Pixalo Photography Community  

Go Back   Pixalo Photography Community > General forums > General Chat
Register Search Today's Posts Mark Forums Read

General Chat Discuss Microsoft warns on browser bugs...Just a heads up for any members still using IE, not that there is anything you can do about it ...

Welcome to the Pixalo Photography Community. As a Guest you are free to browse the site, but see what extras you get as a Member here.


Expired Thread The thread "Microsoft warns on browser bugs" has not received any replies for 18 months. It has been automatically closed as a result. Please start a new thread on the topic if the information in this thread is not sufficient.

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 27-03-2006, 16:04   #1 (permalink)
Pixalo Crew
 
Steve's Avatar
 
Join Date: Jan 2005
Location: An Englishman living in Germany
Posts: 15,999
Steve is a jewel in the rough
Steve is a jewel in the roughSteve is a jewel in the rough

Image editing O.K.
User's Gallery
Users Camera Equipment List
Microsoft warns on browser bugs

Just a heads up for any members still using IE, not that there is anything you can do about it until April 11th

Quote:
Microsoft has urged users to be wary as three newly discovered bugs leave people open to attack while using the net. All three bugs affect the software firm's Internet Explorer browser.

Security firms said the vulnerabilities were already being targeted by malicious hackers keen to catch out unsuspecting users.

Microsoft said it would produce patches for the vulnerabilities in its next security update due on 11 April.

Attack vector

The first of the problems discovered in Internet Explorer will simply make the browser program crash if it is used to visit a specially crafted webpage.

The other two vulnerabilities are potentially more serious because they can be used to take control of a victim's computer.

Already, said security firms, specially written websites and hijacked servers were being used to host the malicious code that uses the loopholes to invade vulnerable machines.

In security bulletins about the trio of bugs, Microsoft played down the threat and said: "The attacks are limited in scope for now".

Microsoft usually issues security updates on the second Tuesday of every month and its security team is working towards this date, 11 April, to produce patches for the bugs. However, it said the patches would be released earlier if the threat grew significantly.

Those using the patched versions of IE bundled with Windows 2000, Windows XP and Windows Server 2003 are vulnerable to these bugs. People trying out the Beta 2 version of Internet Explorer 7 are safe.

To avoid falling victim, Microsoft urged users to avoid websites they did not trust and to refrain from opening attachments on e-mail messages from unknown senders.
Another reason to try Firefox or Opera
Steve is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 27-03-2006, 16:22   #2 (permalink)
Been here a while
 
evilowl's Avatar
 
Join Date: Sep 2005
Location: London village
Posts: 376
evilowl will become famous soon enoughevilowl will become famous soon enoughevilowl will become famous soon enoughevilowl will become famous soon enoughevilowl will become famous soon enoughevilowl will become famous soon enough

Image editing O.K.
User's Gallery
Quote:
Originally Posted by Steve
Just a heads up for any members still using IE, not that there is anything you can do about it until April 11th



Another reason to try Firefox or Opera
Or IE7 beta

Seriously though, other than flaky FTP integration in Firefox (workaround is to use a 3rd party product) ... I can't think of a good reason for anyone to be using IE anymore.

www.mozilla.org

Still, once OSX is installed on everyone's machines by default instead and we're all using Safari as a browser, I'll be much happier
evilowl is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 27-03-2006, 16:34   #3 (permalink)
Pixalo Crew
 
Steve's Avatar
 
Join Date: Jan 2005
Location: An Englishman living in Germany
Posts: 15,999
Steve is a jewel in the rough
Steve is a jewel in the roughSteve is a jewel in the rough

Image editing O.K.
User's Gallery
Users Camera Equipment List
Microsoft can't get their full products to run bug free and comply with industry agreed standards, that doesn't give me much confidence in their beta attempts

I’ll stick to Firefox for now, thanks
Steve is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 27-03-2006, 17:51   #4 (permalink)
Member
 
Join Date: Jan 2005
Location: kings hill
Posts: 5,269
Matty is an unknown quantity at this point

Image editing O.K.
User's Gallery
im running ie7beta2 and its pretty good, seems to be working ok and the bug reporting system is very good, ive posted 2 that i have found and both times the bug has been replied too by an employee working on the software with an explanation of whats occuring and why. Trouble with high use software is that malicious hackers will always try and beat it, and that is now true as much to firefox as IE, security holes are being found in that now too
Matty is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 27-03-2006, 18:11   #5 (permalink)
Pixalo Crew
 
Steve's Avatar
 
Join Date: Jan 2005
Location: An Englishman living in Germany
Posts: 15,999
Steve is a jewel in the rough
Steve is a jewel in the roughSteve is a jewel in the rough

Image editing O.K.
User's Gallery
Users Camera Equipment List
The difference being that FireFox is a compliant browser, supported by many people who don't only update it every 2nd week according to their schedules.

It may be drawing attention now but it is still more secure and has less security issues reported.
Steve is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 27-03-2006, 18:16   #6 (permalink)
Member
 
Join Date: Jan 2005
Location: kings hill
Posts: 5,269
Matty is an unknown quantity at this point

Image editing O.K.
User's Gallery
ms do normally rush out security fixes if its urgent, for some reason these ones dont seem to be of much interest to them
Matty is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 27-03-2006, 18:19   #7 (permalink)
Pixalo Crew
 
Steve's Avatar
 
Join Date: Jan 2005
Location: An Englishman living in Germany
Posts: 15,999
Steve is a jewel in the rough
Steve is a jewel in the roughSteve is a jewel in the rough

Image editing O.K.
User's Gallery
Users Camera Equipment List
Slackers

They are too busy panicking over the much delayed Vista
Steve is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 27-03-2006, 20:30   #8 (permalink)
New here
 
Join Date: Mar 2006
Posts: 31
Chris_Mitton is on a distinguished roadChris_Mitton is on a distinguished road

User's Gallery
The trouble is that every body want's to have a go at Microsoft. Victims of their own success.
Chris_Mitton is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 27-03-2006, 21:07   #9 (permalink)
Member
 
Join Date: Jan 2005
Location: kings hill
Posts: 5,269
Matty is an unknown quantity at this point

Image editing O.K.
User's Gallery
i tried getting beta of vista but its closed off now, will have to buy it!

thats right Chris, (welcome, btw)anything successful gets pulled down, be it by mischevious hackers or corporate games, success breeds contempt!
Matty is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 27-03-2006, 22:19   #10 (permalink)
Forum Regular
 
SammyC's Avatar
 
Join Date: Jul 2005
Location: Bristol
Posts: 1,466
SammyC is on a distinguished roadSammyC is on a distinguished road

Image editing O.K.
User's Gallery
It does annoy me when MS get slagged off. I'm no real MS fan but they have advanced the PC desktop (regardless of who thought up the ideas initially) way farther than they would have otherwise.

I realise that if MS hadn't done it someone else probably would have but I'd rather be using XP and Word than the Linux stuff I have to struggle with at work everyday. For example, I shouldn't have to know soooo much about sound cards just to get MP3s playing!

Just my 2p.
SammyC is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 27-03-2006, 22:48   #11 (permalink)
Pixalo Crew
 
Steve's Avatar
 
Join Date: Jan 2005
Location: An Englishman living in Germany
Posts: 15,999
Steve is a jewel in the rough
Steve is a jewel in the roughSteve is a jewel in the rough

Image editing O.K.
User's Gallery
Users Camera Equipment List
I am not against MS just IE. My recent experiances with web design has given me just reason to hate it with a passion. Just becasue they are massive company doesn't mean that they shouldn't play along to agreed browser standards, it is just plain pointless and shows their arrogance IMO.
Steve is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 28-03-2006, 00:06   #12 (permalink)
Getting Comfy
 
Mr THX's Avatar
 
Join Date: Sep 2005
Location: Barnsley
Posts: 177
Mr THX is on a distinguished roadMr THX is on a distinguished road

Image editing O.K.
User's Gallery
Quote:
Originally Posted by evilowl
... I can't think of a good reason for anyone to be using IE anymore.

www.mozilla.org
How do you get your Windows updates then ??
Mr THX is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 28-03-2006, 00:10   #13 (permalink)
Pixalo Crew
 
Steve's Avatar
 
Join Date: Jan 2005
Location: An Englishman living in Germany
Posts: 15,999
Steve is a jewel in the rough
Steve is a jewel in the roughSteve is a jewel in the rough

