home contact keylogger.org add keylogger.org to favorites set keylogger.org as homepage Google Translate from English into Chinese (Simplified) Google Translate from English into French Google Translate from English into German Google Translate from English into Italian Google Translate from English into Japanese Google Translate from English into Portuguese Google Translate from English into Russian Google Translate from English into Spanish  Anti-Keylogger.org
Monitoring Software
Keylogger home Keylogger testing policy Press-releases Keylogger developers Keylogger articles Links Sponsorship & services Keylogger forum
Search for software: Powered by RegNow
PC Activity Monitor Pro (PC Acme Pro)
Current section
Site News
DISCLAIMER: Logging other people's keystrokes or breaking into other people's computer without their permission can be considered illegal by the courts of many countries. The monitoring software reviewed here is ONLY for authorized system administrators and/or owners of computers. We assume no liability and are not responsible for any misuse or damage caused by the keylogging software. The end user of this software is obliged to obey all applicable local, state, federal and other laws in his country of residence.

July 08th, 2009

Microsoft may have known about critical IE bug for months

The vulnerability that sent Microsoft scrambling yesterday and is being used by hackers now to attack Internet Explorer (IE) users may have been reported 18 months ago or more.

In the security advisory it issued yesterday, Microsoft credited a pair of researchers -- Ryan Smith and Alex Wheeler -- with reporting the bug. Smith and Wheeler once worked together at IBM's ISS X-Force, although Wheeler now is at Texas-based 3Com's TippingPoint DVLabs.

Wheeler confirmed that he and Smith uncovered the vulnerability, but he gave most of the credit to Smith. Wheeler declined, however, to say when the bug was reported to Microsoft. "I don't feel comfortable talking about that," he said, citing a non-disclosure agreement related to the vulnerability that he signed at the time. Instead, he steered questions to his former employer, ISS X-Force.

"But we worked on it prior to my time with TippingPoint," Wheeler acknowledged. Wheeler, who is the manager of DVLabs, started at TippingPoint in January 2008.

The CVE (Common Vulnerabilities and Exposures) number for the vulnerability -- CVE-2008-0015 -- points to a possible early 2008 reporting date. According to the database, the CVE number was reserved on Dec. 13, 2007.

ISS X-Force was not immediately able today to confirm a reporting date for the vulnerability, but the security firm did note in its own advisory, also published Monday, that hackers have been exploiting the bug since at least June 9, 2009, nearly a month ago.

In fact, X-Force listed two separate vulnerabilities in its advisory, saying that the flawed Microsoft Video Controller ActiveX Library, or the "msvidctl.dll" file, not only contained the buffer overflow bug attributed to Smith and Wheeler, but also harbored a memory corruption vulnerability discovered by X-Force researcher Robert Freeman.

Microsoft did not respond to questions about when it was informed of the vulnerability, and if it was in late 2007 or 2008, why it had not patched the problem.

No matter when it was reported, the bug is serious, Wheeler said today. "This particular vulnerability is relatively easy to exploit in a reliable way, if that makes sense," he said. "Although it does require setting up malicious hosting servers to serve the exploit ... you have to go to a [malicious] Web page to be compromised."

Attack code hasn't been posted widely, Wheeler added, but it won't be hard for other hackers to duplicate what's already in the wild. "It will be relatively simple to do that," he said, "compared to what they have to choose from at the moment."

Yesterday, Microsoft not only confirmed ongoing attacks against IE6 and IE7 users running Windows XP, but also offered an automated tool that sets 45 different "kill bits" in the ActiveX control, effectively disabling it and rendering attacks moot.

But Wheeler suggested another option: switch browsers. "Unless they're specially configured, other browsers will face substantially lower risk," said Wheeler. Browsers such as Mozilla's Firefox, Google's Chrome and Apple's Safari don't rely on ActiveX technology to drive add-ons, as does IE.

"Any client-side vulnerability is serious," said Wheeler, "but of the range, this one is in the more serious range."

Microsoft has promised to patch Windows and/or IE, but has not committed to a delivery date. Its next regularly-scheduled security updates will be released a week from today, on July 14.


