also @ TechSpot: UK's SOCA seizes domain of popular music blog, rnbxclusive.com
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.

Go Back   TechSpot OpenBoards > TechSpot Community > General Discussion

Download Now:

IE Hole Is Actually A "Feature"!

Page 1 of 2 1 2
Thread Tools Search this Thread
  #1  
Old 07-05-2004
Phantasm66's Avatar
TechSpot Evangelist
 
Location: Glasgow, Scotland
Member since: Feb 2002, 6,504 posts
IE Hole Is Actually A "Feature"!

You will recall that last week security experts (man, what a cool job!) released evidence that there were certain vulnerabilities in IE and IIS 5.0 that could allow hackers to redirect browsers and download a keylogging trojan from a Russian website. We posted a story about a released fix, here.

Anyway, you will be interested I am sure to find out this security flaw is actually a feature that allows an ActiveX ADODB.Stream object to read and write files on a hard drive. Attackers used this "feature" to download copies of a keystroke logging trojan onto the unsuspecting browser user's computers.

In addition to the fix, there is also now a workaround in progress, and rest assured Microsoft is currently thinking up more "features" for us as we speak.
  #2  
Old 07-05-2004
Mictlantecuhtli's Avatar
TechSpot Special Forces
 
Location: Finland
Member since: Feb 2002, 4,886 posts
System specs
Somehow I find scripts that don't have read/write access to local files to be more secure..
  #3  
Old 07-05-2004
Phantasm66's Avatar
TechSpot Evangelist
 
Location: Glasgow, Scotland
Member since: Feb 2002, 6,504 posts
What, you mean as in UNIX, basically? Yeah.
  #4  
Old 07-05-2004
STK STK is offline
TechSpot Member
 
Location: Bronx, NY
Member since: Jun 2004, 138 posts
thank god IE isnt good, lol it stopped working for me a little while ago.
  #5  
Old 07-05-2004
Phantasm66's Avatar
TechSpot Evangelist
 
Location: Glasgow, Scotland
Member since: Feb 2002, 6,504 posts
I've started using Firefox for anything I consider in any way hostile (i.e. just about every web site out there!)
  #6  
Old 07-05-2004
STK STK is offline
TechSpot Member
 
Location: Bronx, NY
Member since: Jun 2004, 138 posts
I am using Mozilla, since IE stopped working.
  #7  
Old 07-05-2004
Federelli's Avatar
TechSpot Booster
 
Location: Buenos Aires, Argentina
Member since: Mar 2002, 382 posts
I second that Phantasm66.

Though my IE hasn't stoped working at all. But i did use to get lots of adware, and with firefox, i've not used ad-aware for a long time now.

I wonder what you meant with "features"
  #8  
Old 07-05-2004
Phantasm66's Avatar
TechSpot Evangelist
 
Location: Glasgow, Scotland
Member since: Feb 2002, 6,504 posts
...and when Longhorn arrives, I am sure that will be "feature" packed as well!

  #9  
Old 07-05-2004
STK STK is offline
TechSpot Member
 
Location: Bronx, NY
Member since: Jun 2004, 138 posts
Yes, i think it will be... just like every other windows OS.
  #10  
Old 07-05-2004
Phantasm66's Avatar
TechSpot Evangelist
 
Location: Glasgow, Scotland
Member since: Feb 2002, 6,504 posts
Just think about all of the "features" Microsoft is working on right now...
  #11  
Old 07-05-2004
STK STK is offline
TechSpot Member
 
Location: Bronx, NY
Member since: Jun 2004, 138 posts
Ya, i think they will probably have a more advance "feature" where anyone is allowed to access your windows folder.
  #12  
Old 07-05-2004
Phantasm66's Avatar
TechSpot Evangelist
 
Location: Glasgow, Scotland
Member since: Feb 2002, 6,504 posts
I can very vividly picture Bill Gates in my head saying "....and its got these really cool features, where blah blah blah...."

I think a much better approach to modern software engineering on products destined for the unwashed masses should be to rank what people hate about computers and exterminate everything on the list. Then redesign based on that. Not add more problems to something that's already got enough problems, thanks.

Its doesn't take much imagination to put things like spam, security holes, viruses and so forth on that list, and design product that from the ground up just aren't susceptable to these things, full stop.

All of this going around adding "features" is basically adding extra bugs onto things that are already bug ridden and messy.

If Firefox shows us anything, is that a sucessful product is simple in design, just does what you want it to do, and does not permit anything annoying. End of story.
  #13  
Old 07-05-2004
STK STK is offline
TechSpot Member
 
Location: Bronx, NY
Member since: Jun 2004, 138 posts
Ya, i can see bill saying that. I can also picture the windows where you are working on a word document and it crashes and says Error 263472562738253822936(also known as some cracker is looking at you personal files right now and we think it would help if we ended word.

