How to protect yourself from Internet Explorer’s latest zero-day vulnerability

Zero Day exploit / Password (Shutterstock mkabakov)

The most-used versions of Internet Explorer are vulnerable to a new zero-day exploit, but you can protect yourself until Microsoft issues a fix.

We know it sounds like a broken record: A new security vulnerability has been found in Microsoft Internet Explorer that can enable attackers to take over a computer, collect personal data, run any software they like, yada yada yada. However, this one comes with a bit of a twist: The vulnerability is being actively exploited in the wild, and was apparently produced by the same group of Chinese attackers who launched targeted attacks using the critical Java vulnerabilities Oracle patched last month. All it takes to take over a vulnerable system is visiting a maliciously-crafted Web site.

More bad news: The bug effects Internet Explorer 7, 8, and 9 on Windows XP, Windows Vista, and Windows 7, meaning millions of people are potentially vulnerable. Even more bad news: Microsoft has not yet issued a patch, and security companies (and even governments) are recommending users stop using Internet Explorer and switch to another browser — at least into the exploit is patched.

There is some good news: IE users can protect themselves in the meantime by installing Microsoft’s Enhanced Mitigation Experience Toolkit — but that may not be a slam dunk.

What’s the problem?

Internet Explorer 9

The exploit was first uncovered and publicized by Luxembourg-based security researcher Eric Romang, who found it on a server used by Chinese malware developers. The Metasploit team and Romang quickly verified the vulnerability and added it to their open source vulnerability testing framework. Normally security researchers quietly report vulnerabilities to appropriate companies and only release details when a patch becomes available. However, in this case the exploit was discovered out and around on the Internet, so going public seemed like the fastest way to help protect people.

There are indications this exploit was developed by the the same group that developed, the so-called “Nitro” attacks of 2011, which appear to have been industrial espionage efforts targeting defense and chemical companies. The new zero-day exploit seems to be along the same lines. AlienVault manager Jaime Blasco has uncovered evidence sites carrying the new IE vulnerability may be targeting defense contractors.

The attack itself can be placed in any Web page. It loads an Adobe Flash file that performs a “heap spray” (basically, seeding code throughout memory used by Internet Explorer) to load an iframe which, in turn, downloads the malware executable. This executable enables attackers to monitor remote computers and steal data. It’s important to note that while the current attack uses Adobe Flash, this particular vulnerability itself is not in Flash, but Internet Explorer.

The team that developed the zero-day exploit was apparently not very happy to be outed by Romang: The attack disappeared from the server where Romang found it over the weekend.

By Monday, Microsoft had issued a security advisory on the vulnerability.

Who’s affected?

security-breach-hack-hackers

Internet Explorer 7, 8, and 9 are running under Windows XP, Windows Vista, and Windows 7 are all vulnerable to the attack. Right now, the exploit appears to only be used to target specific industries — probably at the business end of a “spearphishing” campaign. Microsoft’s Director of Trustworthy Computing Yunsun Wee claims an “extremely limited number of people” have been impacted by the problem.

Nonetheless, there’s absolutely no telling how long this exploit has been used in the wild — it could easily pre-date things like the recent Java exploits. The number of potentially vulnerable users is gigantic: Security firm Rapid7 estimated as many as 41 percent of North American Internet users are vulnerable to the exploit. As with last month’s Java vulnerabilities, there’s always the possibility this exploit will make it into frameworks and toolkits used by a much wider group of malware authors and hackers. If that happens, the attack could suddenly be targeting millions of people.

What to do?

Internet Explorer Security Zone (medium high default)

Microsoft’s Yunsun Wee says a fix will be available from Microsoft “within the next few days.” Users will be able to patch Internet Explorer with a one-click installation, and Microsoft claims the patch won’t impact users’ Web browsing, or even require users reboot their computers.

In the meantime, Microsoft has recommended users install the Enhanced Mitigation Experience Toolkit (EMET), a collection of tools and utilities that adds security layers and defenses to older versions of Windows and hardens more recent versions of Windows against known exploits.

EMET is separate from Microsoft’s product-related security updates. The idea is to offer patches, lockdowns, and mitigation techniques that aren’t tied to any particular product on a schedule that also not tied to any particular product. EMET can’t really protect against new exploits, but can help protect Windows users against known exploits and variants on known exploits. It has to be separately downloaded, installed, and then manually configured to protect against this particular threat.

Microsoft also recommends Internet Explorer users set their Internet and local intranet security zone settings to “High” to prevent ActiveX and Active Scripting components from loading from sites in those zones. This will protect users against the attack, but it’s also pretty likely to impact Web usability. If sites have problems, users will have to add sites they trust to IE’s Trusted Sites zone to get them to work — and once a site gets added to that list, most users never remember to remove it again once a patch is available.

So what about another browser?

chrome-ie9-firefox-logos-together

Of course, another way to avoid this zero-day vulnerability is simply not to use Internet Explorer. It’s worth noting that none of the other mainstream Web browsers available for Windows — including Chrome, Firefox, Opera, and Safari — are vulnerable to this exploit. In fact, many security experts are recommending Internet Explorer users switch to a different browser until Microsoft issues a patch, and the German government’s Federal Office for Information Security (German) is saying the same thing.

Switching to another browser — even temporarily — might be a viable workaround for many users. It’s not as if Chrome, Firefox, Opera, or Safari are magically immune from zero-day bugs themselves, but at least they aren’t vulnerable to this particular problem that’s casting a shadow over Internet Explorer.

However, for many users, switching away from IE simply isn’t an option. Using Internet Explorer might be mandated by a school or IT department, and there are some sites and services that simply don’t function right (or at all) in anything but Internet Explorer.

Bottom line

Security exploits — especially in Internet Explorer — are nothing new; the best you can do to avoid them is simply to keep software up to date. Windows users should also consider a reputable antivirus and security package. While they can’t patch vulnerabilities in applications or operating systems, they can help protect vulnerable systems from known exploits.

The new zero-day vulnerability shows that criminals looking to exploit software flaws are becoming far more sophisticated — and they apparently have the resources (or at least the patience) to develop intricate attacks aimed at very narrow targets. It’s only a matter of time before some of those attacks make their way into widely-available malware toolkits and go from being quiet, isolated problems impacting an “extremely limited” number of people to problems that effect millions. Right now, we’re only finding out about these exploits because researchers stumble across them via a combination of skill and luck. There’s no telling how many exploits are out there on the Internet, right now, undiscovered.


Source : digitaltrends[dot]com

Samsung pokes fun at Apple devotees again in latest TV ad (for the Galaxy S3)

Recent reports suggested Samsung was filming another of its TV ads poking fun at Apple devotees. And here it is.....

A week after Apple boss Tim Cook stood on a stage in San Francisco to unveil the iPhone 5, along comes the latest in a series of Samsung ads poking fun at Apple devotees.

The ad follows a familiar routine – hordes of young people lining up outside a number of Apple-looking stores in various US cities, just as Apple fans are doing right now as they wait for the launch of the iPhone 5 on Friday.

“All I’m saying is they should have a priority line for people who’ve waited five times,” one guy says at the start of the 90-second ad.

While the iPhone is never referred to by name, many of its specs are mentioned. “You have to have an adapter to use the dock on the new one,” one guy in the line says rather forlornly. “Yeah, but they make the coolest adapters,” says another.

As with Samsung’s previous ads, owners of the company’s newest smartphone also make an appearance, causing confusion and curiosity among those waiting in line. In the latest ad, owners of Samsung’s flagship Galaxy S3 smartphone talk up their device, listing a good number of its features along the way.

The Korean electronics maker clearly believes the ads are effective in denting consumer enthusiasm for Apple’s iPhone, a view that research appeared to back up with regards to the launch of the iPhone 4S last year.

However, Samsung’s latest ad has some work to do if it’s to have any hope of killing the buzz surrounding the iPhone 5 – Apple said on its website on Monday that it took over two million orders for its new handset in the first 24 hours of availability, making it the fastest-selling iPhone ever.

You can check out Samsung’s new ad below.


Source : digitaltrends[dot]com

Do new colors and PlayStation Plus make up for the lack of a PS Vita price drop?

ps vita price drop

Sony announces new games, new colors, and PlayStation Plus for its handheld at TGS, but there's still no PS Vita price drop in sight.

Sony didn’t just announce a grossly overpriced new PlayStation 3 at its Tokyo Game Show event on Wednesday morning. It had a little bit of news to share about the PlayStation Vita as well. The game announcements were less notable than those at the Gamescom conference in 2012 unfortunately. Reason being, most of the games announced are targeted only at the Japanese market. There’s little likelihood that the big-breasted-ninja game Senran Kagura or Monster Hunter clone God Eater 2 will be making it to the US anytime soon.

