IDNetters Forums

Technical News & Discussion => Windows News & Discussion => Topic started by: Rik on Nov 23, 2009, 17:35:43

Title: Javascript & IE
Post by: Rik on Nov 23, 2009, 17:35:43
If you use version 6 or 7 of Microsoft's Internet Explorer browser you should disable the JavaScript function immediately.

Security experts have warned anyone using Internet Explorer 6 or 7 on a Windows XP or Windows Vista PC to take immediate steps to ensure their security.

This is because an exploit for a previously unknown flaw in the browser has been spotted in circulation.

The flaw could enable a hacker to take over a computer if a surfer visited a compromised website using a vulnerable version of the IE browser.

Proof-of-concept code is already circulating on the web, with more exploit code likely to be on the way.

Security firm Symantec advised surfers to disable JavaScript in IE and to ensure their anti-virus definitions were up to date.

"The exploit currently exhibits signs of poor reliability, but we expect that a fully-functional reliable exploit will be available in the near future. When this happens, attackers will have the ability to insert the exploit into sites, infecting potential visitors," Symantec said in a statement.

You can disable JavaScript in IE7 by going to Tools, Internet Options, click on the Security tab and then click on Custom Level. Scroll down until you find the entry for Scripting, then click on Disable.

In IE6, follow the same instructions, though you are looking for the entry for 'Active scripting' in the Custom Level dialogue box. You will also need to restart your browser for the fix to take effect.

Other versions of Internet Explorer and Windows could also be affected, Symantec warned.

Microsoft has not yet commented on the vulnerability.
Title: Re: Javascript & IE
Post by: somanyholes on Nov 23, 2009, 17:40:34
shame they don't have no script ;) On a more serious note turning off javascript is going to break a massive amount of sites, I can't believe they have recommended to turn it off. Web security would be so muc better if javascript didnt exist at all, it really is a big gaping hole in browser security.
Title: Re: Javascript & IE
Post by: Glenn on Nov 23, 2009, 17:40:55
Do you have a link please Rik, I'll send it to my desktop admin team?
Title: Re: Javascript & IE
Post by: Rik on Nov 23, 2009, 17:46:31
I don't, I stole it from elsewhere, So. ;)
Title: Re: Javascript & IE
Post by: Noreen on Nov 23, 2009, 17:47:39
Is it the one called "Scripting of Java Applets", Rik?
Title: Re: Javascript & IE
Post by: Rik on Nov 23, 2009, 17:47:56
This is the best I could find:

http://voices.washingtonpost.com/securityfix/2009/11/new_attack_targets_weakness_in.html
Title: Re: Javascript & IE
Post by: Rik on Nov 23, 2009, 17:48:09
Quote from: Noreen on Nov 23, 2009, 17:47:39
Is it the one called "Scripting of Java Applets", Rik?

Possibly.
Title: Re: Javascript & IE
Post by: Glenn on Nov 23, 2009, 17:48:28
http://news.softpedia.com/news/IE7-0-Day-Vulnerability-Published-in-the-Wild-127732.shtml
Title: Re: Javascript & IE
Post by: Sebby on Nov 23, 2009, 18:03:33
Good old IE. ::)
Title: Re: Javascript & IE
Post by: Baz on Nov 23, 2009, 18:06:20
i dont use IE if I can help it  but for those that do and are not familiar with Javascript  how do you disable it Rik and how long to leave it disabled
Title: Re: Javascript & IE
Post by: Rik on Nov 23, 2009, 18:07:09
QuoteYou can disable JavaScript in IE7 by going to Tools, Internet Options, click on the Security tab and then click on Custom Level. Scroll down until you find the entry for Scripting, then click on Disable.

In IE6, follow the same instructions, though you are looking for the entry for 'Active scripting' in the Custom Level dialogue box. You will also need to restart your browser for the fix to take effect.

