<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Krebs on Security &#187; ie6</title>
	<atom:link href="http://krebsonsecurity.com/tag/ie6/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Wed, 23 May 2012 14:03:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Test Your Browser&#8217;s Patch Status</title>
		<link>http://krebsonsecurity.com/2011/03/test-your-browsers-patch-status/</link>
		<comments>http://krebsonsecurity.com/2011/03/test-your-browsers-patch-status/#comments</comments>
		<pubDate>Wed, 30 Mar 2011 15:04:38 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[chrome]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[ie6]]></category>
		<category><![CDATA[IE7]]></category>
		<category><![CDATA[IE8]]></category>
		<category><![CDATA[IE9]]></category>
		<category><![CDATA[internet explorer]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[opera]]></category>
		<category><![CDATA[personal software inspector]]></category>
		<category><![CDATA[Qualys Browser Check]]></category>
		<category><![CDATA[Registry Mechanic]]></category>
		<category><![CDATA[shockwave]]></category>

		<guid isPermaLink="false">http://krebsonsecurity.com/?p=8784</guid>
		<description><![CDATA[With new security updates from vendors like Adobe, Apple and Java coming out on a near-monthly basis, keeping your Web browser patched against the latest threats can be an arduous, worrisome chore. But a new browser plug-in from security firm Qualys makes it quick and painless to find and patch outdated browser components.]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2011%252F03%252Ftest-your-browsers-patch-status%252F%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Test%20Your%20Browser%27s%20Patch%20Status%22%20%7D);"></div>
<p>With new security updates from vendors like <strong>Adobe</strong>, <strong>Apple</strong> and<strong> Java</strong> coming out on a near-monthly basis, keeping your Web browser patched against the latest threats can be an arduous, worrisome chore. But a new browser plug-in from security firm <strong>Qualys</strong> makes it quick and painless to identify and patch outdated browser components.</p>
<p><a class="lightbox" href="http://krebsonsecurity.com/wp-content/uploads/2011/03/qualysbrowsercheck.jpg"><img class="alignright size-medium wp-image-8900" title="qualysbrowsercheck" src="http://krebsonsecurity.com/wp-content/uploads/2011/03/qualysbrowsercheck-300x264.jpg" alt="Qualys Browser Check plug-in" width="300" height="264" /></a>The <a title="Qualys Browser Check" href="https://browsercheck.qualys.com/" target="_blank">Qualys BrowserCheck plug-in</a> works across multiple browsers &#8212; including <strong>Internet Explorer</strong>, <strong>Firefox</strong>, <strong>Chrome</strong> and <strong>Opera</strong>, on multiple operating systems. Install the plug-in, restart the browser, click the blue &#8220;Scan Now&#8221; button, and the results should let you know if there are any security or stability updates available for your installed plug-ins (a list of the plug-ins and add-ons that this program can check is available <a href="https://community.qualys.com/docs/DOC-1542#s2" target="_blank">here</a>). Clicking the blue &#8220;Fix It&#8221; button next to each action item listed fetches the appropriate installer from the vendor&#8217;s site and prompts you to download and install it. Re-scan as needed until the browser plug-ins are up to date.</p>
<p><strong>Secunia </strong>has long had a very similar capability built into its free <a href="http://krebsonsecurity.com/?s=personal+software+inspector&amp;x=0&amp;y=0" target="_blank">Personal Software Inspector</a> program, but I realize not everyone wants to install a new program + Windows service to stay abreast of the latest patches (Secunia also offers a <a href="http://secunia.com/vulnerability_scanning/online/" target="_blank">Web-based scan</a>, but it requires <strong>Java</strong>, a plug-in that I have <a href="http://krebsonsecurity.com/2010/10/java-a-gift-to-exploit-pack-makers/" target="_blank">urged users to ditch if possible</a>). The nice thing about Qualys&#8217; plug-in approach is that it works not only on Windows, but also on <strong>Mac</strong> and <strong>Linux</strong> machines. On Windows 64-bit systems, only the 32-bit version of Internet Explorer is supported, and the plug-in thankfully nudges IE6 and IE7 users to upgrade to at least IE8.</p>