Image editing O.K.
User's Gallery
Users Camera Equipment List
Quote:
Originally Posted by Mr THX
How do you get your Windows updates then ??
Set Windows to automatically check and download updates, then manually authorise/install them at a convenient time

Works great for me here.
Steve is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 28-03-2006, 00:20   #14 (permalink)
Getting Comfy
 
Mr THX's Avatar
 
Join Date: Sep 2005
Location: Barnsley
Posts: 177
Mr THX is on a distinguished roadMr THX is on a distinguished road

Image editing O.K.
User's Gallery
Found to my annoyance that there were too many times I'd go to get an update off one of the MS sites and it would knock you back. Especially if needing a MS Office download.
Mr THX is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 28-03-2006, 09:01   #15 (permalink)
Been here a while
 
evilowl's Avatar
 
Join Date: Sep 2005
Location: London village
Posts: 376
evilowl will become famous soon enoughevilowl will become famous soon enoughevilowl will become famous soon enoughevilowl will become famous soon enoughevilowl will become famous soon enoughevilowl will become famous soon enough

Image editing O.K.
User's Gallery
As Steve says, use automatic updates and if there's something that you need urgently then just download the individual patch executable.

I subscribe to the Microsoft security bulletins by email so you are notified automatically and you get a link in the email to the files http://www.microsoft.com/security/bulletins/alerts.mspx

If you have a few machines at home then it could also be worth setting up WSUS http://www.microsoft.com/windowsserv...s/default.mspx
evilowl is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 28-03-2006, 09:04   #16 (permalink)
Forum Regular
 
SammyC's Avatar
 
Join Date: Jul 2005
Location: Bristol
Posts: 1,466
SammyC is on a distinguished roadSammyC is on a distinguished road

Image editing O.K.
User's Gallery
Quote:
Originally Posted by Steve
I am not against MS just IE. My recent experiances with web design has given me just reason to hate it with a passion. Just becasue they are massive company doesn't mean that they shouldn't play along to agreed browser standards, it is just plain pointless and shows their arrogance IMO.
I know what you mean Steve, I have a number of '#this is for IE' comments in my CSS files
The same was true of Netscape though before IE really was a contender, they had their own take on what HTML and CSS's should be interpreted as.

Still, I use FF and IE concurently, FF for my main websites and IE for quick browsing. I just fine IE faster to run on my old work PC.

SammyC is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 29-03-2006, 20:32   #17 (permalink)
Pixalo Crew
 
Steve's Avatar
 
Join Date: Jan 2005
Location: An Englishman living in Germany
Posts: 15,999
Steve is a jewel in the rough
Steve is a jewel in the roughSteve is a jewel in the rough

Image editing O.K.
User's Gallery
Users Camera Equipment List
Just an update for anyone still taking an interest in this...

Quote:
Security firms have released patches for a critical loophole in Microsoft's browser that leaves users open to attack.

The release pre-empts Microsoft which is not due to release a fix for the bug until 11 April.

The security firms said the patches were needed because hundreds of websites had been created to exploit the loophole.

But Microsoft said it did not recommend that users apply the patches.

Patch problem

In late March, three security loopholes were found in Microsoft's Internet Explorer browser by security firms.

The most serious of the three, known as the CreateTextRange bug, allowed malicious hackers to take over a PCs if it was used to visit specially crafted webpages.

Now two firms, eEye Digital Security and Determina, have separately produced software patches that close this loophole. Earlier, Microsoft said it would produce a patch in time for the next scheduled Windows security update that falls on 11 April.

Marc Maiffret, eEye's co-founder and chief hacking officer, said its patch was a stop-gap prior to the official version from Microsoft. He said eEye's patch would disable itself once the official version was released and installed.

Microsoft said it could not endorse the patches or recommend that users install them as they had not been through the software giant's testing and evaluation program.

Although Microsoft has played down the threat from people exploiting this loophole, others have found hundreds of websites built to take advantage of the bug in the IE web browser.

Websense said it had seen more than 200 unique web links that were trying to catch people out using the loophole.

On its security blog, Microsoft said it was working with law enforcement to shut down websites created to exploit the bug.
If you wish to check it out and install, you do so at your own risk. I am not an IE user nor recommending or condemning the above in any way
Steve is offline