Baz. Not sure about IE8.
Title: Re: Javascript & IE
Post by: Baz on Nov 23, 2009, 18:08:37
opps   sorry Rik didnt read it all  :whistle: :whistle:

:)
Title: Re: Javascript & IE
Post by: Rik on Nov 23, 2009, 18:09:33
 ;D I know the feeling Baz, I do it all day.
Title: Re: Javascript & IE
Post by: Baz on Nov 23, 2009, 18:10:55
what do they class as a compromised website or is there far too many to mention  ;D
Title: Re: Javascript & IE
Post by: Noreen on Nov 23, 2009, 18:11:25
I found this  http://www.technipages.com/internet-explorer-7-enabledisable-javascript.html
Title: Re: Javascript & IE
Post by: Rik on Nov 23, 2009, 18:11:51
Thanks, Noreen. :thumb:
Title: Re: Javascript & IE
Post by: psp83 on Nov 23, 2009, 18:17:12
Quote from: somanyholes on Nov 23, 2009, 17:40:34Web security would be so muc better if javascript didnt exist at all, it really is a big gaping hole in browser security.

Web security would be better if IE didnt exist!

Its not javascript thats in the wrong, its the browser not coded correctly.
Title: Re: Javascript & IE
Post by: somanyholes on Nov 23, 2009, 18:30:05
Quote
Web security would be better if IE didnt exist!

Its not javascript thats in the wrong, its the browser not coded correctly.

xss/csrf dont care what browser your using, javascript/actionscript all lead down the same path.
Title: Re: Javascript & IE
Post by: Noreen on Nov 23, 2009, 18:31:11
I disabled it and found that I couldn't use smilies in posts so I've reset it again.
Title: Re: Javascript & IE
Post by: Rik on Nov 23, 2009, 18:33:04
It would do that, and affect some other forum functions too.
Title: Re: Javascript & IE
Post by: Noreen on Nov 23, 2009, 18:39:14
Possibly doesn't affect Vista, only XP. http://blogs.pcmag.com/securitywatch/2009/11/unpatched_vulnerability_and_ex.php
Title: Re: Javascript & IE
Post by: Noreen on Nov 24, 2009, 17:40:04
Looks as though it does affect Vista. :( http://www.microsoft.com/technet/security/advisory/977981.mspx
Title: Re: Javascript & IE
Post by: Rik on Nov 24, 2009, 18:07:51
Nice to see they're really going flat out to fix it, isn't it. ;)
Title: Re: Javascript & IE
Post by: Gary on Nov 24, 2009, 18:36:58
Quote from: Rik on Nov 24, 2009, 18:07:51
Nice to see they're really going flat out to fix it, isn't it. ;)
Makes Windows 7 look tempting for those with XP and Vista, Rik.
Title: Re: Javascript & IE
Post by: Rik on Nov 24, 2009, 18:37:26
Makes a Mac look even more tempting. ;D
Title: Re: Javascript & IE
Post by: Gary on Nov 24, 2009, 18:39:31
Quote from: Rik on Nov 24, 2009, 18:37:26
Makes a Mac look even more tempting. ;D
;D I am cuddling mine as we speak, I was deprived today as we had carpets laid throughout the Bungalow so not internet till about an hour ago
Title: Re: Javascript & IE
Post by: Rik on Nov 24, 2009, 18:41:29
I have a radiator valve to be replaced in here tomorrow, so I'm going to be cut off too...
Title: Re: Javascript & IE
Post by: Gary on Nov 24, 2009, 18:42:54
Quote from: Rik on Nov 24, 2009, 18:41:29
I have a radiator valve to be replaced in here tomorrow, so I'm going to be cut off too...
Ouch  :o changing your name to Bobitt by any chance?
Title: Re: Javascript & IE
Post by: Rik on Nov 24, 2009, 18:43:22
Not unless I stand too close. :)
Title: Re: Javascript & IE
Post by: Gary on Nov 24, 2009, 18:50:02
Quote from: Rik on Nov 24, 2009, 18:43:22
Not unless I stand too close. :)
;D I will be offline again for a while, getting a new router, a Netgear DGN3300 So I can use the mac on the ratified 802.11n on the 5GHz frequency and my Playstation and iPhone on the 2.4ghz simultaneously if it all works correctly  :fingers:
Title: Re: Javascript & IE
Post by: Rik on Nov 24, 2009, 18:52:33
 :fingers: :fingers: :fingers: :fingers: :fingers: :)
Title: Re: Javascript & IE
Post by: Colin Burns on Nov 25, 2009, 08:37:43
i got board and just disabled everything in IE  :whistle:

