Profile

unixronin: Galen the technomage, from Babylon 5: Crusade (Default)
Unixronin

December 2012

S M T W T F S
      1
2345678
9101112131415
16171819202122
23242526272829
3031     

Most Popular Tags

Expand Cut Tags

No cut tags
Wednesday, December 17th, 2008 11:05 am

Via C|Net:

Critical IE 7 exploit making the rounds

Microsoft issued a critical security warning Tuesday that a malicious exploit is making the rounds and attacking vulnerabilities in Internet Explorer 7.  [...]

You almost have to wonder why they even bother making the announcement.  Has there ever been a period longer than about a week when there was NOT some unpatched system-pwning Internet Explorer exploit in the wild?

Tags:
Wednesday, December 17th, 2008 05:16 pm (UTC)
In a world where the flu is rampant, this one has the potential to be eboli.
Wednesday, December 17th, 2008 05:42 pm (UTC)
I don't see what it is about this one that makes it any worse than any of the past complete-system-compromise IE holes. I mean, in the final analysis your system can really only be just so pwn3d.


(Besides, none of the hemorrhagic fevers has ever spread far yet, because they kill their hosts before they actually get a chance to infect many new ones. The worst hemorrhagic fever outbreak on record, the Marburg outbreak of 2005 in Uige Province, Angola, killed 244 people; by comparison, the 1918 Spanish 'flu pandemic killed between 20 and 40 million people in a single year, more than the Black Death killed in four.)
Wednesday, December 17th, 2008 05:58 pm (UTC)
The problem with this one is that it's being pretty aggressively pursued by malware people these days.

Christmas has always historically been the Big Infection Vector, with lots of people getting new computers. We've got a bit of a "perfect storm" effect, combining Christmas, large pre-existing botnets, and aggressively deployed injection attacks on major Internet sites. Further, it happens right after Patch Tuesday, which gives the maximum possible time for infection.

So it's not the exploit itself that could cause problems, it's the timing and the aggressiveness of the attack.

Wednesday, December 17th, 2008 06:01 pm (UTC)
Good point on that, btw. A few weeks ago my gf downloaded and installed a "special" media player to play an Office episode.

It installed every malware product you could imagine: the installer looked perfectly legitimate, the website was stunningly well designed, and the only sign that something was wrong was when the maching started metaphorically spewing blood out of all its orifices.

Had the malware been less aggressive, we probably wouldn't even have noticed for a week or so, but it made the machine so unusable that we had to reformat and reinstall the same day.
Wednesday, December 17th, 2008 06:02 pm (UTC)
To fix up the eboli metaphor somewhat, you'd imagine that eboli infected all the mosquitos in North America. Then it doesn't matter how infectious it is to humans.