Then that guy that uses linux and doesnt get any bugs, viri, trojans, adware, or spyware that got your IP address from who knows where(one of the millions of places that your IP is just waiting to be taken), is sitting at his computer laughing at you.
  #14  
Old 07-05-2004
Mictlantecuhtli's Avatar
TechSpot Special Forces
 
Location: Finland
Member since: Feb 2002, 4,886 posts
System specs
Quote:
Originally posted by Phantasm66
All of this going around adding "features" is basically adding extra bugs onto things that are already bug ridden and messy.

If Firefox shows us anything, is that a sucessful product is simple in design, just does what you want it to do, and does not permit anything annoying.
Perfection is reached, not when there is no longer anything to add, but when there is no longer anything to take away.

-- Antoine de Saint-Exupery
  #15  
Old 07-05-2004
BrownPaper's Avatar
TechSpot Booster
 
Location: Los Angeles, CA USA
Member since: Feb 2003, 467 posts
System specs
Microsoft has good intentions trying to create the capabilities to have programs do more and more. Their problem is that their software sometimes does more than we want it to (without our consent).

Shoddy programming is making things very complex and huge. Just make it do what the software is supposed to do and not make it do anything else.
  #16  
Old 07-05-2004
TechSpot Member
 
Location: Virginia
Member since: May 2003, 146 posts
funny how this never realy effects "joe schmoe user" like it effects people in the know.

Ignorance is bliss after all... I remember when features sounded like a good thing.
  #17  
Old 07-06-2004
Phantasm66's Avatar
TechSpot Evangelist
 
Location: Glasgow, Scotland
Member since: Feb 2002, 6,504 posts
The problems ARE affecting you, you just don't know its happening. Its like being infected with a virus on your machine and you don't have anti-virus software so you don't even know its there.

But that doesn't change the fact that it IS there.
  #18  
Old 07-06-2004
TechSpot Member
 
Location: Virginia
Member since: May 2003, 146 posts
true, but I was making the point that joe schmoe only checks his e-mail and looks up flights occasionally... they're not running their offices network security or anything... you know, the guys with a AMD 600 and no reason to upgrade.

Thought I'd throw this out there too, in regards to the Anti-Virus: I recently found that Avast- AntiVirus is a great FREEWARE anti virus. You have to register, but it's free and hassle-free, just fill out like a 3 second form and they e-mail you a reg code that's valid for a year.. then when the year is up, register again for free!! I'm not one for advertising, but it's definitley worth a look. It even scans incoming website trojans, much related to this topic, so I KNOW I was having issues with this IE 'Feature' on one of my comps.

You can get Avast from download.com
  #19  
Old 07-06-2004
Guest
 
Opera owns.

[url]www.opera.com[/url]
  #20  
Old 07-06-2004
Phantasm66's Avatar
TechSpot Evangelist
 
Location: Glasgow, Scotland
Member since: Feb 2002, 6,504 posts
Quote:
Originally posted by Mictlantecuhtli
Perfection is reached, not when there is no longer anything to add, but when there is no longer anything to take away.

-- Antoine de Saint-Exupery

Really, it IS true. You can't believe how better my computing seems now I have striped away alot of the unnecessary rubbish like:

1)Dual booting

2)Having small screens with lots of windows open

3)Constantly chasing all of the most "up-to-date" application suites like office, photoshop, macromedia, etc...

...and just concentrated on pure USE.

If you don't use something don't bother installing it and the best software to use is likely to be that which is simple and effective in a great many cases.


Quote:
Originally posted by Strakian
true, but I was making the point that joe schmoe only checks his e-mail and looks up flights occasionally... they're not running their offices network security or anything... you know, the guys with a AMD 600 and no reason to upgrade.
...which is exactly why these guys need simple, bug-free software just like Mozilla Firefox that is not prone to complex and annoying problems. These people aren't equiped to deal with these complex security issues and so forth so they need to know its being delt with. A lot of the problems that "joe nobody" experiences with computing IS result of security problems and viruses, they just don't realise it. They blame themselves. They think its just "them being stupid" and don't realise that they have a virus infection or anything like that because they have no anti-virus software and don't know how to get it or that they need it.

Closed Thread
Page 1 of 2 1 2

Similar Topics
Topic Replies Forum
"My Computer", "Trash Bin", "Control Panel" etc will not open. 6 Windows OS
"Insecure Internet Activity" and "Security Center Alert" about Win32.zafi.B 1 Virus and Malware Removal
Viacom's "bass-ackwards" screw-up: issues takedown for video it "pirated" 0 General Discussion
repeating BSOD "feature" 3 Windows BSOD, Freezing, Restarting Help
Mac OS X To Gain New "Spotlight" Search Feature 2 General Discussion

Thread Tools Search this Thread
Search this Thread:

Advanced Search
All times are GMT -4. The time now is 02:05 AM.