though i dont ever use it. Shame i cant completly kill it without hurting xp
Title: Re: Javascript & IE
Post by: Gary on Nov 26, 2009, 11:56:32
Seems IE 8 is vulnerable, if its the same expolit, "IE8 flaw makes 'safe' sites unsafe. The latest version of Microsoft's Internet Explorer browser contains a bug that can enable serious security attacks against websites that are otherwise safe.

The flaw in IE 8 can be exploited to introduce XSS, or cross-site scripting, errors on webpages that are otherwise safe, according to two Register sources, who discussed the bug on the condition they not be identified. Microsoft was notified of the vulnerability a few months ago, they said"

Nice of MS to keep on top of the patching again.
Title: Re: Javascript & IE
Post by: Rik on Nov 26, 2009, 12:01:26
 ::)
Title: Re: Javascript & IE
Post by: Glenn on Nov 26, 2009, 12:04:37
News from MS http://www.microsoft.com/technet/security/advisory/977981.MSpx?pubDate=2009-11-25
Title: Re: Javascript & IE
Post by: Gary on Nov 26, 2009, 12:45:23
Quote from: Glenn on Nov 26, 2009, 12:04:37
News from MS http://www.microsoft.com/technet/security/advisory/977981.MSpx?pubDate=2009-11-25
This must be a different bug in IE8 http://www.theregister.co.uk/2009/11/20/internet_explorer_security_flaw/
Title: Re: Javascript & IE
Post by: Sebby on Nov 26, 2009, 15:43:25
There are so many, it's easy to lose track. ;D
Title: Re: Javascript & IE
Post by: Den on Nov 26, 2009, 16:54:14
I promised not to come over to the Mac thread as long you refrained from having goes at Microsoft, your on thin ice  ;)
Title: Re: Javascript & IE
Post by: Gary on Nov 26, 2009, 19:29:35
Quote from: Den on Nov 26, 2009, 16:54:14
I promised not to come over to the Mac thread as long you refrained from having goes at Microsoft, your on thin ice  ;)
Considering that bug is Months old it damn poor that IE8 is Vulnerable, and we still have a Windows machine in the house  ;D Microsoft need to patch faster, not sit on problems for so long  :(
Title: Re: Javascript & IE
Post by: Den on Nov 26, 2009, 19:55:13
 ;D :bartmoon: :out:  I like IE8 and Windows 7   ;D
Title: Re: Javascript & IE
Post by: Gary on Nov 26, 2009, 20:02:18
Quote from: Den on Nov 26, 2009, 19:55:13
;D :bartmoon: :out:  I like IE8 and Windows 7   ;D
I am sure you do, I like Sencha tea  ;D
Title: Re: Javascript & IE
Post by: Den on Nov 26, 2009, 20:33:00
I don't like any kind of tea  ;D
Title: Re: Javascript & IE
Post by: Sebby on Nov 26, 2009, 20:56:42
Quote from: Den on Nov 26, 2009, 16:54:14
I promised not to come over to the Mac thread as long you refrained from having goes at Microsoft, your on thin ice  ;)

