IE (internet explorer) 8 is the new release of microsoft browser in the world, but who knows, there are holes in that browser that affected US firms. This is the bad news for Microsoft about their product.
How do you think about this IE hole and how to overcome this problems? Let see what will they take.
So, for more secure, you should not use it until the hole be prepared. Let's see and wait for a good news.
Attackers targeting Google and a host of other U.S. companies recently used software that exploits a new hole in Internet Explorer, Microsoft said Thursday.
"Internet Explorer was one of the vectors" used in the attacks that Google disclosed earlier this week, Microsoft said in a statement. "To date, Microsoft has not seen widespread customer impact, rather only targeted and limited attacks exploiting IE 6," the statement said.
The vulnerability affects Internet Explorer 6, IE 7, and IE 8 on Windows 7, Vista, Windows XP, Server 2003, Server 2008 R2, as well as IE 6 Service Pack 1 on Windows 2000 Service Pack 4, Microsoft said in an advisory on Thursday afternoon.
Google disclosed the attacks targeting it and other U.S. companies on Tuesday and said the attacks originated in China. Human rights activists who use Gmail also were targeted, Google said.
Source code was stolen from some of the more than 30 Silicon Valley companies targeted in the attack, sources said. Adobe has confirmed that it was targeted by an attack, and sources have said Yahoo, Symantec, Juniper Networks, Northrop Grumman, and Dow Chemical also were targets.
Microsoft said the vulnerability in IE exists as an invalid pointer reference and that it could allow an attacker to take control of a computer if the target were duped into clicking on a link in an e-mail or an instant message that led to a Web site hosting malware. "It could also be possible to display specially crafted Web content using banner advertisements or other methods to deliver Web content to affected systems," Microsoft said in the statement.
Microsoft is working on a fix but could not say whether it would address the issue as part of its next Patch Tuesday scheduled for February 9 or before.
Keeping the IE Internet zone security setting on "high" will protect users from the vulnerability by prompting before running ActiveX Controls and Active Scripting, Microsoft said. Customers should also enable Data Execution Prevention (DEP), which helps mitigate online attacks, the company said. DEP is enabled by default in IE 8 but must be manually turned on in earlier versions.
Microsoft acknowledged Google, Mandiant, Adobe Systems, and McAfee for working with the company and providing details on the attack.
Operation Aurora
Earlier on Thursday, McAfee CTO George Kurtz detailed the vulnerability in a blog post.
"As with most targeted attacks, the intruders gained access to an organization by sending a tailored attack to one or a few targeted individuals. We suspect these individuals were targeted because they likely had access to valuable intellectual property," Kurtz wrote. "These attacks will look like they come from a trusted source, leading the target to fall for the trap and clicking a link or file. That's when the exploitation takes place, using the vulnerability in Microsoft's Internet Explorer."
Many targeted attacks involve a "cocktail" of zero-day vulnerabilities combined with social engineering, he said. "So there very well may be other attack vectors that are not known to us at this time," he wrote.
Initially, security researchers investigating the attacks believed that a hole in Adobe Reader was a culprit, but Adobe has said that it has no evidence to suggest that a vulnerability in its technology was an attack vector.
McAfee believes the internal name attackers gave to the operation was "Aurora," which the code indicated was the directory name on the computer where the code was compiled into an executable file, said Dmitri Alperovitch, vice president of threat research at McAfee.
The attack was notable for its level of sophistication, using obfuscation techniques not typically seen in attacks on corporations, he said. It dropped about 10 different malicious files with different capabilities that were used at different stages of the infection and used crypto and other techniques to avoid detection, he added.
"The exploit itself was a piece of JavaScript code that encrypted itself and had multiple layers of encryption that got you to the executable binary code, which phoned home and then pulled an encrypted file from an external server," Alperovitch said. "That file used multiple keys for encryption and once it was decrypted it turned into an executable that dropped various modules onto the infected system."
One of the modules was a back door that phoned home to a different server and established an encrypted channel designed to avoid detection by masquerading as an Secure Sockets Layer protocol, he said. "That allowed the hackers to connect to the machine and basically take it over remotely. From then on they had a beachhead to explore the rest of the network for reconnaissance."
Asked what what type of data or areas of the network the code was programmed to look for or access, Alperovitch said "We saw the backdoor, but we did not see the capability in the malware to scan networks and locate things."