<p>Having the latest browser updates in one, easy-to-manage page is nice, but remember that the installers you download may by default come with additional programs bundled by the various plug-in makers. For example, when I updated Adobe&#8217;s <strong>Shockwave</strong> player on my test machine, the option to install  <strong>Registry Mechanic</strong> was pre-checked. The same thing happened when I went to update my <strong>Foxit Reader</strong> plug-in, which wanted to set Ask.com as my default search provider, set ask.com as my home page, and have the Foxit toolbar added.</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2011/03/test-your-browsers-patch-status/feed/</wfw:commentRss>
		<slash:comments>41</slash:comments>
		</item>
		<item>
		<title>Another Way to Ditch IE6</title>
		<link>http://krebsonsecurity.com/2010/02/another-way-to-ditch-ie6/</link>
		<comments>http://krebsonsecurity.com/2010/02/another-way-to-ditch-ie6/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 10:55:53 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Latest Warnings]]></category>
		<category><![CDATA[alex holden]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[ie6]]></category>
		<category><![CDATA[internet explorer]]></category>
		<category><![CDATA[ms-its]]></category>

		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=787</guid>
		<description><![CDATA[This past week, I was reminded of a conversation I had with an ethical hacker I met at the annual Defcon security conference in Las Vegas, who showed me what may have been (and still remains) the shortest and most elegant trick I've seen to crash Internet Explorer 6 Web browser. I was reminded because the guy who told me about it said it still worked, even though he alerted Microsoft to the flaw back in 2004.]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2010%252F02%252Fanother-way-to-ditch-ie6%252F%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Another%20Way%20to%20Ditch%20IE6%22%20%7D);"></div>
<p>This past week, I was reminded of a conversation I had with an ethical hacker I met at the annual <strong>Defcon</strong> security conference in Las Vegas a couple of years back who showed me what remains the shortest, most elegant and reliable trick I&#8217;ve seen to crash the <strong>Internet Explorer 6</strong> Web browser.</p>
<p>If you&#8217;re curious and have IE6 lying around, type or cut and paste the following into the address bar (that last character is a zero):</p>
<p>ms-its:%F0:</p>
<p>or just click <a href="ms-its:%F0:" target="_self">this link</a> with IE6.</p>
<p>Here&#8217;s a short video example of the crash that results from typing that text above into an IE6 window:</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/ulYYtMyaNoc&amp;hl=en&amp;fs=1" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/ulYYtMyaNoc&amp;hl=en&amp;fs=1" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p><span id="more-787"></span></p>
<p>The &#8220;ms-its&#8221; bit is a reference to one of the helper extensions built into IE6. <strong>Alex Holden</strong>, the Wisconsin based researcher who showed me this crash, said the bug is the result of a <a href="http://goodfellas.shellcode.com.ar/docz/bof/fsp-overflows.txt" target="_blank">pointer overflow</a> in IE. The crash does not appear to work in newer versions of IE.</p>
<p>Holden said he notified Microsoft about his finding back in 2004. An e-mail thread Holden shared with krebsonsecurity.com indicates that Microsoft engineers believed there were no severe security consequences of this bug, and that it would probably be fixed in a future service pack. Obviously, it never was.</p>
<p>One way XP users might encounter this would be if the short code above or something like it were included in a link sent to a targeted user via instant message or e-mail. Indeed, one could imagine a computer worm that went around and changed the victim&#8217;s default home page to this short bit of code. The victim would be no longer be to get online&#8230;.with IE6, anyway (although a registry hack could almost certainly fix the swapped home page).</p>
