Avoid using IE if possible: AusCERT
Summary: Australia's Computer Emergency Response Team (AusCERT) has recommended organisations "consider using a web browser other than Internet Explorer until a patch becomes available" — an option that many large firms cannot seriously consider.
Australia's Computer Emergency Response Team (AusCERT) has recommended organisations "consider using a web browser other than Internet Explorer until a patch becomes available" — an option that many large firms cannot seriously consider.
"We needed a patch yesterday"
Graham Ingram, GM AusCERT
(Credit: AusCERT)
The zero-day flaw first reported last Thursday, which Microsoft later admitted affected all versions of Internet Explorer has prompted AusCERT to advise Australian organisations to "consider" using an alternative browser, which could include Opera, Mozilla Firefox, Google Chrome or Safari.
"What we've said is quite specific in our advisory — we've said that users should consider using an alternative browser — if that is possible," AusCERT's general manager Graham Ingram told ZDNet.com.au today.
AusCERT was cautious in its advice to use an alternative browser because it was aware many large organisations' desktops were "locked down". That is, configured to only allow approved applications to run, which in many cases means Internet Explorer is the only web browser option.
"There are a lot of companies that lock down [their computer] environment," said Ingram.
However, the reason that AusCERT went ahead with the advice was due to the importance of the web browser in modern desktops.
"There are a number of ways to mitigate to this, but the browser is one of the most fundamental pieces of software on the modern workstation," said Ingram.
"Having an unpatched browser is a massive problem. A zero-day unpatched IE is something that is not trivial and we needed a patch yesterday," Ingram stressed.
Other possible strategies included the drastic measure of turning off all web browsing, or creating a whitelist of websites that administrators considered safe from attacks that use specific exploit. Organisations should also update their antivirus, he said.
"But with the rise of legitimate sites being compromised there's no assurance that even safe sites haven't been compromised," he said.
Microsoft admits it has detected several hundred exploits for this vulnerability, however, the sites taking advantage of the flaw appear to be hosted on Chinese domains.
Microsoft yesterday did not know when a patch would be released. The next Patch Tuesday is scheduled for 13 January.
"IE is so widely spread and has so many platforms within it, developing a patch would be a Herculean task," Ingram added.
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.
Talkback
When did this get reported in main news?
IE has never been good anyway
For internet user, IE is slow, heavy, ugly, unreliable and now "security issue"
Internet Exploder hits again
If organisations would care about their security, they would upgrade users to a decent browser already - whether it be Firefox, Opera, Safari, Chrome, [insert any other non-IE browsers].
Don't turn it off
In the meanwhile, why not try another browser, Firefox, Opera and Safari are excellent products.
get a grip
Nothing like a good media beat up.
timing for reality check
http://www.bit9.com/news-events/press-release-details.php?id=102
Guess what fan boys:
-Firefox #1
-Safari #5
Explain why you would want to swap ?
Maybe this is one of the reasons people use IE because it does not make the list.
@ Get a grip!
For what ever reason, the situation does exist!
Users just do not have the technical expertise or don't even see the news reports. Not everyone gets ZDNet or sees the CERT reports.
Any other browser would be better than IE, simply because they are not targeted to the same extent. Users would have a much better experience with any other browser.
IE is slow, clunky & riddled with security problems. M$ can patch till the cows come home & it wont make one iota of difference.
Web designers need to stop catering to the M$ monopoly. The IE browser doesn't even conform to the International specs!
Please take your dodgy advice & shove it Mr Anonymous.
timing for reality check - MARKED AS SPAM BY AKISMET
The list, only includes apps that (and i quote) -
• Relies on the end user, rather than a central IT administrator, to manually patch or upgrade the software to eliminate the vulnerability, if such a patch exists.
• The application cannot be automatically and centrally updated via free Enterprise tools such as Microsoft SMS & WSUS.
The second criteria basically rules out any M$ apps, which CAN be updated, but generally aren't by any large organisations until they've undergone internal testing.
The exploit is real and in the field, any responsible IT professional needs to deal with it as soon as possible - until M$ release a patch, removing Local Admin access appears to be the only reasonable mitigation plan.
validity/incentive of press releases.
bit9's claim to fame:
"Now at over 6 billion records, the Bit9 Global Software Registry is growing at a rate of up to 20 million files each day"
******************
Before these rascals surfaced-- Queensland University commenced cyber-crime monitoring,along with Interpol, and the FBI--stated that NONE of these security propositions were technically correct:
ie you pay for a service that protects you from viruses that have not been EVEN created--is too alice in wonderland.
What these sods/ organisations/botcoms/banksand certain universities,as well as the system manufacturers failed to notify is that Microsoft products--which bit9 claim is lockdownable--instead--AS A FUNCTION OF OPERATION-- leave a galaxy of LISTENING PORTS.
This has been FBI alerted since 2001.
AUtomatic UPDATES--is exactly the same regards procedure and vunerability.
ANY FORM that employs Javascript--also allows third-party ACCESS.
The DOTCOM ideal of companies selling fresh air--seems REALLY where we might expect such persons as anonymous to be--rather than the more preferred COURTS OFLAW regards
social fragrance.
Internet Exploder hits again
I cant believe how everyone always bags Microsoft about its products. Before bagging them learn how to write code yourself, put an application out there and see how long it takes for someone to find a vulnerability.
get a grip
And to everyone else Don't Believe the Hype
@ Get a grip!
Get A Grip
Comedy Gold Auscert!
firefox too have drawbacks!!!
So Liam Step up
Security update for Mozilla Firefox web browser and SeaMonkey application suite. - SSO-AD2008-026
This is the services run by AusCERT for DBCDE.
Hey Mr Ingram where is your advice on swapping from firefox.
Where is the hype from everyone on lets not use Firefox ???
Or is this different because it is not Microsoft.
This is just a media beat all browser have bugs.
Com on ZDNET run a story on this new exploit
Patch availability
Internet Exploder.
24x7, for years at a time. Public-access systems. And, with zero known bugs at the end of a 7-year period of operation.
But OTOH, we didn't build code that was vulnerable left, right & center to buffer overruns. Didn't build toy C++, using the vastly flawed coding techniques, shown by MS in *EVERY SINGLE F*%#'N MSDN EXAMPLE*.
Now the patch-counts between browsers, are misleading as a basis for comparison. This is because MS perform 'bundling' and conceal a far higher number of vulnerabilities, in every fix they report.
My professional assessment, last performed 3 or 4 months ago, was that virus attacks are almost irrelevant these days: browser attacks & drive-bys are now the major threat vector.
Where currently many of these are nuisance-grade or advertising, with perhaps 3% malicious -- I expect an ongoing & rapid rampup, to 70% malicious or so, within 4 years.
(Keystroke/ password loggers, banking & account attacks, personal data/ corporate secret harvesting, access obtained then passed to humans for further exploitation.)
My assessment is that IE, is & will continue to be far less secure than available alternative browsers.
By virtue of both 1) inferior engineering & quality focus and 2) mass-market target.
IE was engineered to "bring the Web into the desktop". Remember ActiveX, Active Desktop, etc?
These original design "ideas" represent the exact opposite of security consciousness. Right from the start, they got it wrong.