The attacks lasted about three weeks, from mid-December until January 4 and were most likely timed to coincide with the holiday season when offices would be closed or lightly staffed, he said.
In early January the command-and-control channels that the code used to receive instructions from the attackers were shut down, he said, adding, "So, we could not verify where the data was going or whether there were links to China."
He said he does not know why the command-and-control servers were shut down. They were located in Taiwan and in Texas and Illinois, he said.
"We believe this attack is a watershed moment," Alperovitch said. "We've never seen this level of sophistication on attacks targeting commercial companies that aren't affiliated with a government or the defense industrial base."
Internet Explorer (IE) hole exploited in attacks on U.S. firms
Subscribe now!
Post Comments (Atom)
145 comments:
thanks, your post very good. I like to read it
wow,,,, seremmm
wah bagus nih infonya....terimakasih
make me know... thx
i ussualy use firefox for my browser.
loan insurance
good info,.
thanks.
thank for post
i like it
I noted that Google's browser is a step ahead compared to Microsoft's.
Chrome
nice info thanks for information,,,
mantap juga infonya,,makasih dan sukses slalu,,
thanks for share,,,i like it,,,
keep blogging moga jadi ilmu yang berguna,,,,
info good everyting.
This is really a nice information and I liked it very much..
great post,,,thanks for share,,
terima kasih infonya,salam sukses saja
terima kasih infonya, semoga sukses selalu
Thakns for your sharing.
Your article is very usefull.
good news...very very great article
i hate IE 6.. I love Google Product
Nice Thanks for sharing.
Let me start by saying nice post. Im not sure if it has been talked about, but when using Chrome I can never get the entire site to load without refreshing many times. Could just be my computer. Thanks.
Kocaso M860W, A Budget Friendly Android 4.0 Tablet
Quiz and Game Solutions | Android and iOS Games and Applications
makasih infonya
great post...although i dont use it now
sungguh infonya sangat membantu saya mkasih
infonya menarik dan bermanfaat sekali infonya makasih semoga sukses selalu gan
nice to blog
salam kenal semuanya
nice share bro
thanks sob,,, keep posting
I very rarely use Internet Explorer so it was not so worried about security holes
mantap cuy
nice share nih mas brot
keep posting sobat
infonya sangat menarik
IE not browser but "junk"
not recomended laa for web designer
i using IE for browsing, stable if you update your IE
IE not stable browser i love firefox .. and linux platform =)
selamat sore dan salam kenal semuanya
memang mantap tuh IE
thanks banget ya sobat atas infomrasinya
mantap banget dah informasinya
nice share nih mass bro
thanksssssssss
thx informasinya gan
nice share ,, :)
nice share :)
thx nih infonya sangat bermanfaat
nice post nih gan
thx informasinya ,, :)
ijin menyimak nih gan
nice share ,, :D
mantap kali gan infonya
keep blogging kawand
like this gan
mantab deh infonya :)
ijin nyimak nih gan
happy bloging .. lam kenal :)
thx infonya sob
mantap nih .. ijin nyimak yaa
thx infonya nih
nice share .. :)
ijin nyima nih gan ..
kunjungan pagi dan pertama yang sekaligus menambah banyak pengetahuan saya, terimakasih banyak obat pengental sperma
thanks for your sharing...nice article
selamat pagi dan salam kenal semuanya, kunjungan pertama yang menambah pengetahuan saya, terimakasih banyak, jangan lupa kunjungan baliknya di obat penyakit
s
luar biasa sekali sangat bermanfaat informasinya... terimakasih banyak atas informasinya... semoga suksesnya....
luar biasa sekali sangat bermanfaat infonya..
Banyak pelajaran yang saya dapatkan pada blog ini...
Makasihnya...Semoga sukses...
seneng banget ni aku bisa nyimak artikel ini, tanks ya mas :)
info yang menraik
mantap juga ni gan info nyasukses yah ....
Informasinya boleh banget nih.
terimakasih ya atas informasinya
I do like your articel visit me @ pulau tidung
Terima kasih sudah berbagi info yang sangat menarik dan bermanfaat
Menarik sekali..
