AplusWebMaster
Topic Starter
FYI…
MS Bulletin MS04-004
Cumulative Security Update for Internet Explorer (832894)
- http://www.microsoft.com/technet/treeview/…in/MS04-004.asp
"…
Impact of vulnerability: Remote Code Execution
Maximum Severity Rating: Critical…"
(Cumulative update for IEv6 contains 3 patches)
Use WindowsUpdate
-or- download the patch from here:
- http://www.microsoft.com/downloads/details…&displaylang=en
==============================================
FYI…suggest checking with your financial sites PRIOR to installing the patch!
IE Patch Could Disrupt E-Commerce
- http://www.internetnews.com/ec-news/print.php/3306451
January 30, 2004
"Microsoft's planned Internet Explorer modification to fix security holes in the browser could disrupt e-commerce sites that use clear text to authenticate user names and passwords. Lead product manager in Microsoft's Windows division Greg Sullivan told internetnews.com that e-commerce Web sites that send clear text for authentication will return an "invalid syntax error" on Web pages once a user applies the IE patch. That's because the updated browser will remove support for handling user names and passwords in both HTTP and HTTPS URLs. The withdrawn support for clear text authentication effectively provides a workaround for the URL-spoofing flaws that are commonly used by scammers to mask fake sites and trick users into giving up sensitive information including credit card and social security numbers. In advance of the patch release, Microsoft made the unusual move of releasing a knowledge base article to provide details and workarounds for application and Web site developers that still use clear text authentication…"
MS Bulletin MS04-004
Cumulative Security Update for Internet Explorer (832894)
- http://www.microsoft.com/technet/treeview/…in/MS04-004.asp
"…
Impact of vulnerability: Remote Code Execution
Maximum Severity Rating: Critical…"
(Cumulative update for IEv6 contains 3 patches)
Use WindowsUpdate
-or- download the patch from here:
- http://www.microsoft.com/downloads/details…&displaylang=en
==============================================
FYI…suggest checking with your financial sites PRIOR to installing the patch!
IE Patch Could Disrupt E-Commerce
- http://www.internetnews.com/ec-news/print.php/3306451
January 30, 2004
"Microsoft's planned Internet Explorer modification to fix security holes in the browser could disrupt e-commerce sites that use clear text to authenticate user names and passwords. Lead product manager in Microsoft's Windows division Greg Sullivan told internetnews.com that e-commerce Web sites that send clear text for authentication will return an "invalid syntax error" on Web pages once a user applies the IE patch. That's because the updated browser will remove support for handling user names and passwords in both HTTP and HTTPS URLs. The withdrawn support for clear text authentication effectively provides a workaround for the URL-spoofing flaws that are commonly used by scammers to mask fake sites and trick users into giving up sensitive information including credit card and social security numbers. In advance of the patch release, Microsoft made the unusual move of releasing a knowledge base article to provide details and workarounds for application and Web site developers that still use clear text authentication…"