Partner With Us
























Microsoft Patches IE, But Security Issues Remain

As usual, the bad guys are ahead in the tug-of-war over security.

December 17, 2008
By Richard Adhikari: More stories by this author:

Page 2 of 2

Attacks on the browser are expected to increase, with the browser increasingly being considered an application platform, security experts say. Mozilla's Firefox, for example, was ranked as the most vulnerable application by whitelisting vendor Bit9, although Mozilla has since issued a set of ten patches to its Firefox browser.

Experts disagree on how to prevent attacks on browsers in the future.

Microsoft should strip down IE to only the features users need, Wolfgang Kandek, chief technology officer at Qualys, told InternetNews.com. "Why does that browser, which is tightly integrated into Windows, have a very powerful library when users only need a subset of those functionalities?" he asked. "When a library offers way too many features, that opens the door for exploits."

It's all about Web 2.0

But McAfee's Marcus said stripping down IE is not the answer. "Users expect rich dynamic content in this day and age - streaming audio and video - and the browser simply reflects what they're looking for," he said. "You can't stop car theft or bank robberies, you manage the risk and you have to manage the risk of browser attacks in the same way, with layers of defense, knowing exactly what the risks of your assets are and defending them properly."

Marcus said it is difficult to pin down the exact number of infected sites because malware authors are using IFrame attacks.

The situation will only get worse over the next few weeks, Derek Manky, Fortinet's project manager, cyber security and threat research, told InternetNews.com.

"In October Microsoft issued an out of band patch for a vulnerability in the server service that was very high profile, but that flaw is still being exploited," he explained. For two to three weeks after that patch was issued malware activity was low, and now the activity has increased, Manky said.

"I expect to see the same with this IE exploit," Manky said. "In other words, the worst is yet to come."

Go to page: Prev  1  2  

TAGS: Microsoft, Internet Explorer, malware, security, browser




Web Content Archives | 7 Day InternetNews Summary | Contact Richard Adhikari | Back to top

Add internetnews.com
to your browser search box.

IE 7 | Firefox 2.0 | Firefox 1.5.x
Receive news
via our XML/RSS:
feed



More InternetNews.com


Hardware Software Mobility Web Content
Search Government Developer Business
Storage E-Commerce Networking Security



internet.commediabistro.comJusttechjobs.comGraphics.com

Search:

WebMediaBrands Corporate Info

Legal Notices, Licensing, Reprints, Permissions, Privacy Policy.
Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs