EditorsAbout the SiteComes vs. MicrosoftUsing This Web SiteSite ArchivesCredibility IndexOOXMLOpenDocumentPatentsNovellNews DigestSite NewsRSS

01.22.10

Microsoft Security Negligence Confirmed: Critical Internet Explorer Flaw Known and Ignored for 4 Months

Posted in Deception, Microsoft, Security, Windows at 4:12 pm by Dr. Roy Schestowitz

Summary: The newest facts show that Microsoft knowingly refused to fix flaws that led to tremendous damage; lies from Microsoft (about its competition) are refuted as well

IN MANY RECENT posts about Internet Explorer [1, 2, 3, 4, 5, 6, 7, 8], we have pointed out Microsoft’s pattern of negligence [1, 2, 3], which always passes costs (damages) to the public. Microsoft should probably be sued for it, rather than make money from it. Microsoft — like Goldman Sachs — is making a lot of money out of a crisis caused by its own risk-taking.

Here are some self-explanatory news headlines:

Microsoft lies to your face about browser security

Microsoft’s Head of Security and Privacy in the UK has told TechRadar that people who jump ship from Internet Explorer after the recent spate of bad headlines risk ending up on a less secure browser. With France and Germany both advising a move away from Internet Explorer, things are far from rosy for Microsoft’s browser [...yet] Microsoft’s UK security chief Cliff Evans insists that a non-Microsoft browser is the worse option. “The net effect of switching [from IE] is that you will end up on less secure browser,” insisted Evans. “The risk [over this specific] exploit is minimal compared to Firefox or other competing browsers… you will be opening yourself up to security issues.

Let’s fight FUD with facts…

Vulnerability Report: Mozilla Firefox 3.5.x
Unpatched: 0

Vulnerability Report: Google Chrome 3.x
Unpatched: 0

Vulnerability Report: Opera 10.x
Unpatched: 0

Vulnerability Report: Apple Safari 4.x
Unpatched: 0

Vulnerability Report: Microsoft Internet Explorer 6.x
Unpatched: 24
Most Critical Unpatched: Extremely critical

Vulnerability Report: Microsoft Internet Explorer 7.x
Unpatched: 11
Most Critical Unpatched: Extremely critical

Vulnerability Report: Microsoft Internet Explorer 8.x
Unpatched: 4
Most Critical Unpatched: Extremely critical

My recommendation if you use Windows: make sure the version of IE that’s installed (because you can’t uninstall it!) is the latest/least vulnerable (IE8) and then install at least one of the non-IE browsers listed (personally I always recommend Firefox :) and then use THAT. Of course, you could always switch to a Mac or Linux…

Microsoft patches IE, admits it knew of bug last August

As Microsoft patched the Internet Explorer (IE) vulnerability that was used to break into Google’s network, it also acknowledged that it had known of the bug since August 2009, when an Israeli security company reported the flaw.

MS knew of Aurora exploit four months before Google attacks

Microsoft first knew of the bug used in the infamous Operation Aurora IE exploits as long ago as August, four months before the vulnerability was used in exploits against Google and other hi-tech firms in December, it has emerged.

Redmond’s security gnomes finally got around to patching the exploit on Thursday. the hack attacks against Google et al targeted IE 6, a browser first released in 2001. Exploits involved tricking users of vulnerable browsers into visiting booby-trapped websites. These sites downloaded the Hydraq backdoor Trojan and other malicious components onto compromised PCs.

[...]

A quick search of Secunia’s database, via its PSI patching tool, reveals a problem with an unpatched ActiveX control that looks just as bad, for example.

Emergency IE patch goes live as exploits proliferate

Microsoft released an emergency security update for all versions of Internet Explorer on Thursday as attacks exploiting a critical vulnerability in the widely used browser spread to hundreds of websites.

[...]

While some of the sites hosting the attacks were free services that had been co-opted, others appeared to be domains of legitimate companies that had been compromised.

[...]

In an admission that’s sure to spark criticism, Microsoft said it learned of the critical bug more than three months ago.

[...]

The unscheduled bulletin fixes a memory corruption flaw in most versions of the widely used browser that allows attackers to execute malicious code simply by luring victims to a booby-trapped website. It fixes seven other privately reported vulnerabilities, some of which also made remote code execution possible, that Microsoft had been planning to issue next month during its next regularly scheduled patch release.

[...]

Systems compromised by the sites reported by Symantec were infected with a backdoor that collected registry settings and other system information and sent it to an email address that was under the control of attackers. That email address has since been disabled, Talbot said.

Widespread Attacks Exploit Newly Patched IE Bug

The first widespread attack to leverage a recently patched flaw in Microsoft’s Internet Explorer browser has surfaced.

Starting late Wednesday, researchers at antivirus vendor Symantec’s Security Response group began spotting dozens of Web sites that contain the Internet Explorer attack, which works reliably on the IE 6 browser, running on Windows XP. The attack installs a Trojan horse program that is able to bypass some security products and then give hackers access to the system, said Joshua Talbot, a security intelligence manager with Symantec.

Once it has infected a PC, the Trojan sends a notification e-mail to the attackers, using a U.S.-based, free e-mail service that Symantec declined to name.

Make the right browser update: Firefox 3.6

Neolithic Windows security hole alive and well in Windows 7

One of the reasons I’ve never liked Windows is that it was never made to deal with the security problems of working in a networked, multi-user world. As a direct result, Windows has been fundamentally insecure for more than a decade. Even so, I was surprised to find that there’s a 17-year old security hole that’s been in Windows since NT and it’s still present today in Windows 7.

Wow. Even I’m shocked by this latest example of just how rotten Windows security is. It just reminds me again though that while Microsoft keeps adding features and attempting to patch its way out of security problems to Windows, Windows’ foundation is built on sand and not on the stone of good, solid design.

[...]

Be that as it may, the code’s still in there. An attacker can trigger the vulnerability through a variety of means. The end-result is, surprise, another Windows machine that’s totally owned by the attacker. Once in charge, they can vacuum down your files, install malware, and all the other usual tricks.

Vista 7 was never secure to begin with. See the examples below.

  1. Cybercrime Rises and Vista 7 is Already Open to Hijackers
  2. Vista 7: Broken Apart Before Arrival
  3. Department of Homeland Security ‘Poisoned’ by Microsoft; Vista 7 is Open to Hijackers Again
  4. Vista 7 Security “Cannot be Fixed. It’s a Design Problem.”
  5. Why Vista 7 Could be the Least Secure Operating System Ever
  6. Journalists Suggest Banning Windows, Maybe Suing Microsoft Over DDoS Attacks
  7. Vista 7 Vulnerable to Latest “Critical” Flaws
  8. Vista 7 Seemingly Affected by Several More “Critical” Flaws This Month
  9. Reason #1 to Avoid Vista 7: Insecurity
  10. Vista 7 Left Hijackable Again (Almost a Monthly Recurrence)
Share this post: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Reddit
  • co.mments
  • DZone
  • email
  • Google Bookmarks
  • LinkedIn
  • NewsVine
  • Print
  • Technorati
  • TwitThis
  • Facebook

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

A Single Comment

  1. uberVU - social comments said,

    January 22, 2010 at 9:26 pm

    Social comments and analytics for this post…

    This post was mentioned on Twitter by schestowitz: Critical Internet Explorer Flaw Known and Ignored for 4 Months http://boycottnovell.com/2010/01/22/refusing-to-fix-ie-flaws/

What Else is New


  1. The 'Offenses' of EPO Staff Representatives Boil Down to Truth-Telling

    Dutch television examined the documents of the mock 'trials' against SUEPO leaders and concluded that whistle-blowing (i.e. exposing abuses by EPO management), not misconduct, is the reason for overzealous dismissals



  2. Rumours About Dismissal of Benoît Battistelli and New Letter From Union Syndicale Federale Blasting Battistelli's Behaviour

    hings have been heating up since the dismissal of staff representatives at the European Patent Office (EPO) and some even spread rumours about withdrawal/dismissal of the EPO's President



  3. VirnetX Case Against Apple Shows Not the Problem With Patent Trolls But With Software Patents

    What the media really ought to be talking about after the high-profile VirnetX case, rather than obsess about the status of Apple or patent trolls in the Eastern District of Texas



  4. Diápositivas de Nueva Charla Explican la Connección Entre la Corte De Patentes Unitarias (UPC) y Patentes de Software

    Benjamín Henrion habló el pasado Domingo acerca de las patentes de software europeas -una presentación que habla de la Corte Unitaria de Patentes, por la que la OEP aboga sin cesar y que es lo que significa para las patentes de software.



  5. Las Políticas de Microsoft Alienan Incluso a los Hinchas Más Acérrimos de Microsoft, Incluyendo Pro-Microsoft Web Sites

    El agresivo comportamiento de Microsoft y su BAJA CALIDAD DE PRODUCTOS dejan algunos de sus últimos restos de ´hinchas´ descorazonados y molestos.



  6. Links 6/2/2016: CoreOS Rocket 1.0, Scientific Linux 7.2

    Links for the day



  7. Maybe It's Time for Class Action Lawsuits Against Microsoft for Forced Vista 10 'Upgrades', Which Were Definitely No Accident

    The sheer arrogance of Microsoft, which silently changes the operating system on people's computers (without their consent), makes lawsuits imperative, not just a possibility



  8. Readers' Article: A Strange Conspiracy of Silence in the German Media (Part II)

    Željko Topić's allegedly dark background, which includes a suicide, a retreat of potential witnesses, German funds in Topić's private bank account and several more interesting bits



