Tag Archives: Internet Explorer

Microsoft issues fix for older versions of IE

Microsoft has released a quick fix for a vulnerability in older versions of its Internet Explorer browser that is actively being used by attackers to take over computers.

The vulnerability affects IE versions 6, 7 and 8. The latest versions of the browser, 9 and 10, are not affected. The company occasionally issues quick fixes as a temporary protective measure while a permanent security update is developed if a vulnerability is considered particularly dangerous.

Microsoft issued an advisory on Saturday warning of the problem, which involves how IE accesses “an object in memory that has been deleted or has not been properly allocated.” The problem corrupts the browser’s memory, allowing attackers to execute their own code.

The vulnerability can be exploited by manipulating a website in order to attack vulnerable browsers, one of the most dangerous types of attacks known as a drive-by download. Victims merely need to visit the tampered site in order for their computer to become infected. To be successful, the hacker would have to lure the person to the harmful website, which is usually done by sending a malicious link via email.

To read this article in full or to leave a comment, please click here

Source: PCWorld

Microsoft gets busy on fix for IE watering hole attack

(Phys.org)—Microsoft has published a security advisory about a vulnerability in Internet Explorer 6, 7, and 8. “We are only aware of a very small number of targeted attacks at this time,” a Microsoft team blog said. The company acknowledged the vulnerability in its Microsoft Security Advisory (2794220) published on Saturday. Reports about the problem pointed to affected users who had visited the Council of Foreign Relations (CFR) website. According to network security company FireEye, “we can also confirm that the CFR website was also hosting the malicious content as early as Friday, December 21.”
Source: Phys.org

Review: Greenshot offers full-feature screen grabs for free

I have to admit I was skeptical about Greenshot, a free, open-source screenshot tool that claims to be as full-featured as similar paid programs. But after using it, I’m a believer: Greenshot may not be perfect, but this free tool has me wondering why I’d ever pay for one like it again.

Greenshot downloads and installs easily, and requires little to no setup. By default, the program uses the “Print Screen” key (sometimes marked Prnt Scr) as its hotkey; pressing that key in combination with another key (such as Alt or Ctrl) allows for different types of screen capture. In my case, the Print Screen key was already assigned to another screen capture program, so Greenshot notified me that I’d need to choose a new one. I did so easily in the program’s settings menu, and within minutes I was up and running.Greenshot can capture a region of your screen, the last region you selected with Shift & Print Screen, one program window with Alt & Print Screen, the full screen with Ctrl & Print Screen, or an Internet Explorer window with Ctrl & Shift & Print Screen. You simply press your assigned hotkey and the capture is done. If you choose to capture a region, Greenshot lets you select it with a green overlay that makes it easy to pick the area you’d like to capture. SnagIt, a $50 rival, offers these same capture options, but adds a few more, such as the ability to capture just a menu, text from a Window, images from a Web page, and recording video from the screen.

Greenshot offers most of the same features as a commercial screen capture program

When you capture a screen in SnagIt, that program automatically opens the image in its editor, which is a full-featured editing tool. Greenshot gives you a few more options in terms of sending your captured screen to other programs or places with the destination picker. This menu pops up as soon as you capture a screen, and allows you to choose between saving the image, opening it in Greenshot’s image editor, copying it to the clipboard, sending it to your printer, uploading it to Imgur, or opening it in a variety of programs, such as Microsoft Outlook, Powerpoint, Word, Excel, or Paint, or Mozilla Thunderbird. Greenshot’s built-in image editor is more basic than SnagIt’s, though it does offer one feature that is very useful. Included among its editing options is “Obfuscate,” which lets you render a section of the screen unreadable by pixelation or blurring. As someone who captures a lot of screenshots that contain email addresses and other personal info, I find this tool invaluable, and it’s easier to use than a similar feature offered by SnagIt.

I did have one problem when using Greenshot, which occurred I tried to capture an entire Internet Explorer window. This is something that SnagIt handles flawlessly, but Greenshot faltered a bit: the capture process seemed to work fine, but the capture only showed a small portion of the IE screen.

To read this article in full or to leave a comment, please click here

Source: PCWorld

Review: Add life to Facebook fan and business pages with Heyo Social

Your small business or fan Facebook page is probably fine just the way it is. But it could be a whole lot better. That’s the idea behind Heyo Social, a nifty Web-based tool that allows you to add a whole lot of content to your Facebook fan or small business pages.Until recently, Heyo was known as Lujure, and offered a Web-based tool strictly focused on Facebook fan pages. With the name change the company has an expanded focus: Heyo now offers tools to create mobile apps and social Web sites, too. Each of its functions is offered a la carte, or you can package several options together to save more. In this review, we focused on the Heyo Social Facebook service, which starts at $3 per month for a single tab.To use Heyo Social to add content to your Facebook fan page, you simply sign in with Facebook. It will find any pages you manage, and within a few minutes you’re ready to begin adding content. You do this by creating entirely new pages that are linked to your Facebook fan page through its tabs—those small squares that sit under the cover photo, showing photos and how many likes your page has.

Heyo Social makes it easy to add images and other content to Facebook fan pages.

If you’re intimidated by the prospect of designing an entire page from scratch, Heyo offers several templates to get you started. You can apply a template to your page with a single click through the neatly organized and intuitive editor. Templates are available for many of the uses that businesses would likely have for Facebook, including selling products, offering discounts and deals, and more. Heyo Social also offers a series of widgets that you can add to your Facebook page, for things such as adding email links and inserting Google maps. All of these are very easy to use, allowing you to insert slick, professional-looking elements into your pages with ease.The templates offer an easy way to fill your tabs with content, and are helpful when you’re getting started. But I quickly found them limiting, as you can’t change all of the aspects of the template. Some aspects such as the background design, are fixed. You can start from scratch with a blank tab, which is a bit more time consuming, but gives you more control over the end result. On the left side of your Heyo Social page, you’ll see a dock that offers access to most of the tools you need to create the tab, including options for adding text, HTML, images, changing colors and more. The tools are easy enough to access, but I often found them finicky. The text editor refused to allow me to change text color when I was using Internet Explorer; switching to Firefox solved that problem, but even in that browser, I still found it more difficult than necessary to make quick fixes like as changing a font size. Heyo Social is an easy-to -se way to create polished tabs for your Facebook fan pages, but the service suffers from one major flaw: It doesn’t allow you to save or preview your work before you publish it. I created an entire page using Internet Explorer, but when Heyo Social wouldn’t allow me to change the font color, I wasn’t able to save it to open it in another browser. That meant I had to redo all of my work. Even without this font color issue, Heyo Social needs a save and preview function. You may be pulled away from your work for any number of reasons, and when you are, you need a way to save what you’re working on and come back to it later. Once you publish your content (which is when you pay for it), you can easily go back in and make changes. But if you want to add more tabs, you’ll have to pay first: Heyo doesn’t let you start drafting a second page before you’ve paid for the first one.I can deal with Heyo’s sometimes finicky tools, and I don’t hold it against them that not everything works all of the time in Internet Explorer. But I really do wish that Heyo Social offered a save and preview feature. It’s a major oversight in an otherwise excellent tool for those looking to expand their Facebook presence.

Note: The Download button on the Product Information page takes you to the vendor’s site, where you can use the latest version of this Web-based software.

Source: PCWorld

Microsoft downplays IE flaw that allows mouse tracking

Microsoft says it is investigating a possible bug in Internet Explorer that allows others to follow the position of your mouse cursor on screen, even if IE is minimized.

Researchers at Spider.io, an advertising analytics firm, discovered the function and reported it to Microsoft in early October. They identified a vulnerability in Internet Explorer, found in versions 6 through 10, that enables people to track the mouse cursor anywhere on a display, which could compromise the security of virtual keyboards and virtual keypads.

Here’s a video demo of the exploit:

To read this article in full or to leave a comment, please click here

Source: PCWorld

Adobe drags Google into Microsoft's Patch Tuesday

Google has been dragged into adopting rival Microsoft’s Patch Tuesday, which is fallout from an Adobe move last month.

Earlier this week, Google updated its Chrome browser, quashing six bugs and as it often does, also updating Adobe’s Flash Player. That same day, Microsoft shipped seven security updates to patch 12 vulnerabilities, and Adobe released a new version of Flash to address three critical bugs.

It was the Flash patches that triggered Chrome’s copycat update: In November, Adobe announced it would synchronize Flash updates with long-time-partner Microsoft’s Patch Tuesday. Most security experts applauded the decision, which they said was prompted by the bundling of Flash with Internet Explorer 10 (IE10) on Windows 8 and Windows RT.

