ciphergoth: (Default)
[personal profile] ciphergoth
Fab fab fab fab party. Fab. Ta muchly.

Update thanks to the ever-alert [livejournal.com profile] deliberateblank.

Microsoft have released a fix to the critical vulnerability I discussed earlier. However, it appears that this fix doesn't actually plug the vulnerability. It's probably still worth keeping your box up-to-date with Windows Update, but it won't protect you against this attack.

I still recommend that you either use Mozilla Firefox or another alternative to IE. If for some reason this is not an option, don't use IE to browse the wider Web.

Date: 2004-07-05 09:57 am (UTC)
From: [identity profile] thekumquat.livejournal.com
I did have reasonable faith in out IT bods to keep out nasties (despite them giving us only IE to use), but today I got my first ever spam at work...

Looks like I'll just have to live with the vulnerability, seeing as hacking about to the extent needed to install other browsers would be classed as gross misconduct.

Date: 2004-07-05 12:48 pm (UTC)
booklectica: my face (crucifix)
From: [personal profile] booklectica
Unrelatedly: is your email working now?

Date: 2004-07-05 06:01 pm (UTC)
From: [identity profile] pavlos.livejournal.com
I laugh at the continued misfortunes of Windows users. Well, actually my mac does have IE installed somewhere and I pray it never gets activated by mistake (although MacOS has a nice feature where it alerts you if a program gets used for the first time).

In case you wonder what would happen if Microsoft did fix their software, see here. I quote:

Microsoft's last major delay of Windows XP Service Pack 2 was caused by a hue and cry from enterprise evaluators about largely invisible new security measures, especially those in Internet Explorer that affect Web applications. [...] Mainstream Web sites that employ unsigned ActiveX applets, downloads, pop-up windows, browser helper objects, and other code- or scripting-based functions may encounter difficulty with SP2 version IE 6.
Sigh...

Date: 2004-07-06 06:05 pm (UTC)
From: [identity profile] pavlos.livejournal.com
Work just mandated firefox :-)

Date: 2004-07-10 11:10 pm (UTC)
From: [identity profile] conwow.livejournal.com
The vulnerability which has been widely reported as effecting only Internet Explorer, whereby the browser doesn't restrict access to the shell: URI handler also effects a number of other products, including Firefox, Mozzila and Mozilla Thunderbird. See the official advisory from Mozilla here (http://www.mozilla.org/security/shell.html). The problem is an inherent security flaw that exists in later versions of Windows rather than a problem with the browser, the various patches that were released by Microsoft for Internet Explorer merely filtered sites from accessing this, rather than removing the flaw hence it was still exploitable even with the patch installed.

Profile

ciphergoth: (Default)
Paul Crowley

January 2025

S M T W T F S
   1234
5678 91011
12131415161718
19202122232425
262728293031 

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jan. 22nd, 2026 04:16 pm
Powered by Dreamwidth Studios