If you use version 6 or 7 of Microsoft's Internet Explorer browser you should disable the JavaScript function immediately.
Security experts have warned anyone using Internet Explorer 6 or 7 on a Windows XP or Windows Vista PC to take immediate steps to ensure their security.
This is because an exploit for a previously unknown flaw in the browser has been spotted in circulation.
The flaw could enable a hacker to take over a computer if a surfer visited a compromised website using a vulnerable version of the IE browser.
Proof-of-concept code is already circulating on the web, with more exploit code likely to be on the way.
Security firm Symantec advised surfers to disable JavaScript in IE and to ensure their anti-virus definitions were up to date.
"The exploit currently exhibits signs of poor reliability, but we expect that a fully-functional reliable exploit will be available in the near future. When this happens, attackers will have the ability to insert the exploit into sites, infecting potential visitors," Symantec said in a statement.
You can disable JavaScript in IE7 by going to Tools, Internet Options, click on the Security tab and then click on Custom Level. Scroll down until you find the entry for Scripting, then click on Disable.
In IE6, follow the same instructions, though you are looking for the entry for 'Active scripting' in the Custom Level dialogue box. You will also need to restart your browser for the fix to take effect.
Other versions of Internet Explorer and Windows could also be affected, Symantec warned.
Microsoft has not yet commented on the vulnerability.
shame they don't have no script ;) On a more serious note turning off javascript is going to break a massive amount of sites, I can't believe they have recommended to turn it off. Web security would be so muc better if javascript didnt exist at all, it really is a big gaping hole in browser security.
Do you have a link please Rik, I'll send it to my desktop admin team?
I don't, I stole it from elsewhere, So. ;)
Is it the one called "Scripting of Java Applets", Rik?
This is the best I could find:
http://voices.washingtonpost.com/securityfix/2009/11/new_attack_targets_weakness_in.html
Quote from: Noreen on Nov 23, 2009, 17:47:39
Is it the one called "Scripting of Java Applets", Rik?
Possibly.
http://news.softpedia.com/news/IE7-0-Day-Vulnerability-Published-in-the-Wild-127732.shtml
Good old IE. ::)
i dont use IE if I can help it but for those that do and are not familiar with Javascript how do you disable it Rik and how long to leave it disabled
QuoteYou can disable JavaScript in IE7 by going to Tools, Internet Options, click on the Security tab and then click on Custom Level. Scroll down until you find the entry for Scripting, then click on Disable.
In IE6, follow the same instructions, though you are looking for the entry for 'Active scripting' in the Custom Level dialogue box. You will also need to restart your browser for the fix to take effect.
Baz. Not sure about IE8.
opps sorry Rik didnt read it all :whistle: :whistle:
:)
;D I know the feeling Baz, I do it all day.
what do they class as a compromised website or is there far too many to mention ;D
I found this http://www.technipages.com/internet-explorer-7-enabledisable-javascript.html
Thanks, Noreen. :thumb:
Quote from: somanyholes on Nov 23, 2009, 17:40:34Web security would be so muc better if javascript didnt exist at all, it really is a big gaping hole in browser security.
Web security would be better if IE didnt exist!
Its not javascript thats in the wrong, its the browser not coded correctly.
Quote
Web security would be better if IE didnt exist!
Its not javascript thats in the wrong, its the browser not coded correctly.
xss/csrf dont care what browser your using, javascript/actionscript all lead down the same path.
I disabled it and found that I couldn't use smilies in posts so I've reset it again.
It would do that, and affect some other forum functions too.
Possibly doesn't affect Vista, only XP. http://blogs.pcmag.com/securitywatch/2009/11/unpatched_vulnerability_and_ex.php
Looks as though it does affect Vista. :( http://www.microsoft.com/technet/security/advisory/977981.mspx
Nice to see they're really going flat out to fix it, isn't it. ;)
Quote from: Rik on Nov 24, 2009, 18:07:51
Nice to see they're really going flat out to fix it, isn't it. ;)
Makes Windows 7 look tempting for those with XP and Vista, Rik.
Makes a Mac look even more tempting. ;D
Quote from: Rik on Nov 24, 2009, 18:37:26
Makes a Mac look even more tempting. ;D
;D I am cuddling mine as we speak, I was deprived today as we had carpets laid throughout the Bungalow so not internet till about an hour ago
I have a radiator valve to be replaced in here tomorrow, so I'm going to be cut off too...
Quote from: Rik on Nov 24, 2009, 18:41:29
I have a radiator valve to be replaced in here tomorrow, so I'm going to be cut off too...
Ouch :o changing your name to Bobitt by any chance?
