Zdnetasia.com Estimated Worth $178,365 USD. Daily Ad Revenue:$244 USD, Daily Views:81,445 Pages... - http://www.haplog.com/www.zdneta...
2 hours 52 minutes ago by Haplog on twitterZDNet is available in the following editions:
Third-party fix plugs a Microsoft browser hole that's increasingly being exploited in cyberattacks.
A group of security professionals has created a third-party fix for a recently discovered Internet Explorer flaw that's increasingly being used in cyberattacks.
The group, which calls itself the Zeroday Emergency Response Team, or ZERT, created the patch so IE users can protect themselves while Microsoft works on an official fix for the Web browser. The software maker has said it will release a security update for the issue on Oct. 10, its next Patch Tuesday.
"Certain members of the group feel that the risk associated with this vulnerability is so great that they can't wait for a patch. Some users might agree with that and apply this patch," ZERT spokesman Randy Abrams said Friday. Abrams is director of technical education at security company ESET and volunteers with ZERT.
The flaw lies in the way IE 6 handles certain graphics. Malicious software can be loaded, unbeknownst to the user, onto a vulnerable Windows PC when the user clicks on a malicious link on a Web site or an e-mail message. Word of the vulnerability came earlier this week, when the weakness already was being exploited in cyberattacks.
"Attacks have ramped up significantly in the past 24 hours," said Ken Dunham, director of the rapid response team at VeriSign's iDefense. In many cases, the attacks install spyware, adware and remote control software on victims' PCs.
In at least one case, cybercriminals broke into a Web hosting company and redirected 500 Internet domains to point to a malicious site that exploits this latest flaw, Dunham said. "So you're just surfing the Web, and all of a sudden, you are redirected to a malicious Web site," he said.
Attacks that exploit the flaw via e-mail likely will surface soon, he added.
While Microsoft is aware of the attacks, it said it does not recommend using the third-party fix. "As a best practice, customers should obtain security updates and guidance from the original software vendor," a Microsoft representative said in a statement.
This is the third time this year somebody has beaten Microsoft to the punch with a security fix. In January, an outside patch was created for a vulnerability in the way Windows renders Windows Meta File images, and in March, two security companies issued patches for a bug related to how IE handled certain tags in Web pages.
ZERT is made up of security professionals from around the world who volunteer their time. The ZERT patch, available for Windows 2000, Windows XP and Windows Server 2003, was created in 19 hours, primarily by three experts: Joe Stewart of Lurhq, Israeli reverse-engineering specialist Gil Dabah, and vulnerability researcher Michael Hale Ligh, Abrams said.
Risk of third-party fixes
A word of caution is warranted when it comes to third-party fixes, ZERT noted. "There is a risk associated with a third-party patch because it hasn't gone through the extensive testing that Microsoft puts its patches through," Abrams said. ZERT does provide the source code of its fix, allowing people to validate what it does.
On its Web site, ZERT stresses that its fix has no warranties. "While ZERT tests these patches, they are not official patches with vendor support and are provided as-is with no guarantee as to fitness for your particular environment. Use them at your own risk or wait for a vendor-supported patch," the group stated. The ZERT fix will be removed from the group's site once Microsoft has issued its update, the group said.
ZERT's patch may work well for some individual users or smaller organizations, iDefense's Dunham said. "Most small businesses are agile, but for larger organizations, applying a patch is a bigger hassle. A third-party patch introduces a wide variety of concerns and cost measures, and those can't be ignored," he said.
In addition to compatibility problems, third-party fixes could introduce security vulnerabilities, Dunham said. Microsoft provides several workarounds that do not require the third-party patch on its Web site. Dunham recommends using a workaround, but also said he expects Microsoft to rush out its patch before Oct. 10.
Zdnetasia.com Estimated Worth $178,365 USD. Daily Ad Revenue:$244 USD, Daily Views:81,445 Pages... - http://www.haplog.com/www.zdneta...
2 hours 52 minutes ago by Haplog on twitterrecently estimated website net worth of zdnetasia.com - http://www.haplog.com/www.zdneta...
2 hours 52 minutes ago by haplog on topsyWhen I create an event, I click on an approximate time during the day when I want the event to occur, then I click "edit event detail...
17 hours 28 minutes ago by bessellbrowne on Google Calendar gets 'smart' reschedulingipads break alott i had one it broke three times in the month i had it so i got rid of the damn thing id just go for the laptop Top Grade...
17 hours 30 minutes ago by bessellbrowne on Report: 'Hundreds of thousands' of iPad preordersThere are a number of websites that still require Internet Explorer to view and IE for Mac Stinks (it is really ies4osx which is the Wind...
17 hours 31 minutes ago by bessellbrowne on Microsoft: Only minor tweaks in Windows 7 SP1The receivers don't transmit back to the satellite. Unless there is a phone line attached to the receiver, they don't have any wa...