Not having a go, just stating a fact. Having a go would have been "I hate Microsoft". :)
Title: Re: Javascript & IE
Post by: Ann on Nov 26, 2009, 21:29:47
Has anyone ever been caught by these so called vulnerabilities?  I never have.  In fact in all my years with computers, my computer has never been infected.  And I've always used IE.  At the moment I use IE mostly and Chrome for one particular forum.  That one's a bugger.  I don't know why but I can't keep logged in with IE and as I'm an admin I need to be logged in to deal with spammers.  But I digress.  MS is not so bad..
Title: Re: Javascript & IE
Post by: Den on Nov 26, 2009, 21:38:18
I cant remember the last time I have picked up a virus or had any other problems and I have always used IE. I don't use it because it is put out by MS, I use it because I have never realy liked the alternatives and have yet to try one that can hold a candle to IE8.
Title: Re: Javascript & IE
Post by: Simon on Nov 26, 2009, 22:04:29
I don't think IE is inherently bad - it's just not as good as Sea Monkey.  :)
Title: Re: Javascript & IE
Post by: Gary on Nov 27, 2009, 07:15:35
Quote from: Den on Nov 26, 2009, 20:33:00
I don't like any kind of tea  ;D
Green tea is very different.  ;D
Title: Re: Javascript & IE
Post by: Den on Nov 27, 2009, 07:24:53
All tea makes me go   :puke:
Title: Re: Javascript & IE
Post by: somanyholes on Nov 27, 2009, 08:14:26
QuoteHas anyone ever been caught by these so called vulnerabilities?  I never have.  In fact in all my years with computers, my computer has never been infected.  And I've always used IE.  At the moment I use IE mostly and Chrome for one particular forum.  That one's a bugger.  I don't know why but I can't keep logged in with IE and as I'm an admin I need to be logged in to deal with spammers.  But I digress.  MS is not so bad..

Ann this maybe of interest to you. http://download.cnet.com/AutoRefresher-for-IE/3000-12512_4-10062693.html. Just don't set the frequency to high.
Title: Re: Javascript & IE
Post by: Gary on Nov 27, 2009, 09:01:57
Quote from: Den on Nov 27, 2009, 07:24:53
All tea makes me go   :puke:
I am sure it does  ;)
Title: Re: Javascript & IE
Post by: Rik on Nov 27, 2009, 09:06:28
Just to broaden the debate, I don't like tea or coffee, in fact any hot drinks.
Title: Re: Javascript & IE
Post by: Glenn on Nov 27, 2009, 09:19:43
I don't like coffee, but my tea I prefer to be very hot.
Title: Re: Javascript & IE
Post by: Gary on Nov 27, 2009, 09:29:12
Quote from: Rik on Nov 27, 2009, 09:06:28
Just to broaden the debate, I don't like tea or coffee, in fact any hot drinks.
I don't drink caffeine of any sort, and I like my Sencha warm, although you make it just off the boil at 90c then leave for 5 mins, its a acquired taste I guess, but there are so many green teas that taste good, like Gunpowder, thats another one I like
Title: Re: Javascript & IE
Post by: Rik on Nov 27, 2009, 09:30:15
I only ever drink cold drinks, have done since I was about 12, Gary.
Title: Re: Javascript & IE
Post by: Gary on Nov 27, 2009, 09:32:30
Quote from: Rik on Nov 27, 2009, 09:30:15
I only ever drink cold drinks, have done since I was about 12, Gary.
Why is that, Rik?
Title: Re: Javascript & IE
Post by: Rik on Nov 27, 2009, 09:33:37
I just went off tea, and have never been tempted back.
Title: Re: Javascript & IE
Post by: Gary on Nov 27, 2009, 10:55:12
Quote from: Rik on Nov 27, 2009, 09:33:37
I just went off tea, and have never been tempted back.
Fair enough, I have to keep my liquids up anyway and Coffee and normal tea were not helping me, oddly I find it harder to sleep now that I don't take caffeine, and I have been off it for about 2 months
Title: Re: Javascript & IE
Post by: Rik on Nov 27, 2009, 11:12:53
Lucky you, I have to keep them down.
Title: Re: Javascript & IE
Post by: Lance on Nov 27, 2009, 11:22:38
I'm drinking a coffee now whilst reading this!
Title: Re: Javascript & IE
Post by: Gary on Nov 27, 2009, 11:23:29
Quote from: Lance on Nov 27, 2009, 11:22:38
I'm drinking a coffee now whilst reading this!
I'm drinking a Camomile tea.....man  ;D
Title: Re: Javascript & IE
Post by: Sebby on Nov 27, 2009, 17:01:52
I love a cup of tea. ;D
Title: Re: Javascript & IE
Post by: Rik on Nov 27, 2009, 17:02:43
I wouldn't be allowed it now even if I did, no stimulating drinks. :( OTOH, alcohol is a depressant. ;D