Those same experts said Adobe’s hand was probably forced by Microsoft, which had bumbled this fall when it failed to sync IE10 updates with those shipped by Adobe for Flash.
To read this article in full or to leave a comment, please click here
Source: PCWorld

Is Internet Explorer leaking sensitive information?

Do you use Internet Explorer? If you do, hopefully you’ve already applied the updates from Patch Tuesday earlier this week. But, even if you did it seems your browser might still be vulnerable to a potentially serious issue.

Spider.io, a company in the business of helping customers distinguish between actual human website visitors and automated bot activity, claims to have discovered a flaw that affects Internet Explorer the current flagship browser from Microsoft, versions 6 through 10. The vulnerability reportedly allows the mouse cursor position to be tracked wherever it is on the screen—even if IE is minimized.

Spider.io disclosed the vulnerability to Microsoft on October 1, 2012, but it was not addressed in the most recent security update for Internet Explorer. Spider.io asserts that the flaw is being actively exploited, and claims the Microsoft Security Research Center (MSRC) has acknowledged the vulnerability, but has no immediate plan to patch it.
A bug in IE may leak potentially sensitive information
I asked Microsoft for its position on the alleged vulnerability. A spokesperson sent me this official response: “We are currently investigating this issue, but to date there are no reports of active exploits or customers that have been adversely affected. We will provide additional information as it becomes available and will take the appropriate action to protect our customers.”
To read this article in full or to leave a comment, please click here
Source: PCWorld

Internet Explorer flaw gives ad trackers a sneaky edge — for now

Some advertising analytics companies are using a vulnerability in Microsoft’s Internet Explorer browser for a questionable edge in figuring out if web users are actually seeing display advertisements buried within web pages.

The flaw, if fixed by Microsoft, could take away a metric called “viewability,” which is helping companies decide where to spend their sought-after advertising budgets on display ads with only the most productive of publishers.

Spider.io, a U.K.-based security company, published details of the vulnerability on Wednesday. But the flaw has been used for some time by at least two major advertising analytics companies in the course of business, said Spider.io CEO Douglas de Jager.

Display advertising is hoped to be a rich source of revenue for publishers. But not many people actually click on display ads, which makes it harder to measure whether the ads are having an impact on customers. Display ads are usually sold for a fee per one thousand impressions, known as CPM.To read this article in full or to leave a comment, please click here
Source: PCWorld

Final Patch Tuesday of 2012 includes five 'critical' updates

Today is the last Patch Tuesday of the year. There are seven new security bulletins from Microsoft this month, and five of them are rated “critical.” If you use Windows, Microsoft Office, or Internet Explorer, you’ve got some work to do to get these new patches applied.

MS12-082 and MS12-083, security bulletins related to flaws in DirectPlay and IP-HTTPS respectively, are rated Important. The Critical security bulletins apply to the Windows operating system, Microsoft Office, the Internet Explorer Web browser, and Microsoft Exchange Server—and a few of them require a restart for the patch to take effect.

Andrew Storms, director of security operations for nCircle, singles out MS12-077—the cumulative update for Internet Explorer—as the most urgent of the bunch. “Attackers will be targeting online holiday shoppers with this bug, so patch this before you do anything else.”

Storms also notes the unusual fact that the critical flaw in IE affects all versions, but is only exploitable on the newer versions, which are ostensibly “more secure” than their predecessors, including IE10 on Windows RT. Storms quips, “We can be sure this bug is not a gift Microsoft wanted to receive this holiday season.”
To read this article in full or to leave a comment, please click here
Source: PCWorld

Safe online shopping: 10 tips to avoid getting burned

You need to buy some gifts. You need to buy them quickly. You can (a) brave the madness of holiday retail shopping at your local mall, rife with screaming children and airborne contagions, or (b) kick back at home and buy all your gifts online, accompanied by nothing more obnoxious than a warm cup of cocoa—or a cold glass of wine.

We’ll take the online shopping option. We’re civilized adults at PCWorld, and we’re not interested in rubbing shoulders with rabid mall zombies unless we have to.

But the world of online shopping isn’t all hot chocolate and chardonnay. Buying gifts via a Web browser certainly speeds up one’s shopping regimen, but it also bears risks. Here are 10 easy ways to lock down your Web security this season, and still get all your shopping done in time.

Keep your browser updated

Start at the beginning. Whether you use Chrome, Firefox, or Internet Explorer, updating your browser will help to ensure that you’re getting the most up-to-date security protection.
To read this article in full or to leave a comment, please click here
Source: PCWorld