Artikel yang Anda berikan sangat bermanfaat,,
salam sehat..
informasi yang sangat bermanfaat..
semoga semakin sukses
terimakasih banyak pak untuk informasinya, sangat bermanfaat sekali. Salam kenal aja yah pak admin :)
semoga Tambah sukses Dan Sehat Selalu...Aminnn
Mantaap Websitenya Mantapppp
terimakasih sebelumnya atas informasinya, saya tunggu info yang
lainnya yaa. . . .
salam terhangat buat seluruh bangsa indonesia.
artikelnya sangat menarik untuk dibaca,penuh ilmu pengetahuan..terima kasih pak untuk semua informasinya ...
terima kasih atas semua informasi yang sudah disampaikan sangat bermanfaat sekali gan ..! ..ditunggu kunjungan bailknya
terima kasih atas semua informasi yang sudah disampaikan sangat bermanfaat sekali gan ..! ..ditunggu kunjungan bailknya
terima kasih pak admin telah menghadirkan informasi dan berita yg bermanfaat,semoga dengan sering di updated akan menjadikan website ini lebih bermanfaat lagi bagi pengunjung..
informasi dan berita yang agan berikan kepada kami sangat bermanfaat
makasih banyak atas semua informasinya. Saya sangat beruntung bisa menemukan situs web ini yang menarik sekali ..
postingan selanjutnya saya tunggu ...
selamat pagi selamat beraktivitas kembali gan .. :)
share nya semoga bermanfaat dan bertambah lagi ilmunya !!! trimakasih atas infonya pencerahan baru untuk saya
kunjungan sore sangat enak jika membaca artikel bermanfaat seperti ini.. makasih informasinya ya..
di tunggu postingan selanjutnya,karena di sini kami sangat tertarik dengan berita anda ..
terimakasih banyak atas artikel yang di sajikan hari ini,
sangat bermanfaat sekali untuk saya.
Sukses selalu yan buat website dan adminnya.
banyak hal positif yang dapat saya ambil dari artikel ini.
Terimakasih untuk infonya, di tunggu informasi terbarunya.
wow heemm mantap
gak ngerti bahasanya hehe
terimakasih untuk infromasi yang sangat berharga ini
Hai, Selamat siang !!
Apakabar hari ini ?? Mudah-mudahan semuanya dalam keadaan sehat, dan mudah-mudahan yang sakit, cepat diberikan kesembuhan ..
untuk informasi sebagus ini dan sharenya ane ucapin terima kasih banyak gan,,
senang berjumpa dengan anda!dengan artikel yang sangat bermanfaat.
terimakasih pak, informasinya sangat bermanfaat sekali
untuk menambah pengetahuan saya ..
Nice post, cocok buat nambah pengetahuan
post yang benar benar menarik dan bermanfaat ini ..
artikel yang sangat bermanfaat, semoga saja dapat memberikan kontribusi kepada para pembaca setia website ini. terimkasih yaahh .
artikelnya sangat bagus sekali nih.
terimakasi h atas informasi nya yaa ...
informasi yang sangat menarik gan, ikut menyimak dan salam sehat semua :)
semoga agan tidak pernah berhenti untuk menyampaikan informasi-informasi yang sangat menarik bagi pembaca nya , karena kami akan selalu menunggu informasi-informasi yang sangat bermutu seperti ini ....
di tunggu postingan selanjutnya,karena di sini kami sangat tertarik dengan berita anda ..
informasinya sungguh sangat berguna untuk menambah ilmu baru,terima kasih ya pak admin untuk informasi nyah ..
terima kasih banyak karena telah menyajikan berbagai informasi yang sangat menarik..
dengan membaca kita bisa belajar dan mengetahui hal-hal baru yang terjadi ..
terimkasih atas artikelnya kawan :)
terima kasih atas informasinya sangat membantu saya sekali
terima kasih, informasinya sangat berguna. Senang deh berkunjung ke website ini, semoga terus ditambah artikelnya. dengan lebih menarik lagi ...
Saya ucapkan terimakasih kepada pembuat artikel ini, artikel ini berisi informasi yang sangat bermanfaat untuk smeua pembaca khususnya saya sendiri. Saya tunggu lagi informasi-informasi lainnya yang tidak kalah menarik.
Sukses selalu untuk anda
banyak hal positif yang dapat saya ambil dari artikel ini terimakasih untuk infonya dan ane tunggu artikel selanjutnya yah gan :)
selamat siang :)
semangat yaaa ...
yang baca komenan ini akan semangat menjalani hari harinya :D
postingan di webnya sangat mengagumkan trimakasih atas informasinya
terimkasih infonya, sangat bagus sekali, mudah di mengerti dan tetap selalu menjadi web yang bagus .. sukses yaaa :)
terima kasih telah berbagi..
mudah2n jadi berkah dan manfaat gan..
website ini penuh dengan informasi yang bermanfaat .. thank
Kunjungan di pagi hari yang amat menyenangkan dengan suguhan artikel cukup menarik....
terima kasih, informasinya sangat berguna. Senang deh berkunjung ke website ini, semoga terus ditambah artikelnya.
Terimakasih Informasi informatifnya pa
info yang menarik gan terimakasih
makasi ya informasinya semoga bermanfaat tetap berkarya dan salam sehat yah kawan :)
share yang sangat ditunggu para pencari backlink, terimakasih :)
terima kasih, informasinya sangat bermanfaat.
Tambah terus informasinya yah.
terima kasih banyak untuk informasinya
senang bisa berkunjung.
selamat Siang. Mantap Bos Artikelnya, Terima kasih banyak sudah berbagi info yang menarik, sukses
Ini sungguh artikel yang sangat menarik, terima kasih sudah berbagi info..
keren postingannya.. AMAZING hehehe...
lanjutkan kk,
keren postingannya.. AMAZING hehehe...
lanjutkan kk,
www.betking88.net
Obat Biduran Atau Alergi Gatal Gatal Pada Kulit
Terima kasih sudah berbagi.
SEX TOY
SEX SHOP
ALAT BANTU SEX
Kumpulan Cerita Dewasa, Nonton Bokep Online, Film Semi dan Kumpulan Foto Bugil ..
Cerita Sex
Cerita Dewasa
Nonton Movie Online
Film Semi
Streaming Movie Online
Nonton Bioskop Online
Kumpulan Cerita Dewasa, Nonton Bokep Online, Film Semi dan Kumpulan Foto Bugil ..
Cerita Dewasa
Bokep Online
Cerita Sex
Film Semi
Info Judi Online Terpercaya
Info Judi Online
Info Judi Terpercaya
Judi Online
Kumpulan Agen poker terpercaya indonesia ..
Judi Poker Online | luckypoker99
Poker Uang Asli | luckypoker99
Agen Domino | luckypoker99
Bagi anda para pencinta taruhan bola, casino online. Mari bergabung bersama kami di HOKIBET. Minimal deposit hanya Rp 50.000, dengan proses deposit dan withdraw tercepat tanpa neko-neko.agen bola
Hi, saya ingin merekomendasikan salah satu situs judi online terpercaya di Indonesia yang menyediakan beragam permainan terpopuler kalangan seluruh masyarakat Indonesia seperti Sporsbook (taruhan bola), casino online, poker online, togel online, slot games dan lain sebagainya.
judi bola online
agen bola
AGEN JUDI SLOT
AGEN JUDI SLOT TERPERCAYA
Can scr888 you please scr888 Malaysia provide more scr888 apk information on this subject scr888 casino? BTW your blog scr 888 is great. Cheers.
Lovely pictures, awesome these are looking so romantic and locations are
rollex casino download for android great.
Lovely pictures, awesome live22 malaysia these are looking so romantic and locations are great.
To download the game to use the facilities of eager customers, you can apply for attachment of the support from the connection card of the safe website, which will encourage us be more successful, but allow us look what the application process is. Who are the members of secure websites using the bolster and are interested in investing? Can be fully invested by growing demand and addict expectations. Download the game For the investment process and relief see this here process that will back up us have a chance to succeed or profit from the investment, keep busy register as a zealot of a high-quality and high-quality website, which needs to be researched.
this web page from yahoo and start reading several of your other content. They are stunning. Pleasee continue this great work. Cheers,
The article gave us a significant Brainstorm session of all the possibilities we could make use of on our blog.
Pretty good post. I haveshopbymark
Hey, I think your really on target with this, I wont say I am completely on the same page, but its not really that big of a issue.
Hey this is a good post . Can I use a portion of it on my page? I would of course link to your site so people could view the complete article if they Sarah Berger
Leave a Comment
MAY YOU HAVE SOME IDEA, COMMENTS, WRITE IT DOWN