Not unless I stand too close. :)
Quote from: Rik on Nov 24, 2009, 18:43:22
Not unless I stand too close. :)
;D I will be offline again for a while, getting a new router, a Netgear DGN3300 So I can use the mac on the ratified 802.11n on the 5GHz frequency and my Playstation and iPhone on the 2.4ghz simultaneously if it all works correctly :fingers:
:fingers: :fingers: :fingers: :fingers: :fingers: :)
i got board and just disabled everything in IE :whistle:
though i dont ever use it. Shame i cant completly kill it without hurting xp
Seems IE 8 is vulnerable, if its the same expolit, "IE8 flaw makes 'safe' sites unsafe. The latest version of Microsoft's Internet Explorer browser contains a bug that can enable serious security attacks against websites that are otherwise safe.
The flaw in IE 8 can be exploited to introduce XSS, or cross-site scripting, errors on webpages that are otherwise safe, according to two Register sources, who discussed the bug on the condition they not be identified. Microsoft was notified of the vulnerability a few months ago, they said"
Nice of MS to keep on top of the patching again.
::)
News from MS http://www.microsoft.com/technet/security/advisory/977981.MSpx?pubDate=2009-11-25
Quote from: Glenn on Nov 26, 2009, 12:04:37
News from MS http://www.microsoft.com/technet/security/advisory/977981.MSpx?pubDate=2009-11-25
This must be a different bug in IE8 http://www.theregister.co.uk/2009/11/20/internet_explorer_security_flaw/
There are so many, it's easy to lose track. ;D
I promised not to come over to the Mac thread as long you refrained from having goes at Microsoft, your on thin ice ;)
Quote from: Den on Nov 26, 2009, 16:54:14
I promised not to come over to the Mac thread as long you refrained from having goes at Microsoft, your on thin ice ;)
Considering that bug is Months old it damn poor that IE8 is Vulnerable, and we still have a Windows machine in the house ;D Microsoft need to patch faster, not sit on problems for so long :(
;D :bartmoon: :out: I like IE8 and Windows 7 ;D
Quote from: Den on Nov 26, 2009, 19:55:13
;D :bartmoon: :out: I like IE8 and Windows 7 ;D
I am sure you do, I like Sencha tea ;D
I don't like any kind of tea ;D
Quote from: Den on Nov 26, 2009, 16:54:14
I promised not to come over to the Mac thread as long you refrained from having goes at Microsoft, your on thin ice ;)
Not having a go, just stating a fact. Having a go would have been "I hate Microsoft". :)
Has anyone ever been caught by these so called vulnerabilities? I never have. In fact in all my years with computers, my computer has never been infected. And I've always used IE. At the moment I use IE mostly and Chrome for one particular forum. That one's a bugger. I don't know why but I can't keep logged in with IE and as I'm an admin I need to be logged in to deal with spammers. But I digress. MS is not so bad..
I cant remember the last time I have picked up a virus or had any other problems and I have always used IE. I don't use it because it is put out by MS, I use it because I have never realy liked the alternatives and have yet to try one that can hold a candle to IE8.
I don't think IE is inherently bad - it's just not as good as Sea Monkey. :)
Quote from: Den on Nov 26, 2009, 20:33:00
I don't like any kind of tea ;D
Green tea is very different. ;D
All tea makes me go :puke:
QuoteHas anyone ever been caught by these so called vulnerabilities? I never have. In fact in all my years with computers, my computer has never been infected. And I've always used IE. At the moment I use IE mostly and Chrome for one particular forum. That one's a bugger. I don't know why but I can't keep logged in with IE and as I'm an admin I need to be logged in to deal with spammers. But I digress. MS is not so bad..
Ann this maybe of interest to you. http://download.cnet.com/AutoRefresher-for-IE/3000-12512_4-10062693.html. Just don't set the frequency to high.
Quote from: Den on Nov 27, 2009, 07:24:53
All tea makes me go :puke:
I am sure it does ;)
Just to broaden the debate, I don't like tea or coffee, in fact any hot drinks.
I don't like coffee, but my tea I prefer to be very hot.
Quote from: Rik on Nov 27, 2009, 09:06:28
Just to broaden the debate, I don't like tea or coffee, in fact any hot drinks.
I don't drink caffeine of any sort, and I like my Sencha warm, although you make it just off the boil at 90c then leave for 5 mins, its a acquired taste I guess, but there are so many green teas that taste good, like Gunpowder, thats another one I like
I only ever drink cold drinks, have done since I was about 12, Gary.
Quote from: Rik on Nov 27, 2009, 09:30:15
I only ever drink cold drinks, have done since I was about 12, Gary.
Why is that, Rik?
I just went off tea, and have never been tempted back.
Quote from: Rik on Nov 27, 2009, 09:33:37
I just went off tea, and have never been tempted back.
Fair enough, I have to keep my liquids up anyway and Coffee and normal tea were not helping me, oddly I find it harder to sleep now that I don't take caffeine, and I have been off it for about 2 months
Lucky you, I have to keep them down.
I'm drinking a coffee now whilst reading this!
Quote from: Lance on Nov 27, 2009, 11:22:38
I'm drinking a coffee now whilst reading this!
I'm drinking a Camomile tea.....man ;D
I love a cup of tea. ;D
I wouldn't be allowed it now even if I did, no stimulating drinks. :( OTOH, alcohol is a depressant. ;D