"…Continuing Report: Unpatched IE Vulnerabilities
This is ground that's been tread over and over again recently, but it bears repeating: We are continuing to receive reports of exploitation of unpatched vulnerabilities in Internet Explorer resulting in code execution and system compromise. Take whatever precautions you feel are necessary to avoid becoming a victim…"
- http://www.microsoft.com/security/incident…ct.mspx?pf=true
Updated July 2, 2004 6:00 A.M. Pacific Time
"…On Friday, July 2, 2004, Microsoft is releasing a configuration change for Windows XP, Windows 2000, and Windows Server 2003, to address recent malicious attacks against Internet Explorer, also know as Download.Ject. Windows customers are encouraged to apply this configuration change immediately to help be protected from current Internet Explorer exploits. The update is currently available on the Download Center and will be made available later today on Windows Update… Supported Operating Systems: Windows 2000, Windows NT, Windows Server 2003, Windows XP…
- How does the extended support for Windows Millennium Edition, Windows 98 Second Edition, and Windows 98 affect the release of this update for these operating systems?
Updates for these operating systems may not be available concurrently with the other updates provided as part of this bulletin, but they will be made available as soon as possible following this release. However, customers who feel comfortable creating these configuration changes manually can have the additional protection on their systems today by following the instructions in Knowledge Base Article 870669…"
- http://www.siliconvalley.com/mld/siliconva…/printstory.jsp
Jul. 02, 2004
"Microsoft Corp. issued an interim security update Friday to protect users of its nearly ubiquitous Internet Explorer browsers from a new technique for spreading viruses. The update does not entirely fix the flaw that makes the spread possible, but it changes settings in Windows operating systems to disable hackers' ability to deliver malicious code with it…Friday's setting changes thwart any attack by prohibiting a Web application from writing files – such as the virus code – onto users' computers. Stephen Toulouse, a security program manager at Microsoft, said the company still was working on a comprehensive patch to fix vulnerabilities with Internet Explorer, but the settings change should protect users from the immediate threat…"
Microsoft Plugs IE; Report Warns All Browsers At Risk
- http://www.techweb.com/wire/story/TWB20040702S0007
July 2, 2004
"As if to prove the point that security is like the Dutch boy at the dike, Microsoft on Friday released a stop-gap fix for one of several vulnerabilities that have plagued its Internet Explorer just as a security firm warned that virtually every browser – not just IE – can be spoofed by hackers. The update, which Microsoft tagged as "Critical", isn't a patch per se, but rather an change to Windows that disables the ADODB.Stream object within the operating system's Data Access Components (DAC)…Wednesday, Secunia issued a warning saying it had discovered a vulnerability within IE that allowed scammers to spoof, or fake, the content of a site displayed in the browser.
- On Friday, however, the security vendor modified the alert to claim that virtually every browser, from Internet Explorer and Mozilla to Opera and Netscape – including browsers for both Windows and the Mac OS – has this flaw. "It's not a code vulnerability," said Secunia's Kristensen, "but a design flaw." The problem stems from how browsers handle frames. "Some time ago, browser designers decided that one site needed to be able to manipulate the content of another, and the functionality was adopted by everyone," said Kristensen. But hackers can use this to inject phony content – say their own credit card-stealing form – into a frame of an actual trusted Web site, such as a user's online bank. "In these times of phishing attacks and other scams, this is a problem," said Kristensen. "You're visiting a bank or an e-commerce site, and you're certain of that site, but meanwhile, it's [actually] open in the background to content change by hackers." Internet Explorer users can stymie such spoofing attacks by disabling the "Navigate sub-frames across different domains" setting under Tools/Internet Options/Security.
Secunia offered up a quick test that users can run to see if their current browser is vulnerable to this problem."
>>> http://secunia.com/multiple_browsers_frame…erability_test/
Internet Explorer users can stymie such spoofing attacks by disabling the "Navigate sub-frames across different domains" setting under Tools/Internet Options/Security.
> Issue #2: Multiple Browsers Frame Injection Vuln
- http://secunia.com/advisories/11978/ "…Secunia issued a warning saying it had discovered a vulnerability within IE that allowed scammers to spoof, or fake, the content of a site displayed in the browser. On Friday, however, the security vendor modified the alert to claim that virtually every browser, from Internet Explorer and Mozilla to Opera and Netscape – including browsers for both Windows and the Mac OS – has this flaw. 'It's not a code vulnerability,' said Secunia's Kristensen, 'but a design flaw.'…"
>> Workaround for IE:
"…Internet Explorer users can stymie such spoofing attacks by disabling the 'Navigate sub-frames across different domains' setting under Tools/Internet Options/Security…"
- http://www.securitypipeline.com/news/showA…bleArticle=true
"…What's missing from this month's security fixes…is a top-to-bottom patch for several bugs in Microsoft's Internet Explorer browser. Vulnerabilities in IE have been exploited by several prominent attacks of recent weeks, including one run by Russian hackers that dropped Trojan horses and keyloggers on systems. On July 2, Microsoft released a temporary fix, but it has yet to produce a permanent patch. Then, Microsoft said it was working on a series of updates to IE in "coming week" company executives last week wouldn't commit to a release date, or even if it would roll out IE fixes in the monthly patch cycle. From the content of the security bulletins posted Tuesday, Redmond's passed…IE fixes are AWOL…"
New Phishing Technique Works on Multiple Browsers
- http://www.eweek.com/print_article/0,1761,a=131696,00.asp
July 19, 2004
"A British Web developer has revealed a new form of a cross-site scripting, or XSS, attack that facilitates phishing activities. The attack…allows an attacker to execute scripts in the context of another Web site. Testing by eWEEK.com indicates that the attack works on both Internet Explorer on Windows XP with SP2 (Release Candidate 2) and on the Mozilla Firefox 0.9.1 browser…The main, obvious effect of the attack is that the page appears to be running in the victim site, but is incorporating elements from the attacker site. An attacker could therefore use the technique to persuade a user to provide personal information…Cross-site scripting attacks have been a hot item recently in security circles, but usually as a way to run scripts in the local machine context for a browser user and attack that computer. Using it against a Web site to spoof that site is new. Netcraft adds: "Although cross-site scripting has been a well known technique for over four years, it is an easy mistake for programmers to make, and can be an awkward one to test thoroughly."…"
Microsoft To Patch IE Next Week
- http://www.techweb.com/wire/story/TWB20040729S0004
July 29, 2004 - By Gregg Keizer, TechWeb News
"Microsoft executives said that a comprehensive patch for Internet Explorer will be released next week, finally plugging the hole that hackers exploited in a sneak attack during June…"We're targeting the release within the next week," said Dean Hachamovitch Wednesday in the security-oriented hosted monthly by Mike Nash, the head of Microsoft's security efforts. "We're doing our final checks right now." The upcoming patch will be released "out of cycle," said Hachamovitch, who oversees development for IE. That means it will appear before Microsoft's next regular-scheduled patch day. Microsoft rarely departs from the second-Tuesday-of-the-month schedule, an indication of how critical the company sees the fix. The next scheduled patch day is August 10. IE's patch, which will apply to IE 5.01, 5.5, and 6.0, was long in development and testing, said Hachamovitch, because "the core vulnerability was complicated." He also noted that extensive testing – both on other applications that might be affected by the patch and the various versions of IE and Windows – meant the patch took longer to finalize…"
- http://www.microsoft.com/technet/security/…n/ms04-025.mspx Microsoft Security Bulletin MS04-025
Cumulative Security Update for Internet Explorer (867801) Issued: July 30, 2004
Version: 1.0
- Summary:
- Who should read this document: Customers who use Microsoft® Internet Explorer
- Impact of Vulnerability: Remote Code Execution
- Maximum Severity Rating: Critical
- Recommendation: Customers should apply the update immediately.
- Security Update Replacement: This update replaces the one that is provided in Microsoft Security Bulletin MS04-004, which is itself a cumulative update.
- Caveats: This update does not include hotfixes for Internet Explorer provided since the release of MS04-004. Customers who have received hotfixes from Microsoft or their support providers since the release of MS04-004 should review the FAQ section for this update to determine how this update might impact their operating systems…"
Update to MS04-025 for XP users
- http://isc.sans.org/diary.php?date=2004-08-01
Updated August 2nd 2004 01:25 UTC
"For all folks using Windows XP, it is advised that you do another Windows Update to ensure that your patches have been correctly updated.
Microsoft stated the following:
'Subsequent to the release of this security bulletin, Microsoft was made aware that the update provided for Windows XP customers running the new version of Windows Update, Windows Update Version 5, did not contain the final release code for the vulnerabilities addressed in the security bulletin. Microsoft has corrected the update and is re-releasing this bulletin to advise of the availability of a revised update available to Windows Update Version 5 customers. Customers who are utilizing Windows Update Version 4, the vast majority of customers, are not affected by this revision'…"
- http://www.microsoft.com/technet/security/…n/ms04-025.mspx
Updated: August 1, 2004
Version: 2.0