Hackers wield newest IE exploit in drive-by attacks
French, German governments urge users to dump IE until Microsoft produces patch
Computerworld - Hackers are attacking consumers with an exploit of Internet Explorer (IE) that was allegedly used last month by the Chinese to break into Google's corporate network, a security company said Monday.
That news came on the heels of warnings by the information security agencies of the French and German governments, which recommended that IE users switch to an alternate browser, such as Firefox, Chrome, Safari or Opera, until Microsoft fixes the flaw.
In a Monday alert Websense said it identified "limited public use" of the unpatched IE vulnerability in drive-by attacks against users who strayed onto malicious Web sites. The site Websense cited in its warned has since been yanked from its hosting server.
According to Websense, the attack code it spotted is the same as the exploit that went public last week. That code was quickly turned into an exploit module for Metasploit, the open-source penetration testing framework, by HD Moore, the creator of Metasploit and chief security officer for security company Rapid7.
Websense also said its researchers were working with Microsoft's to identify sites serving up the exploit.
On Sunday, however, Microsoft continued to downplay the threat. In a post to the Microsoft Security Research Center (MSRC) blog, George Stathakopoulos, general manager of the Trustworthy Computing Security group, repeated earlier claims by the company that it had only seen a "very limited number of targeted attacks against a small subset of corporations."
Stathakopoulos stressed that the only attacks detected thus far have been against the eight-year-old IE6. That version of Microsoft's browser lacks security measures, including DEP (data execution prevention), that are available in IE7 and IE8. For that reason, Stathakopoulos urged users of IE6 or IE7 -- the latter is potentially vulnerable to attack when run on Windows XP -- to upgrade to IE8.
However, some security organizations don't believe that is enough, and have instead recommended that users switch to another browser until Microsoft issues a patch. Both the German and French government computer security agencies have urged IE users to run a different browser.
Last Friday, Germany's Federal Office for Information Security, known by its German initials of BSI, and France's CERTA each issued advisories about the IE vulnerability.
Both BIS and CERTA called for users to ditch IE. "Pending a patch from the publisher, CERT recommends using an alternative browser," a translation of the French advisory stated.
A spokesman for Opera Software claimed that the download rate in Germany for its browser doubled over the weekend, and attributed the jump to the BIS warning.
Although U.S. researchers did not go so far as to suggest abandoning IE, some said the risk to IE users was high. "Internet Explorer users currently face a real and present danger due to the public disclosure of the vulnerability and release of attack code, increasing the possibility of widespread attacks," said George Kurtz, chief technology officer of McAfee, in a blog update Sunday.
Web giants attacked
- White House orders security review in wake of WikiLeaks disclosure
- Leaked U.S. document links China to Google attack
- Update: Researchers track cyber-espionage ring to China
- Google, China now playing cat and mouse?
- McAfee: 'Amateur' malware not used in Google attacks
- Military warns of 'increasingly active' cyber-threat from China
- China: Google 'totally wrong' to stop censoring
- Update: Google stops censoring in China
- Google's China ad partners wait in 'incomparable pain'
- Google may soon leave China, reports say
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Inquiry Spotlight: Consumer-Facing Identity The challenges of consumer-facing identity management, access management, and authentication differ in ways subtle and dramatic from those of the employee-facing variety.
- IDC Security Infographic From the Era Before security to this current era of empowerment this infographic from Blue coat provides a timeline navigates the rise of...
- Key Drivers: Why CIOs Believe Empowered Users Set the Agenda for Enterprise Security Several years ago, a transformation in IT began to take place; a transformation from an IT-centric view of technology to a business-centric view...
- Security Empowers Business Every magazine article, presentation or blog about the topic seems to start the same way: trying to scare the living daylights out of...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts
