IE exploits now seen worldwide!

Howdy bob3160,

I use that too, my friend, and I also posted in the national anthem query. You still have that Prussian old anthem there? And you still love Sauerkraut and Wurst? I do.Well, but to mention it - actually a decent browser war has a purpose, it makes us all more secure. Always look on the bright side of life, as I tell you,

Damian

Damien,
I’ve looked at the bright side of life and a lot of other subjects for many many years.
Here are just 2 examples:
http://forum.avast.com/index.php?topic=19766.msg166105#msg166105
http://forum.avast.com/index.php?topic=13246.0

Have a great day. :slight_smile:

Just for the record, Bob, I think this is complete bullshit.

I challenge you to find one post where I’ve gone beyond reporting the facts or making a reasonable criticism.

Bob is not the source of objectivity he pretends to be: he has always played down security problems with IE in the past.

He’s consistently stated that it doesn’t matter what browser you use- all have security issues- and if you stick to safe sites, you’ll be fine with any browser.

This advice flies in the face of major problems with IE like this one, where, as pointed out in previous threads comments, we have security web sites suggesting that people simply avoid IE, and reports of in the wild exploits appearing on hacked legitimate web sites.

Am I a Firefox Fanboy and Bob a source of illumination? I’ll leave that to others to judge, but I’d rather we avoid the childish labels.

EDIT: correction.

As I said in another thread:

In the same spirit ... let's skip characterizing other forum members as "anti-Microsoft". It is useless, it is counter-productive and it does nothing to forward a thread or build forum community.

However important anyone may consider themselves to these forums please remember that apart from the avast team contributors the only folks really indispensable in these forums are Tech and DavidR. For the rest of us we need to remember that personal attacks are forbidden. There are a some of us (yes even me) that need to mend our ways but I am far from alone … and if I have to I will ask the moderators for their guidance on further personal attacks.

Friends (if not that then let’s work harder to make it so) we are here to help the users of avast not to battle in front of them - or else, quite rightly, this sub forum will disappear too.

Agreed, We ALL need to work together, NOT fight over Which OS or browser is the best, Let Microsoft, Mozilla and Apple do that, That’s what they get paid to do.

Come on people, We’re ALL better than this.

Frank, you alanrf and bob have done a LOT to help people on these forum, And I’ve learned A lot from ALL of you.

To Frank, If I’ve said anything to disturb you, Please except my apology.

NOW, Can we get back to helping each other??

Nothing to apologise for, Marc. :slight_smile:

Glad to hear that friend. ;D

Howdy folks,

Let us start with helping each other then. In the case you run IE7 on XP SP3 the the recommended workaround to run IE if you have to use it, is described here:
http://blogs.technet.com/swi/archive/2008/12/12/Clarification-on-the-various-workarounds-from-the-recent-IE-advisory.aspx
I past here some advice that I got posted:

They (that is the workarounds) should be sufficient.

  • Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and Local intranet security zone
  • Disable XML Island Functionality

That done, I’ve decided to still follow the prudent advice I posted and stay off IE until this exploit is patched. Too many trusted sites require Active Scripting or ActiveX Controls to work properly. In the meantime I’ve disabled the Always-view-in-IE feature of IE View too.

I would like to add if you need to run IE for some reason, at least run it without full admin rights,

polonus

P.S. Info about a recent new infected Chinese website: http://securitylabs.websense.com/content/Alerts/3261.aspx

Bob is not the source of objectivity he pretends to be: he has always played down security problems with IE in the past.
I have ??? ???

All browsers are flawed. None of them are 100% perfect.
It’s up to the user to be prudent how they secure their own choice of a browser.

Right now I’m using SRWare Iron. ( My Own personal Choice ) You’ll have to choose your own. :slight_smile:

Yes, really. Once these little panics are over, you go back to saying,

In my opinion, all of these broswers are equaly secure providing the person using them only goes to safe sites.

http://forum.avast.com/index.php?topic=40370.msg338478#msg338478

and conveniently forget what a piss poor record “some” browsers have.

Check my posts in this thread- I’ve just reported the facts, not told anybody how crap IE is or to go and use another browser, despite the fact that the evidence just might justify such a statement.)

Plenty of other people have commented on IE security or recommended another browser.

I’d like to know how just posting the a story is “bashing the browser” or Microsoft, and why I get picked on to be insulted?

EDIT: Not even ‘the’ story- it was Polonus’s thread.

Hi FwF and bob3160 and all the others,

In such a way we will never learn a thing about browser security and what is very important in these malware ridden days about the very important topic called “in-browser security”.

What I wanted to start is a thread with which I could educate a user away from just blindly take things for granted, copy what is main consensus, and know just why they are clicking or aren’t clicking a link or using a particular piece of software.

Why it is important that the software is fully updated and patched.

While visiting here and elsewhere to study browser security somewhat more, I learned a lot on MozillaZine, while using and tweaking Flock and the code, and also learned a lot from ways that browser views should not be presented, we all remember the troll with the mythycal stroke that eventually was demasked by FwF, while he had almost gained guru status with the new users.

I was the man that warned people about the browser-shell adware of Browzar, that some thought was a revelation to hide your tracks at school. I talked here about ID tags, and about web bug finding extensions so you could kill them through adblocking.
And gradually my insight grew. I introduced the DrWeb browser plug-in here on the forum, asked for a Flock version and the developer came with a version that ran inside Flock, learned about admin rights from DavidR and why you better not use them while browsing. Just do impartial research and help each other, folks, present pro’s and con’s and we all benefit, but do it so your knowledge grows and you will get better security attitudes, because that is the bonus you gets, thanks avast…

polonus

Wow.

Polonus and FreeWheelinFrank.

You seem to be ready to sacrifice an Evangelist only because of your fanatical devotion to Mozilla?

Go post there.

This is Avast.

The statements that Bob3160 has profesionally provided are objective and valid.

But they don’t suit you, because your minds are both infested beyond help with Mozilla world-wide brainwashing tactics.

Hello Doomer,

If you read a topic “IE exploirs now seen worldwide” you cannot simplify the topic and say the man that posts such a thread is critical of IE and reports (I hope temporary) facts about this because “that suits him or his views”. In the thread and throughout the thread I tried to be very impartial.
Just told what I read online and at the Microsoft support pages and comments to that. This all that visitors and readers of the thread may benefit from what info it holds.
That I am a tester of Fx and Flock browsers and like the added security of the NoScript extension etc. there is just a sheer coincidence, and should not come in to the matter. I admit that sometimes I use the IE browser for downloading, I have to admit also while I do not use it much it is my default browser on Windows XP SP3 and Vista.
On the other hand it is easier to see what is going on with a browser like SRWare Iron, the privacy friendly clone of GoogleChromium, while the code there is open source, so everbody can look at it and help the developers and coders develop on.
Well I would not like to “sacrifice” my good friend bob3160, because thanks to him I have my avatar size correct and he was the first person that welcomed me here, and I consider bob3160 and also FwF longstanding and important forum friends. So do not read things into the discussion that are not there,

polonus

I don’t like where this thread is going …

@ doomer: Inspite of what you and a few others here think, i can assure you that Polonus and FWF are not FF fanboiz(if they are then so am i and everybody else that likes and uses FF) and their intentions are certainly not to make us all switch to FF but ONLY to educate/inform the rest of us of what is going on in the world of security. You can learn alot from both of them as i and many others have over the years. They’re great guys both of them. So is Bob3160 and i consider all 3 of them as friends and have nothing but respect for them.

Thanks doomer for comming to my defense but it really isn’t needed.
I have fairly broad shoulders. :slight_smile:
Believe it or not but a disagreement, when handled properly, is actually very constructive.
There is nothing wrong with a disagreement about a broad subject like browsers.
At the moment, FWF thinks I’m a Microsoft fanboy since I don’t bash them when there
is a problem with one of their products.
I don’t have a favorite. Right now I’m using SRWare Iron. Prior to that, I used FF next week,
it may be The World browser. (Really pretty nice but, based on IE and not safe right now)
I’ve also followed quite a bit of the advice posted on this forum by FWF and Polonus and Tech and DavidR and
darth_mikey and many others.
Tech once called us a “band of brothers” and even the best of brothers on occasion disagree.

At the moment, FWF thinks I'm a Microsoft fanboy since I don't bash them when there is a problem with one of their products.

Please don’t put words in my mouth.

Actually I objected to you accusing me of bashing IE and Microsoft for the heinous crime of posting one link to a story from the Washington Post (that well known den of Fanboyism) in Polonus’s thread.

You still haven’t justified that accusation.

I don’t think you’re a Microsoft fanboy, but I don’t think as doomer seems to that you are the arbiter of balance on this forum.

To IE an FF-users:

Just for the sake of completeness and balance: We must not forget the safe alternative Opera.

Said by an (Operafanboy ?) using IE7 to visit Windows Updates.

HL

But seriously: The ‘best’ browser isn’t invented (yet).

Microsoft Security Advisory (961051) Vulnerability in Internet Explorer Could Allow Remote Code Execution
At this point, there is only one safe way to use Internet Explorer:
http://mysharedfiles.no-ip.org/DropMyRights/DropMyRightsInstructions.html

For added protection, that same method is also recommended for any of the other browsers.

Hi bob3160,

That is the preferred way to be connected to the Internet. In most cases you only need full admin rights to change configuration, download and install certain software and updates. So I use a full admin account to do these things, and I have a SafeXP normal user account to do all the other things.
You know, bob3160, but an enormous number of people do not know there is anything else then “Windows as it comes out of the box” or to say it in a different way Windows “as by default”. And we know here that Windows “as by default” allows malware to do things on a computer we would not like it to do, and with limited rights we prevent this to quite an extent,

polonus

Click the picture to see the animation agree!

P.S. and to hlecter -Opera’s password manager chest is the best around:
http://www.info-svc.com/news/2008/12-12/