Results 1 to 6 of 6
  1. #1
    Untanglit
    Join Date
    Mar 2008
    Posts
    18

    Default AURORA Zero day MS internet explorer vulnerability

    Can it be detected by untangle? any input guys?

  2. #2
    Master Untangler
    Join Date
    Oct 2008
    Posts
    117

    Default

    bump

  3. #3
    Untanglit
    Join Date
    Mar 2008
    Posts
    18

    Default

    Quote Originally Posted by eljudo View Post
    Can it be detected by untangle? any input guys?


    bump, bump

    someone please help!

  4. #4
    Untangle Ninja sky-knight's Avatar
    Join Date
    Apr 2008
    Location
    Phoenix, AZ
    Posts
    16,971

    Default

    And what about this "one" zero day has you worried about it enough that you're asking? Because it's made the news somewhere?

    This vulnerability is all but negated if you have data execution prevention enabled on your machine. This feature is enabled by default on any XP/Vista/7/2003/2008 computer.

    And no, there is nothing in Untangle to prevent the abuse of a bug in the rendering engine of any web browser.

    Don't panic... read.

    http://www.sophos.com/blogs/sophoslabs/v/post/8227

    Btw...

    http://community.websense.com/blogs/...-attack_012109

    is wild pack of lies. Websense doesn't offer a single product that completely rewrites the http session. Which would be required to prevent this attack.
    Last edited by sky-knight; 01-21-2010 at 02:05 PM.
    Rob Sandling, BS:SWE, MCP
    Intouch Technology
    Phone: 480-272-9889
    NexgenAppliances.com
    Phone: 866-794-8879

  5. #5
    Untanglit
    Join Date
    Sep 2008
    Posts
    25

    Default

    http://lists.emergingthreats.net/pip...ry/005567.html

    That might help mitigate until you get your patches out.

    I haven't tested this, but you can write your snort rules for anything. I will reiterate what was said previously that this is one of many 0 days.

    http://www.zerodayinitiative.com/advisories/upcoming/

    That's just a glimpse of what more you should be worried about

  6. #6
    Master Untangler
    Join Date
    Aug 2008
    Posts
    513

    Default

    Quote Originally Posted by sky-knight View Post
    And what about this "one" zero day has you worried about it enough that you're asking? Because it's made the news somewhere?

    This vulnerability is all but negated if you have data execution prevention enabled on your machine. This feature is enabled by default on any XP/Vista/7/2003/2008 computer.
    Not positive, but I thought I read an article this week that stated that this technique could be used to bypass DEP.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

SEO by vBSEO 3.6.0 PL2