<p>There is one interesting possible use for this tiny snippet of crash-inducing code. Maybe someone you know and care about insists on using IE6 or refuses to upgrade to IE7 or IE8. Install Firefox or some other browser alternative, and then change their IE home page to &#8220;ms-its:%F0:&#8221; Chances are good they will never be able to open IE6 again.</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2010/02/another-way-to-ditch-ie6/feed/</wfw:commentRss>
		<slash:comments>37</slash:comments>
		</item>
		<item>
		<title>Revisiting the Internet Explorer Security Bug</title>
		<link>http://krebsonsecurity.com/2010/01/revisiting-the-internet-explorer-security-bug/</link>
		<comments>http://krebsonsecurity.com/2010/01/revisiting-the-internet-explorer-security-bug/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 07:56:04 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Latest Warnings]]></category>
		<category><![CDATA[Dina Dai Zovi]]></category>
		<category><![CDATA[ie6]]></category>
		<category><![CDATA[mcafee]]></category>
		<category><![CDATA[Steve Ballmer]]></category>

		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=576</guid>
		<description><![CDATA[I had just finished opening an account at the local bank late last week when I happened to catch a glimpse of the bank manager&#8217;s computer screen: He had about 20 Web browser windows open, and it was hard to ignore the fact that he was using Internet Explorer 6 to surf the Web. For [...]]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2010%252F01%252Frevisiting-the-internet-explorer-security-bug%252F%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Revisiting%20the%20Internet%20Explorer%20Security%20Bug%22%20%7D);"></div>
<p>I had just finished opening an account at the local bank late last week when I happened to catch a glimpse of the bank manager&#8217;s computer screen: He had about 20 Web browser windows open, and it was hard to ignore the fact that he was using Internet Explorer 6 to surf the Web. <a href="http://www.krebsonsecurity.com/wp-content/uploads/2010/01/ieicon.jpg"><img class="alignright size-full wp-image-475" title="ieicon" src="http://www.krebsonsecurity.com/wp-content/uploads/2010/01/ieicon.jpg" alt="" width="102" height="104" /></a></p>
<p>For more than a second I paused, and considered asking for my deposit back.</p>
<p>&#8220;Whoa,&#8221; I said. &#8220;Are you really still using IE6?&#8221;</p>
<p>&#8220;Yeah,&#8221; the guy grinned sheepishly, shaking his head. &#8220;We&#8217;re supposed to get new computers soon, but I dunno, that&#8217;s been a long time coming.&#8221;</p>
<p>&#8220;Wow. That&#8217;s nuts,&#8221; I said. &#8220;You&#8217;ve heard about this latest attack on IE, right?&#8221;</p>
<p>I might as well have asked him about the airspeed velocity of an African Swallow. Dude just shook his head, and so did I.</p>
<p>Well, you can&#8217;t really blame the poor guy for not knowing. Just hours before, <strong>Microsoft Chief Executive Steve Ballmer</strong> looked a bit like a deer in headlights when, standing in front of the White House in a planned <a href="http://www.cnbc.com/id/15840232?video=1385649601&amp;play=1" target="_blank">CNBC interview</a> on how the Obama administration is looking to use technology to streamline its operations, he was suddenly asked about a report just released from <strong>McAfee</strong> effectively blaming a slew of recent cyber break-ins at Google, Adobe and more than 30 top other Silicon Valley firms on a previously unknown flaw in IE.</p>
<p>&#8220;Cyber attacks and occasional vulnerabilities are a way of life,&#8221; Ballmer said. &#8220;If the issue is with us, we’ll work through it with all of the important parties. We have a whole team of people that responds very real time to any report that it may have something to do with our software, which we don’t know yet.&#8221;</p>
<p><span id="more-576"></span></p>
<p>Microsoft has of course since acknowledged that a critical, unpatched security flaw indeed exists and is being exploited in targeted attacks. The software giant says it has only observed the now-public exploit code working against IE6, and that IE users should upgrade to the latest version IE8, which Microsoft says is much better insulated from the current batch of exploits.</p>