PlayStation Plus for the PS Vita, on the other hand, will absolutely be a selling point for the struggling portable in the coming months. Sony already confirmed that PlayStation Plus would extend its reach to Vita at Gamescom but it was only at TGS that pricing and release info was made available. Vita gets PlayStation Plus in November for $18 per month or $50 per year, and that fee will net you discounts on myriad downloadable games and free access to others.

Sony also announced a couple of new Vita colors, namely a snappy red console and a nice blue one as well. These are only confirmed for Japan at the moment, but Sony never shied away from releasing new PSP colors with regularity. The US will still get access to the white PS Vita when it comes out bundled with Assassin’s Creed III: Liberation in October.

Sony already said in August that it didn’t plan on a PS Vita price drop before 2013, but it’s still disappointing to have TGS come and go without Sony attempting to incentivize a purchase of the handheld. The Vita’s a great gaming machine, with some quality games. Gravity Rush, Sound Shapes, LittleBigPlanet PS Vita, and others have made the Vita’s first year more memorable than PSP’s first three years on shelves combined. At $250, without one of Sony’s expensive proprietary 32GB memory cards, Sony just doesn’t have a machine to entire people yet. They’re spending on Kindle Fire, on the iPhone 5, on the iPod Touch, and even Nintendo 3DS before they are Vita. The only thing that Sony can do to lure them in is to either drop the price, or bundle both the PlayStation 3 and the PS Vita together at $350, positioning it as a Wii U competitor.


Source : digitaltrends[dot]com

Photive Natural Slim iPhone 5 Case for Only $10

So, assuming you put in your pre-order early enough, you should be getting your hands on the brand new Apple iPhone 5 a little later this week. You probably want to make sure that your precious new iPhone is properly protected, but that doesn’t mean you need to buy an expensive case. Sometimes, a cheaper $10 one will do.

Case in point is the Photive Natural Slim Fit Case for the iPhone 5. They say that it is a “guaranteed fit” for the new iPhone and it doesn’t add much in terms of bulk, so you still get that slender and sleek appearance that you desire. It’s pretty simple, with just a plain black housing, but I’d say the understated beauty is even more attractive. The lack of the two-toning on the back, though, might make people think you have that dinosaur of a device called the iPhone 4S.



Source : mobilemag[dot]com

UK spy agency launches contest in hunt for tomorrow’s cyber security experts

UK spy agency GCHQ has launched a special contest in the hope of uncovering the cyber security experts of tomorrow.

With governments and businesses facing a growing number of cyber attacks perpetrated by increasingly sophisticated criminals, such bodies are struggling to keep pace with the escalating threat.

The Government Communications Headquarters (GCHQ) – the UK’s central spy agency specializing in electronic intelligence gathering – is perhaps more worried than most, with many of its skilled tech wizards leaving for better paid jobs in the private sector.

In an attempt to shore up its defenses against hostile states and criminal gangs operating online, the spy service has launched a computer security competition open to all Brits aged 16 and over in the hope of discovering the cyber security experts of tomorrow.

The Balancing the Defence test puts contestants “in charge of managing the risk to a Government department’s computer network. You will analyse the network, looking for vulnerabilities that an attacker could exploit, and apply a range of defensive controls,” it says on the competition’s website.

“Some will be technical in nature, but others will be based in the security policies you establish. Your budget is limited and you will have to make tough decisions about which controls you can apply to get value for money and reduce the risk to your network.”

Registration for the competition ends September 26, with the test lasting five days from from October 1.

The designer of the test – a GCHQ employee known only as ‘Karl’ – told the Guardian that no computer system can ever be 100 percent protected.

“There is no such thing as a completely secure system – businesses will always need to balance where to spend a limited budget, to manage risks and provide opportunities,” he said.

Back in June, the head of the UK’s domestic security service, MI5, said he was shocked by the number of cyber attacks taking place against the country.

“The extent of what is going on is astonishing, with industrial-scale processes involving thousands of people lying behind both state-sponsored cyber espionage and organized cyber crime,” MI5 boss Jonathan Evans told said in a speech in London.

With that in mind, the British government will certainly be hoping GCHQ’s cyber security competition uncovers some bright sparks who can help build an effective system to defend against attacks, ensuring the protection of highly sensitive information in the process.

[via Reuters] [Image: Rafal Olechowski / Shutterstock]


Source : digitaltrends[dot]com

It's free
index