Users of IE7 should disable JS for the time being!

Hi malware fighters,

Users of IE7 should disable Javascript!

http://c22.statcounter.com/counter.php?sc_project=2343767&java=0&security=2d1f75fb&invisible=0
shows only four av scanners detect this malware

http://www.virustotal.com/de/analisis/596d88d57bc91d977f037f317eb9aa99

A second exploit for the zero-day security hole in Internet Explorer 7 has appeared,
that also makes Windows Vista SP1 bite the dust.
The vulnerability is mainly used throughout China
to steal password for online games,
but security experts fear the situation may soon worsen.

Some advise to prevent JavaScript to run inside IE7,
https://forums.symantec.com/syment/blog/article?blog.id=vulnerabilities_exploits&message.id=180#M180
Microsoft advises to install Data Execution Prevention (DEP) in the browser:
http://www.microsoft.com/technet/security/advisory/961051.mspx

HDMoore’s analysis of the malware can be found here:
http://www.breakingpointsystems.com/community/blog/patch-tuesdays-and-drive-by-sundays

So for the moment I use Fx with NoScript installed,

pol

I don’t know if IE7 is anything like IE6 in that you can’t just disable javascript, but you have to disable active scripting which includes more than just javascript.

Easier to just use firefox or opera ;D

Hi DavidR,

For the moment, and that is until this hole will be patched, and it is a tricky one, that is for sure, Microsoft’s own advise is to enable DEP in IE:

Local Administrators can control DEP/NX by running Internet Explorer as an Administrator. To enable DEP, perform the following steps:

  1. In Internet Explorer, click Tools, click Internet Options, and then click Advanced.
  2. Click Enable memory protection to help mitigate online attacks.

Impact of Workaround: Some browser extensions may not be compatible with DEP and may exit unexpectedly. If this occurs, you can disable the add-on, or revert the DEP setting using the Internet Control Panel. This is also accessible using the System Control panel,

pol

JRE crashes IE 7 if you enable DEP in IE 7 so this workaround isn’t very practicle. Using Protected Mode also helps to mitigate the attack as mentioned in the article polonus linked to above.

Hi, seems this isn’t available in IE 64 bit. ??? tim