  9. Links 5/2/2016: Wine 1.9.3, Slackware 14.2 Beta 2

    Links for the day



  10. Links 4/2/2016: Red Hat Upgraded, Ubuntu Tablet

    Links for the day



  11. The Siege Continues: Patent Lawyers Want More Patents, Including Software Patents, In Spite of Alice

    Lawyers who make money from patent disputes make rather apparent their aspirations, which include patent saturation even in domains that are patents-exempt



  12. European Patent Office Pretends It's Business as Usual and Prepares New Vanity Pieces

    The PR strategy of the EPO, whose destructive patent strategy continues unabated (for now), latches onto Colombia and strives to manufacture mythology wherein the public, patent examiners and patent applicants are all very happy with the EPO



  13. The 'International' Trade Commission Imposes/Reinforces Software Patents to Establish Another Embargo

    The International [sic] Trade Commission is meddling in competition and allowing a US giant, Cisco in this case, to potentially block rivals (no imports from abroad) using software patents



  14. Readers' Article: A Strange Conspiracy of Silence in the German Media (Part I)

    The views of some of our readers regarding reluctance in the German media to challenge the EPO's violations of German law, probably because Germany benefits from being a host nation of the EPO



  15. Benoît Battistelli's EPO: From Show Trials and Mock Trials to a Self-Aggrandising Propaganda Event Later Today in Rijswijk

    A headsup from a reader regarding today's highly misleading event in Rijswijk (e.g. to mislead the media or seed positive media coverage in the Netherlands) and how it was set up



  16. Caricature of the Day: EPO President

    New caricature about Benoît Battistelli, his bodyguards, and the assault on free speech at the European Patent Office



  17. Company Known as European Patent Office Provides Tips on How to Patent Software in Europe

    The European Patent Office (EPO) uses its attendance at CeBIT, which is a corporate expo, to promote software patents in spite of the European Patent Convention (EPC)



  18. Links 3/2/2016: Dell GNU/Linux Laptop, Wine 1.8.1

    Links for the day



  19. The Most Detailed Explanation (Yet) of What's Wrong With the EPO

    The EPO's insistence that it remains above the law is not only coming under fire by the media but is also being challenged based on people who are familiar with the applicability of law to international organisations



  20. Angry Trolls: Rovi (of Angry Birds Fame) Helps Microsoft's Largest Anti-Linux Patent Troll, Intellectual Ventures (Corrected)

    nce known as a game maker and later made notorious for mass surveillance on gamers, Rovi now liaises with the world's largest patent troll



  21. Patent Invalidation Statistics and Cost of Patent Litigation (Even If Bogus) Show That Patent Scope and Examination Standards a Problem in Europe, Not Just the US

    Far too many bogus patents (patents that should not be granted in the first place) and spurious patent lawsuits that end up in favour of the defendant serve to show the external cost (or externality) when it comes to low-quality patent systems that strive to grant a lot of patents irrespective of merit



  22. Es Oficial: Por Medio de Entrismo, Microsoft Ha Convertido a la Pro-Linux Nokia en un Parásito de Patentes Anti-Linux

    Microsoft ha convertido a Nokia en un troll de patentes que ahora ataca a Linux y Android.



  23. Richard Stallman: Patentes Europeas de Software Regresan con la Corte Unitaria de Patentes (UPC)

    Debates acerca de la UPC estan siendo peleados por profesionales de software (entidades prácticantes) y elementos PARÁSITICOS como los abogados de patentes.



  24. SUEPO (EPO Staff Union) Appears to Have Launched a New and Improved Web Site After Attempts to Crush ('Decapitate') SUEPO

    SUEPO, the largest staff union of the European Patent Office, shows signs of strength rather than signs of weakness amidst attacks on the staff and a lot of media coverage, political interventions, and much more



  25. Links 2/2/2016: Chimpbox Quad Core, UNICEF Supports FOSS

    Links for the day



  26. Münchner Merkur Explains That EPO Staff is Defecting to SUEPO, Even The Council Distrusts Battistelli Now

    Press report from Munich, highlighting the crisis of leadership at the EPO, where the President is increasingly viewed as a villain



  27. Microsoft's Policies Alienate Even Microsoft's Biggest Fans, Including Pro-Microsoft Web Sites

    Microsoft's aggressive behaviour and low-quality products leave even some of its last remaining 'fans' disheartened and upset



  28. Slides of New Talk Which Explains the Connection Between the Unitary Patent (UPC) and Software Patents

    Benjamin Henrion's Sunday talk about European software patents -- a presentation which speaks of the Unitary Patent Court that the EPO lobbies for and what it means to software patents



  29. UEFI is Bricking PCs, Yet Again

    A few remarks about a new defect which is starting to attract media attention this morning, serving to highlight the lesser-discussed dangers of UEFI/EFI



  30. Under Battistelli's Regime the European Patent Office is Rapidly Rotting

    Technical problems, patent maximalism (in a desperate effort to artificially elevate patent-related figures) and other serious issues observed inside the European Patent Office (EPO)


CoPilotCo

RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

CoPilotCo

Recent Posts