took the advice to use something other than IE many years ago (back in the days of IE 5.5 and 6 and the 'Love bug' worm and other similar delights)!.
I never even had IE installed back then and use Netscape and when IE took over I see all new people with IE and then all the people posting for help and most were using IE.

I open IE with very high setting as high as I can go and get MS updates.

http://technet.microsoft.com/en-us/s...letin/ms12-sep

Quote:
Microsoft Security Bulletin out of band Advance Notification

This is an advance notification for one out-of-band security bulletin that Microsoft is intending to release on September 21, 2012. The bulletin addresses security vulnerabilities in Internet Explorer.
__________________
Donating to TSG helps to keep the site going so please do your part and help.
Keep Your Security Software Current at Calendar of Updates
"Work like you don't need the money. Love like you've never been hurt. Dance like nobody's watching."
As Seen On

BBC, Reader's Digest, PC Magazine, Today Show, Money Magazine
WELCOME TO TECH SUPPORT GUY!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.


(clock)
THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools


WELCOME
You Are Using: Server ID
Trusted Website Back to the Top ↑