ie6 - yet another serious exploit

From: Nirwana Nirwana (nirwanaaa_at_HOTMAIL.COM)
Date: 06/08/04

  • Next message: Russ: "Problems install with MS04-016 on XP"
    Date:         Mon, 7 Jun 2004 23:04:02 +0000
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    A short ie6 comment from someone at the coalface:
    Those of you that regularly read the c't security news
    (http://www.heise.de/security/, article
    http://www.heise.de/security/news/meldung/48016) may already have looked
    into this 'full disclosure' report at http://62.131.86.111/analysis.htm.

    This certainly adds new quality to the many existing vulnerabilities in ie6
    and confirms once again to me that ie6 simply cannot be trusted for internet
    use. It also gives (IMHO) the earlier statement by Russ that ie6 patching is
    more or less pointless a new meaning: it is a hopeless task and hence a
    waste of your time (patch it anyway for peace of mind if you wish).

    In our company everyone uses Mozilla as their default browser and we have
    banned the use of internet explorer - some explaining of the "why" and
    helping migrating the bookmarks has resulted in a strong support by all(!)
    employees for mozilla within a few weeks. We also got a lot of requests from
    our employees on advice how to get Mozilla working on their home PCs! Add a
    prefbar and an AddBlocker plugin and they never want to go back to ie!

    We use Win2k as our working horse and have also physically removed all
    instances of
    Outlook and Outlook Express (e.g. c't script
    http://www.heise.de/ct/ftp/result.xhtml?url=/ct/ftp/01/21/162/default.shtml&words=Outlook%20entfernen)
    and use Mozilla Mail with Enigmail in combination with a professional
    antivirus server/client solution. Add firewalls and system hardening and you
    have at least some basic defenses in place. This has been working very
    stable and reliable for us and saves a lot of time when it comes to patching
    ie6 and Outlook & Co.

    Cheers,
    Nir
    CSO

    _________________________________________________________________
    Add photos to your messages with MSN 8. Get 2 months FREE*.
    http://join.msn.com/?page=features/featuredemail

    -----
    NTBugtraq Editor's Note:

    Want to reply to the person who sent this message? This list is configured such that just hitting reply is going to result in the message coming to the list, not to the individual who sent the message. This was done to help reduce the number of Out of Office messages posters received. So if you want to send a reply just to the poster, you''ll have to copy their email address out of the message and place it in your TO: field.
    -----


  • Next message: Russ: "Problems install with MS04-016 on XP"

    Relevant Pages

    • Re: SSL und pdfs
      ... > meiner Seite mit dem IE6 keine pdfs herunterladen, mit dem Mozilla ... Das Phänomen lässt sich auf beliebigen Rechnern nachstellen. ...
      (microsoft.public.de.german.entwickler.dotnet.asp)
    • Re: CSS in ASP.NET
      ... design") in pre IE6 versions of IE on this specific instruction. ... when you use the!DOCTYPE declaration to ... measure are based on the font size of the parent object. ... then I should get the same size for IE and Mozilla? ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: [Mozilla+JavaScript] Shouldnt this bug be confirmed?
      ... > There is a bug in Mozilla about this issue, and I cannot figure why this ... > bug isn't yet, at least, CONFIRMED. ... Are you writing sound HTML/XHTML code? ... IE6 isn't worth using to test Web pages. ...
      (comp.lang.php)
    • Mozilla stinkt - Umstieg nicht anzuraten
      ... Mozilla hat ein fettes Problem mit Archiven und Mediadateien, ... beginnt, wird mir die Datei als *Text* im Browser angezeigt, super. ... Die Webmaster, die den Mime-Typ nicht richtig setzen und der IE6, ... Spart euch also den Ärger. ...
      (microsoft.public.de.german.inetexplorer.ie6)
    • SOMEONE PLEASE HELP!
      ... This was the original post on the IE7 Discussion Board. ... When I click the Outlook Express icon on my computer to open it, ... Add/Remove section so that I could get back to IE6. ... my husband downloaded the IE7 Beta on my computer. ...
      (microsoft.public.windows.inetexplorer.ie6.browser)