/?pid=exploits-in-the-wild-for-ie6-flaw-growing-392

Updated:12:37 PM EST Jan 18


this is ggmania.com subsite Exploits in the wild for IE6 flaw growing! - TechAmok

Exploits in the wild for IE6 flaw growing! - [security]
05:33 AM EST - Mar,27 2006 - post a comment

ZDNET's George Ou seems to be getting more and more strident in his warnings about the increasing risk facing IE users. Its now likely over 100 websites are using the latest IE6 flaw and the number is growing. He goes so far as to put this on par with the WMF exploit. He offers 3 basic workarounds including disabling scripts, employing Hardware DEP or switching browsers.
Right now there are some reasonably feasible solutions for Windows PC users:
  • Disable active scripting, for Enterprise and for the home.
  • Enable hardware-enforced DEP if you have the right hardware. 
  • Use an alternate browser like Opera or Firefox.
  • Do not run Windows as an Administrator.

Each one of these solutions are less than desirable in one aspect or another.  Here is a explanation of the options.

  • Disabling active scripting is the official workaround from Microsoft.  It does work 100% of the time, but it also breaks a lot of websites and you'll have to individually add legitimate sites that need active scripting to your trusted IE zone.
  • Enabling hardware-enforced DEP and enabling it for all services and programs seemed to work like a charm.  When I tested a malicious site, hardware-enforced DEP protected me 7 out of 7 times!  Without the hardware-enforced DEP, the malicious website successfully launched a massive number of exploits 2 out of 2 times.  Hardware-enforced DEP works preemptively without any patches to the OS or anti-virus software which is extremely desirable.  The problem is that only the newest computers have it.  The problem with hardware-enforced DEP is that not everyone has the right CPU.  There are still some new computers being sold today that don't have hardware-enforced DEP capability.  Most old computers don't have the capability.  Again you should see my DEP guide and see if you can use it to protect yourself because it's great if you have it.  The WMF exploits were also stopped dead in their tracks by hardware-enforced DEP.
  • Using a browser like Opera or Firefox at least for the time being if the last two options aren't feasible to you is probably a good idea at least until the storm blows over and a patch is available.  Opera seems to be the least flawed of the bunch and Firefox has actually had more flaws per month than Internet Explorer, but Internet Explorer is still a favorite target because of how ubiquitous IE is.  The only issue with Firefox and Opera is that it won't run on some websites and Intranet applications.
  • Not running as Administrator is always a good idea on any computer or operating system you use.  The problem with this on the Windows XP platform is that not all software is compatible with non-administrative access and Windows XP defaults to Administrator mode.
Those using the patched versions of IE bundled with Windows 2000, Windows XP and Windows Server 2003 are vulnerable to these bugs. People trying out the Beta 2 version of Internet Explorer 7 are safe. To avoid falling victim, Microsoft urged users to avoid websites they did not trust and to refrain from opening attachments on e-mail messages from unknown senders.

It's time for Microsoft to hurry up and finish testing their patch and release the fix as soon as possible, yesterday if possible!

Short overview of recent news articles

AI in 2050 (Jan,18 2026 )

iOS 26.2 Fixes Major Security Flaws (Jan,17 2026 )

Google Links its AI to Your Gmail and Photos for "Personal (Jan,17 2026 )

Fastest Koenigsegg v Fastest Bugatti: DRAG RACE (Jan,17 2026 )

Creating a 48GB NVIDIA RTX 4090 GPU (Jan,17 2026 )

CES was frickin weird, guys (Jan,14 2026 )

Lee Cronin's The Mummy - Official Teaser Trailer (2026) Jack (Jan,12 2026 )

Ferrari SF90 XX v Xiaomi SU7 Ultra: DRAG RACE (Jan,12 2026 )

Welcome to the Wasteland - Fallout (American TV series) fan video (Jan,10 2026 )

GOOD LUCK, HAVE FUN, DON'T DIE Trailer 2 (2026) Sam Rockwell (Jan,09 2026 )

NVIDIA Releases GeForce 591.74 WHQL Drivers with DLSS 4.5 Support (Jan,07 2026 )

Predator: Badlands Exclusive Deleted Scene (2025) (Jan,07 2026 )

Greenland 2: Migration - Official Trailer 3 (2026) Gerard Butler, (Jan,06 2026 )

The Best Laptops of 2025 - For Gaming, Creators & Students! (Jan,05 2026 )

Punkt Updates its Privacy-Focused Smartphone (Jan,05 2026 )

Clicks Launches New Ways to Add a Physical Keyboard to Your Life (Jan,05 2026 )

Building a PC for the First Time (Jan,05 2026 )

Building a PC in 2026 (Jan,03 2026 )

I want this phone so bad... - Samsung Galaxy Z TriFold (Jan,02 2026 )

The Real Finewine Strikes Again: Ryzen 5600X, 5700X & 5800XT Revisit (Jan,02 2026 )

Nokia N8 Symbian Re-Awakened With Passion (Jan,02 2026 )

Europe Forces Apple to Open up More of iOS (Jan,02 2026 )

Must have Privacy and Security Tweaks: 2026 Edition (Jan,02 2026 )

How Did RAM Get So Expensive?! (Jan,01 2026 )

GeForce RTX 5090 prices to soar to $5,000 as NVIDIA and AMD prep GPU (Dec,31 2025 )

Hacker arrested for KMSAuto malware campaign with 2.8 million (Dec,30 2025 )

Killer Whale - Official Trailer (2026) Virginia Gardner, Mel (Dec,29 2025 )

NVIDIA Showed Me Their Supercomputer (Dec,28 2025 )

2026 CPU Launches! AMD, Intel & NVIDIA: Buy Now or Wait? (Dec,28 2025 )

Disable this Windows Feature that Secretly Eats Up RAM! (Dec,27 2025 )

New Windows 11 vs Old Malware: Will it survive? (Dec,27 2025 )

Samsung TriFold Durability Test: We found the limit (Dec,27 2025 )

TRUST WALLET CONFIRMS SECURITY BREACH (Dec,26 2025 )

Xiaomi 17 Ultra Leads And Samsung To Follow With A 10 Percent Price (Dec,26 2025 )

Merry Christmas Gaming Insanity (Dec,25 2025 )

Battlefield 6 - Official PS5 Features Trailer (Dec,24 2025 )

NVIDIA GeForce Hotfix Driver 591.67 Released (Dec,24 2025 )

Finally! A Battery That's Better Than Energizer and Duracell! (Dec,23 2025 )

NVIDIA Killing Cheap 16GB Local AI GPUs? (Dec,22 2025 )

Top 10 Movie Sequels of All Time (Dec,21 2025 )

He Built a Privacy Tool. Now He's Going to Prison (Kone Rodriguez, (Dec,21 2025 )

Insane Moves! B-Boy Shigekix vs. B-Boy Issin - Red Bull BC One World (Dec,20 2025 )

9800X3D & RTX 5070 Ti Gaming PC - MSI Project Zero Done Right (Dec,20 2025 )

The XG27AQWMG Sets a New Standard for 1440p OLED (Dec,19 2025 )

OnePlus 15R Boasts Huge 7,400 mAh Battery (Dec,19 2025 )

Motorola Refreshes moto g power for 2026 (Dec,19 2025 )

NVIDIA GeForce 591.59 WHQL Driver (Dec,18 2025 )

Are We Quitting YouTube Due To DRAM Apocalypse? (Dec,18 2025 )

The Samsung TriFold is AWESOME! (Dec,16 2025 )

$30 vs $30,000 TV (Dec,16 2025 )

>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs