<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Exploit in the Wild for New Internet Explorer Flaw</title>
	<atom:link href="http://krebsonsecurity.com/2010/01/exploit-in-the-wild-for-new-internet-explorer-flaw/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2010/01/exploit-in-the-wild-for-new-internet-explorer-flaw/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Wed, 23 May 2012 01:40:28 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: PJ</title>
		<link>http://krebsonsecurity.com/2010/01/exploit-in-the-wild-for-new-internet-explorer-flaw/comment-page-1/#comment-506</link>
		<dc:creator>PJ</dc:creator>
		<pubDate>Sun, 17 Jan 2010 16:26:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=498#comment-506</guid>
		<description>Wasn&#039;t there some speculation about Microsoft source code that was viewed by China?</description>
		<content:encoded><![CDATA[<p>Wasn&#8217;t there some speculation about Microsoft source code that was viewed by China?</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-506" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('506', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-506-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-506" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('506', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-506-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: lembark</title>
		<link>http://krebsonsecurity.com/2010/01/exploit-in-the-wild-for-new-internet-explorer-flaw/comment-page-1/#comment-505</link>
		<dc:creator>lembark</dc:creator>
		<pubDate>Sun, 17 Jan 2010 15:45:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=498#comment-505</guid>
		<description>I&#039;m noticing a pattern: In the last year a significant number of your articles note security holes in all available version of IE. The usual fix is to not use IE version-X (or altogether) &quot;until&quot; MS fixes the problem.

Catch: There is always a new &quot;problem&quot; soon after.

Perhaps the real problem is that IE is fundamentally insecure because of its design criteria: MS simply considers cute features more important than security.

This offers an alternative fix for you to suggest: There are enough alternatives available on the market today -- many of them free -- that the only reasonable fix is to replace IE permanently.</description>
		<content:encoded><![CDATA[<p>I&#8217;m noticing a pattern: In the last year a significant number of your articles note security holes in all available version of IE. The usual fix is to not use IE version-X (or altogether) &#8220;until&#8221; MS fixes the problem.</p>
<p>Catch: There is always a new &#8220;problem&#8221; soon after.</p>
<p>Perhaps the real problem is that IE is fundamentally insecure because of its design criteria: MS simply considers cute features more important than security.</p>
<p>This offers an alternative fix for you to suggest: There are enough alternatives available on the market today &#8212; many of them free &#8212; that the only reasonable fix is to replace IE permanently.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-505" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('505', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-505-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-505" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('505', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-505-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Stardance</title>
		<link>http://krebsonsecurity.com/2010/01/exploit-in-the-wild-for-new-internet-explorer-flaw/comment-page-1/#comment-496</link>
		<dc:creator>Stardance</dc:creator>
		<pubDate>Sun, 17 Jan 2010 07:08:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=498#comment-496</guid>
		<description>The Microsoft Security Advisory about this vulnerability that Brian included in his entry on January 14 says that I.E. 8, as well as I.E. 7 and I.E. 6, are among the affected versions:

http://www.microsoft.com/technet/security/advisory/979352.mspx</description>
		<content:encoded><![CDATA[<p>The Microsoft Security Advisory about this vulnerability that Brian included in his entry on January 14 says that I.E. 8, as well as I.E. 7 and I.E. 6, are among the affected versions:</p>
<p><a href="http://www.microsoft.com/technet/security/advisory/979352.mspx" rel="nofollow">http://www.microsoft.com/technet/security/advisory/979352.mspx</a></p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-496" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('496', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-496-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-496" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('496', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-496-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Steve</title>
		<link>http://krebsonsecurity.com/2010/01/exploit-in-the-wild-for-new-internet-explorer-flaw/comment-page-1/#comment-490</link>
		<dc:creator>Steve</dc:creator>
		<pubDate>Sun, 17 Jan 2010 00:00:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=498#comment-490</guid>
		<description>This is something I just saw on a telecom e-mail list I subscribe to . . .

-----

Official German warning regarding use of Internet Explorer

http://bit.ly/8AYPpE  (Federal Office for Information Security - Bonn, Germany)

http://bit.ly/8VkQsA  (Google translation into English)</description>
		<content:encoded><![CDATA[<p>This is something I just saw on a telecom e-mail list I subscribe to . . .</p>
<p>&#8212;&#8211;</p>
<p>Official German warning regarding use of Internet Explorer</p>
<p><a href="http://bit.ly/8AYPpE" rel="nofollow">http://bit.ly/8AYPpE</a>  (Federal Office for Information Security &#8211; Bonn, Germany)</p>
<p><a href="http://bit.ly/8VkQsA" rel="nofollow">http://bit.ly/8VkQsA</a>  (Google translation into English)</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-490" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('490', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-490-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-490" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('490', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-490-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: yuk bon</title>
		<link>http://krebsonsecurity.com/2010/01/exploit-in-the-wild-for-new-internet-explorer-flaw/comment-page-1/#comment-482</link>
		<dc:creator>yuk bon</dc:creator>
		<pubDate>Sat, 16 Jan 2010 20:29:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=498#comment-482</guid>
		<description>the google attacks were against dissidents, no? I can&#039;t see how anyone other than the chinese government would bother with that.</description>
		<content:encoded><![CDATA[<p>the google attacks were against dissidents, no? I can&#8217;t see how anyone other than the chinese government would bother with that.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-482" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('482', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-482-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-482" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('482', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-482-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Rick</title>
		<link>http://krebsonsecurity.com/2010/01/exploit-in-the-wild-for-new-internet-explorer-flaw/comment-page-1/#comment-481</link>
		<dc:creator>Rick</dc:creator>
		<pubDate>Sat, 16 Jan 2010 20:11:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=498#comment-481</guid>
		<description>This doesn&#039;t seem to be a &#039;reaction&#039; to anything.</description>
		<content:encoded><![CDATA[<p>This doesn&#8217;t seem to be a &#8216;reaction&#8217; to anything.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-481" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('481', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-481-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-481" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('481', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-481-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Rick</title>
		<link>http://krebsonsecurity.com/2010/01/exploit-in-the-wild-for-new-internet-explorer-flaw/comment-page-1/#comment-480</link>
		<dc:creator>Rick</dc:creator>
		<pubDate>Sat, 16 Jan 2010 20:09:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=498#comment-480</guid>
		<description>Ah yes the Honkers. They&#039;ve been around a long time... ;)</description>
		<content:encoded><![CDATA[<p>Ah yes the Honkers. They&#8217;ve been around a long time&#8230; <img src='http://krebsonsecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-480" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('480', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-480-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-480" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('480', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-480-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Rick</title>
		<link>http://krebsonsecurity.com/2010/01/exploit-in-the-wild-for-new-internet-explorer-flaw/comment-page-1/#comment-479</link>
		<dc:creator>Rick</dc:creator>
		<pubDate>Sat, 16 Jan 2010 20:08:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=498#comment-479</guid>
		<description>Servers, yes. But the individual boxes which might be directly accessible or through a targeted mail attack...</description>
		<content:encoded><![CDATA[<p>Servers, yes. But the individual boxes which might be directly accessible or through a targeted mail attack&#8230;</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-479" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('479', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-479-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-479" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('479', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-479-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Rick</title>
		<link>http://krebsonsecurity.com/2010/01/exploit-in-the-wild-for-new-internet-explorer-flaw/comment-page-1/#comment-478</link>
		<dc:creator>Rick</dc:creator>
		<pubDate>Sat, 16 Jan 2010 20:05:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=498#comment-478</guid>
		<description>Or Safari for OS X even. Then you&#039;re really secure! Or Chrome or FF for Linux or OS X or Camino for OS X. There are so many good alternatives!</description>
		<content:encoded><![CDATA[<p>Or Safari for OS X even. Then you&#8217;re really secure! Or Chrome or FF for Linux or OS X or Camino for OS X. There are so many good alternatives!</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-478" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('478', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-478-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-478" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('478', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-478-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: M Henri Day</title>
		<link>http://krebsonsecurity.com/2010/01/exploit-in-the-wild-for-new-internet-explorer-flaw/comment-page-1/#comment-475</link>
		<dc:creator>M Henri Day</dc:creator>
		<pubDate>Sat, 16 Jan 2010 19:36:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=498#comment-475</guid>
		<description>George Kurtz&#039;s «McAfee Security Blog» has the following to say on the matter :

«Our investigation has shown that Internet Explorer is vulnerable on all of Microsoft’s most recent operating system releases, including Windows 7. Still, so far the attacks we’ve seen using this vector have been focused on Internet Explorer 6. Microsoft has been working with us on this matter and we thank them for their collaboration.»

The above isn&#039;t what one would call pellucid, but I interpret it to mean that *all* versions of IE, including IE8 which is installed by default on Windows 7, are affected. Google China may well have been testing websites and services on IE6, as, according to StatCounter&#039;s statistics (http://preview.tinyurl.com/y933y5o ), as many as 60 % of Chinese users are still running this ancient, and very unsafe browser (in a country where the domination of IE is total - perhaps the Chinese would do well to test other browsers ?). But I find it hard to believe that Google employees, as aware as they must be of security concerns, would have been using the browser for anything other than the purposes described above. And Google&#039;s servers run Linux OS, so I find it difficult to imagine that IE, and in particular, IE6 could have been used as an attack vector to access privileged data, which presumably would not be available on computers used for testing how websites render. There are a fair number of factors in reports being promoted on the web that, to me at least, don&#039;t seem to add up....

Henri</description>
		<content:encoded><![CDATA[<p>George Kurtz&#8217;s «McAfee Security Blog» has the following to say on the matter :</p>
<p>«Our investigation has shown that Internet Explorer is vulnerable on all of Microsoft’s most recent operating system releases, including Windows 7. Still, so far the attacks we’ve seen using this vector have been focused on Internet Explorer 6. Microsoft has been working with us on this matter and we thank them for their collaboration.»</p>
<p>The above isn&#8217;t what one would call pellucid, but I interpret it to mean that *all* versions of IE, including IE8 which is installed by default on Windows 7, are affected. Google China may well have been testing websites and services on IE6, as, according to StatCounter&#8217;s statistics (<a href="http://preview.tinyurl.com/y933y5o" rel="nofollow">http://preview.tinyurl.com/y933y5o</a> ), as many as 60 % of Chinese users are still running this ancient, and very unsafe browser (in a country where the domination of IE is total &#8211; perhaps the Chinese would do well to test other browsers ?). But I find it hard to believe that Google employees, as aware as they must be of security concerns, would have been using the browser for anything other than the purposes described above. And Google&#8217;s servers run Linux OS, so I find it difficult to imagine that IE, and in particular, IE6 could have been used as an attack vector to access privileged data, which presumably would not be available on computers used for testing how websites render. There are a fair number of factors in reports being promoted on the web that, to me at least, don&#8217;t seem to add up&#8230;.</p>
<p>Henri</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-475" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('475', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-475-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-475" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('475', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-475-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 3/19 queries in 0.004 seconds using memcached
Object Caching 958/966 objects using memcached

Served from: krebsonsecurity.com @ 2012-05-22 23:49:17 -->