17 hours 34 minutes ago by bessellbrowne on Apple to join the geolocation craze?What to expect from open source Symbian http://is.gd/aPIGL
17 hours 49 minutes ago by rebelk0de on topsy"Lead Cognos BI Developer Insurance in New South Wales , Australian ..." http://bit.ly/ayy19L
18 hours 29 minutes ago by rhrcognos on topsywhatever little understanding I have we 'll only progress toward end of the world if we use HPCs to lenthen life of human being. Huma...
1 day 41 minutes ago by abhi32002@gmail.com on High computing promises elixir of lifeThanks for the knowledgeable article on SDDs. Allas...when all this reasearch will happen in Indian Universities. Hope the new bill on Fo...
1 day 53 minutes ago by abhi32002@gmail.com on APAC HPC users eye solid-state drivesIt was a good article. This brings a good opportunity for Indian IT firms to come up with new solutions in this field. HPC can become a b...
1 day 12 minutes ago by abhi32002@gmail.com on High computing most-wanted job in AsiaCOL KR DHARMADHIKARY(RETD) its very late to reply the link, but if it is still alive and looking for opportunity, i would like to know th...
1 day 9 minutes ago by deb021280 on Education takes off in rural India, helped by PCsIt was just a matter of time until google was marginalised anyway. I'm afraid this will be forgotten in China very quickly. Still, it...
1 day 14 minutes ago by robinsmith on Report: Google to leave China on April 10High performance computing (HPC) most-wanted job in Asia http://bit.ly/9vFC3i (via @zdnetasia) #singapore
1 day 26 minutes ago by mySingapore on twitterHe doesn't care if her shoes are of glass, All he wants to see is a huge rack and nice a*s. Sleeping beauty's not awoken by true ...
1 day 43 minutes ago by warlowdavies on One pair of 3D glasses to rule them allRT @zdnetasia: EMC COO, Pat Gelsinger, on bridging gaps in the organization and its cloud ambitions in Asia. (cont) http://tl.gd/i5jjd
1 day 14 minutes ago by mistymaitimoe on twitterEMC COO, Pat Gelsinger, on bridging gaps in the organization and its cloud ambitions in Asia. http://bit.ly/9etOZW
1 day 19 minutes ago by zdnetasia on twitterAsian SMBs need to pay more attention to disaster recovery planning http://bit.ly/bDet08 via @zdnetasia
1 day 34 minutes ago by asiapacsolution on twitterAsian SMBs need to pay more attention to disaster recovery planning http://bit.ly/bDet08
1 day 49 minutes ago by zdnetasia on twitter[TECH] URL Shorteners slow Web redirection. - http://bit.ly/bySnWK @zdnetasia
2 days 32 minutes ago by danielcktan on twitterURL shorteners are great but they can slow web redirection & you pray it would never go down http://bit.ly/bySnWK via @zdnetasia
2 days 212437 seconds ago by angahsin on twitterTemasek Holdings eyeing tech stocks, indicating optimistic outlook on IT sector. http://bit.ly/aM7VwU
2 days 29 minutes ago by zdnetasia on twitterURL shorteners slow Web redirection. http://bit.ly/bySnWK
2 days 29 minutes ago by zdnetasia on twitterChinese agencies cry foul over Google. http://bit.ly/by6rwV
2 days 35 minutes ago by zdnetasia on twitterPhilippine antipiracy drive focuses on enterprises. http://bit.ly/aWryDC
2 days 56 minutes ago by zdnetasia on twitterGartner: China to become world's fastest-growing enterprise software market. http://bit.ly/bqJTtb
2 days 58 minutes ago by zdnetasia on twitterall of sg's isps have been practising compulsory invisible proxy for all home subscribers at their backend since many years back alre...
2 days 53 minutes ago by melvinchia on Web filters mean bad news for businessit is not to good for china.
Proactol
RT @zdnetasia: HP touts new products and management and productivity tools to address business computing pain points. http://bit.ly/dudgA6
2 days 8 minutes ago by LiruChan on twitterFor those with a computer science background, or interested in the high performance computing scene: http://bit.ly/9vFC3i
2 days 33 minutes ago by zdnetasia on twitterIT security insiders rob casinos of $50K http://is.gd/aPIKR
3 days 9 minutes ago by rebelk0de on topsyVery good explanation of JMX
3 days 43 minutes ago by Babith B on Managing applications with JMXThe reaction to a report issued Tuesday by Flurry Analytics managed to completely overlook some interesting news--the Android-based Motorola Droid outsold the original iPhone over the same period of time following their respective launches--to focus instead on the sales numbers for the Nexus One.
3 days 47 minutes ago by lonemavericks on diggsAnother ZTE story....
3 days 48 minutes ago by Moderate Your Greed on Philippines opens bid for final 3G licenseWe at www.fifosys.com have also seen a growth in IT outsourcing and anticipate it as a growing field.
3 days 22 minutes ago by sarah Jane on Companies' outsourcing spend to increaseThe Desktop Virtualization Revolution is here!
Find our more with Citrix Simplicity is Power
2010 IT Salary & Skills Report
Find out the salary range of IT professionals. Join activeTechPros for free access to the report.
The Internet Show 2010, 21-22 Apr 2010, Singapore
FREE admission for visitors who pre-register online. Register Today!