<p>Redmond typically releases software updates on the second Tuesday of each month (a.k.a. &#8220;Patch Tuesday), but the company said in this case customers may not have to wait until Feb. 9 for a patch for this security hole. Microsoft is eager to assure everyone that the attacks observed so far are only successful against IE6, and that in any event they have not been widespread.</p>
<p>Meanwhile, researchers continue to test that claim. Researcher <strong>Dino Dai Zovi</strong> Tweeted Monday that he had modified the existing exploit so that it worked on IE7, with the caveat that on Microsoft Vista systems it would only allow an attacker read access to the victim&#8217;s files (as opposed to full privileges to delete or modify system files).</p>
<p>In a sign that we may very soon start to see a number of hacked and malicious Web sites leveraging this flaw to install unwanted software, security firm Websense <a href="http://securitylabs.websense.com/content/Blogs/3530.aspx" target="_self">warned</a> that it had spotted a Web site that was exploiting the IE vulnerability.</p>
<p>Microsoft&#8217;s assurances have not been enough for some. The governments of France and Germany <a href="http://www.sfgate.com/cgi-bin/blogs/techchron/detail?&amp;entry_id=55509" target="_blank">have urged people to stop using Internet Explorer</a> (<strong>Update, 1:16 p.m: </strong>The Australian government <a href="http://www.abc.net.au/news/stories/2010/01/19/2795684.htm" target="_blank">just issued a similar warning</a>). For its part, the U.S. government<a href="http://edition.cnn.com/2010/TECH/01/17/china.google" target="_blank"> is expected to issue a demarche</a> to the Chinese government, looking for an explanation of the attacks against Google and others, which experts have described as a sophisticated and targeted attempts to steal trade industry secrets, as well as information about Chinese dissident groups.</p>
<p>At least one top Chinese computer security firm is urging consumers there not to wait for Microsoft&#8217;s patch, but to instead <a href="http://translate.google.com/translate?hl=en&amp;sl=zh-CN&amp;tl=en&amp;u=http%3A%2F%2Fbbs.ejinqiao.com%2Fdispbbs.php%3Fid%3D25787">install</a> <a href="http://translate.google.com/translate?js=y&amp;prev=_t&amp;hl=en&amp;ie=UTF-8&amp;layout=1&amp;eotf=1&amp;u=http%3A%2F%2F3dmgame.chnren.com%2Fbbs%2Fshowtopic-1086875.html&amp;sl=zh-CN&amp;tl=en" target="_blank">an unofficial, stop gap fix</a> (rough, Google translation). No doubt, if the wait drags on for an update from Microsoft, we will see the same offers from U.S. security firms and experts.</p>
<p>There are, of course, alternatives to IE. But then again, I&#8217;m preaching to the choir. Most of my readers already use another browser, according to the latest visitor stats for krebsonsecurity.com, compliments of Google Analytics. Here&#8217;s how my visitors break down:</p>
<p><a href="http://www.krebsonsecurity.com/wp-content/uploads/2010/01/browsershare.jpg"><img class="aligncenter size-medium wp-image-578" title="browsershare" src="http://www.krebsonsecurity.com/wp-content/uploads/2010/01/browsershare-300x175.jpg" alt="" width="300" height="175" /></a></p>
<p>Looks like krebsonsecurity.com does have some IE6 users (and at least one IE5! user). Nearly 14 percent of the visitors browsing this site with IE are using IE6:  Here&#8217;s the visitor breakdown by IE version:</p>
<p><a href="http://www.krebsonsecurity.com/wp-content/uploads/2010/01/ieversion.jpg"><img class="aligncenter size-medium wp-image-589" title="ieversion" src="http://www.krebsonsecurity.com/wp-content/uploads/2010/01/ieversion-300x177.jpg" alt="" width="300" height="177" /></a></p>
<p>If you do want to keep browsing with IE (or, work at an organization like my bank which apparently doesn&#8217;t have much choice in the matter), Microsoft has some tips <a href="http://blogs.technet.com/msrc/archive/2010/01/18/advisory-979352-update-for-monday-january-18.aspx" target="_self">here</a> on ways to leverage additional protections both in Windows and in newer IE versions.</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2010/01/revisiting-the-internet-explorer-security-bug/feed/</wfw:commentRss>
		<slash:comments>60</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 3/9 queries in 0.001 seconds using memcached
Object Caching 543/545 objects using memcached

Served from: krebsonsecurity.com @ 2012-05-24 11:17:23 -->