Source: ComputerWorld




All news for September 18th, 2009:
20:13Microsoft Internet Explorer SSL security hole lingers
20:11Conservatives call for DNA databases to be reduced
20:09McAfee warns of bogus security suite
20:08Security market remains buoyant in choppy waters
20:07The good and bad of government in the cloud
20:05Vista, Windows 7 Are More Secure than Snow Leopard
20:04Will Google's Buy of reCAPTCHA Hurt Internet Security?
20:01HHS guts health-care breach notification law, groups warn
20:00Man gets 15 months for E-Trade skimming scam
19:59Sophisticated botnet causing a surge in click fraud
19:59Microsoft sues scareware scammers
19:58Software company fined for trading with the enemy
19:58Misdirected spyware infects Ohio hospital
19:57Firefox's Flash check drives 10M to Adobe's download
19:55Microsoft, Yahoo in informal talks with EU over search deal

All news for September 17th, 2009:
19:59Wireless Intrusion Detection and Prevention Systems: Selection Criteria
19:58How to Compare and Use Wireless Intrusion Detection and Prevention Systems
19:54Social Networking a Tool for More Secure ID Management?
19:521.8 million UK postcodes available online
19:51Batman 'glide' disabled in anti-piracy measure
19:47Study: eBay, Yahoo among most trusted companies
19:45One in eight Brits hit by identity theft
19:44Attack E-mails Use Fake Shipping Confirmation Ruse
19:44An Amazing Laptop Recovery Story
19:41Has Conroy's dept received filter report?
19:39Will security concerns darken Google's government cloud?
19:35New phishing attack chats up victims
19:34Report: Skype founders sue Skype
19:34Google buys reCAPTCHA to boost book scanning efforts
19:33Microsoft offers tools for secure application development



All news for September, 2009
All news for 2009 year
All news for 2008 year
All news for 2007 year
All news for 2006 year
All news for 2005 year
All news for 2004 year


DONATION: www.Anti-Keylogger.Org and www.Keylogger.Org is an independent research projects supported by a team of enthusiasts. If you find this project useful and would like to help foster its continued development, please consider making a donation.

Thanks in advance for your support!


Computer monitoring spy software |  Employee monitoring |  Internet activity everywhere |  Invisible keylogger surveillance |  Invisible keystroke recorder |  Keylogger |  Monitor kids |  Monitoring solution |  Network sniffer |  Parental control |  Password protected |  Powerful spy tool |  Powerful surveillance tool |  Record all keystrokes typed |  Record every action |  Records users activity |  Remote installation |  Remote spy software |  Remotely monitor |  Screenshot recorder |  Security tools |  Spy software |  Spying on employees |  Visited web pages | 
Keylogger.Org Site News

January 05th, 2010

New version of The Best Keylogger added!

All In One Keylogger
Security World News
Keylogger.Org Security World News

September 18th, 2009

Microsoft Internet Explorer SSL security hole lingers

Conservatives call for DNA databases to be reduced

McAfee warns of bogus security suite

Security market remains buoyant in choppy waters

The good and bad of government in the cloud

Vista, Windows 7 Are More Secure than Snow Leopard

Will Google's Buy of reCAPTCHA Hurt Internet Security?

HHS guts health-care breach notification law, groups warn

Man gets 15 months for E-Trade skimming scam

Sophisticated botnet causing a surge in click fraud

Microsoft sues scareware scammers

Software company fined for trading with the enemy

Misdirected spyware infects Ohio hospital

Firefox's Flash check drives 10M to Adobe's download

Microsoft, Yahoo in informal talks with EU over search deal

Free online TV and internet radio
Voting

We are planning to redesign our site. We would like You to express your opinion in this respect. Would you like to leave the site as it is? What changes would you like to suggest?

Yes, I like the site as it is.
It's ok, but some changes are necessary.
It should be changed completely.
VotingView results
Top | home | testing and reviews | testing policy | press releases | developers |

| articles | contest | chat | forum | sponsorship & services | contacts | links |
Top
Copyright © 2003-2010, Keylogger.Org Team. All Rights Reserved.
Use of any information from this website is permitted only with hypertext link to www.keylogger.org.