« PDF: Pretty Dangerous File
When other people’s (lack of) security makes you insecure »

IE 0 day and general browser security

January 18th, 2010

There have been a lot of talks about the latest 0 day vulnerability affecting Internet Explorer.

According to this article from the BBC, the French and German governments have urged their people to find an alternative to Internet Explorer to keep their computers secure.

The fact of the matter is whether or not you use Internet Explorer, you can still be at risk. Telling people to use a different browser is a way too simplistic measure. It may protect you from this vulnerability but there are many more that apply to all browsers.

A more sensible approach would be to inform people about the risks and if possible provide a temporary solution to mitigate the attack. It may be as simple as tuning off a feature or enabling another one.

People should also think of security as layers. If Internet Explorer fails, most of the time something else will prevail, such as a good AV product.

Jerome Segura

    This entry was posted on Monday, January 18th, 2010 at 11:43 am and is filed under Exploits. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    1.      by
    2.      by
    • (0) comments
    • |
    • Add your comments




RSS feed to this site
Jerome Segura is a Security Researcher at ParetoLogic.

Twitter

 

Malicious URLs

ParetoLogic, a Microsoft Certified Partner

 

 

Links

  • Malicious URLs
  • Phishing Emails
  • Free PDF Scanner
  • About
  • MalwareDiaries in the press
  • Contact Us



Archives

  • September 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (3)
  • Banker Trojans (4)
  • Botnets (9)
  • Conferences (7)
  • DDos (2)
  • Debates (2)
  • Exploits (68)
  • Fake codecs (48)
  • Gaming (1)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (3)
  • Mac security (15)
  • Malware Trends (71)
  • P2P (1)
  • Phishing (47)
  • Podcast (1)
  • ransomware (7)
  • Research (68)
  • Rogue software (58)
  • Rootkits (2)
  • scams (13)
  • Social Networking (7)
  • Spam (4)
  • Uncategorized (122)
  • Wireless Security (2)
  • world map (1)



 
 
 
Microsoft is a registered trademark of Microsoft Corporation in the United States and/or other countries.

© 2010 ParetoLogic Inc.