Donate Now Goal amount for this year: 799 USD, Received: 100 USD (13%)
Please donate to help support this website. The funds will be used to purchase owned license of LiteSpeed Web Server Enterprise (2-CPU). It provides superior performance in terms of raw speed, scalability and anti-DDoS capabilities.

Results 1 to 5 of 5
  1. #1
    Moderator
    Points: 49,131, Level: 100
    Level completed: 0%, Points required for next Level: 0
    Overall activity: 47.0%
    Achievements:
    Recommendation Second ClassRecommendation First Class31 days registered3 months registered100 Experience Points

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,554
    Liked
    546 times

    ms09-054: IE and firefox attack surface

    The Security Research & Defense blog provided additional information on the attack surface for the IE Security Bulletin MS09-059:

    http://www.microsoft.com/technet/sec.../ms09-059.mspx

    In other words, if you happen upon a malicious website, with the Windows Presentation Foundation (WPF) plug-in enabled in Firefox, your computer is vulnerable.


    Recommendations:

    Internet Explorer

    Although XBAP is disabled in IE8 on Win2k8 and Win2k3, that is not the case for IE7 or other operating systems. To disable this setting, edit the security settings in the Internet Zone as follows:

    Launch Internet Explorer --> Click Tools --> Security Tab --> in Internet, click Custom level. Under .NET Framework --> XAML browser applications, Change the setting to Disable.






    Firefox:

    The WPF plug-in was installed in Firefox with .NET Framework 3.5. To disable the plug-in, do the following:

    Click Tools --> Add-ons --> Click the Plugins Tab.
    Select “Windows Presentation Foundation”, and click “Disable”






    By Corrine MVP

    Credits:

    http://securitygarden.blogspot.com/2...k-surface.html

  2. #2
    Experienced User
    Points: 20,378, Level: 90
    Level completed: 6%, Points required for next Level: 472
    Overall activity: 11.0%
    Achievements:
    31 days registered3 months registered1 year registered100 Experience Points500 Experience Points

    Join Date
    Jun 2009
    Location
    Quarantine
    Posts
    1,774
    Liked
    50 times
    Thanks for the Internet Explorer disable guide. M$ should be a shame of themselves. They know it is a security hole, but they did not disable it in their update. Let says there are many people do not know about this issue. They always use IE as their browser. They will get screwed eventually. I can't just stand M$ for playing with people computer. Firefox rocks because they disable it.
    This user has not enabled signature viewing, if you wish to view this user's signature please upgrade to a Raymond Gold account.

  3. #3
    Tech God
    Points: 27,433, Level: 98
    Level completed: 9%, Points required for next Level: 917
    Overall activity: 0.7%
    Achievements:
    31 days registered3 months registered1 year registeredTagger Second ClassTagger First Class

    Join Date
    Sep 2009
    Posts
    2,046
    Liked
    0 times

    no its MS and Mozilla's fault

    i also tweaked IE like this - thanks - but for me this is actually MS and Mozilla's fault: MS who send you the bug AND Mozilla who didnt block it (the installation). what if all other developers start to send you sneaky patches (addons, plugins, etc) like this??? - this is a Firefox security problem Mozilla is going to HAVE to fix.

    btw if anyone knows a safe way - i mean i dont want to do a full .net reinstall - to remove the Windows Presentation Foundation plugin please let me know (i dont want this crap in my box). the .NET Framework Assistant is easy to remove.
    Last edited by noaccount; 10-18-2009 at 07:29 PM.

  4. #4
    Guest
    Points: 45,457, Level: 100
    Level completed: 0%, Points required for next Level: 0
    Overall activity: 44.0%
    Achievements:
    31 days registered3 months registered1 year registeredVeteranTagger Second Class

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,081
    Liked
    522 times
    Quote Originally Posted by luffy View Post
    Thanks for the Internet Explorer disable guide. M$ should be a shame of themselves. They know it is a security hole, but they did not disable it in their update. Let says there are many people do not know about this issue. They always use IE as their browser. They will get screwed eventually. I can't just stand M$ for playing with people computer. Firefox rocks because they disable it.
    It's already been fixed way back on Tuesday! Maybe you just forgot to turn on your Windows Automatic Updates. IE user should have always update their IE client to its latest version to ensure protection.

    Patch Tuesday

    Updated October 16, 2009 - updated blog post to clarify that Firefox users are protected from CVE-2009-2529 if they install the MS09-054 update.
    It just so happened that FF blocked the affected plugin to ensure that all users were protected from threat ( despite MS update fix ). Which is a good move.
    Last edited by ceyfer; 10-18-2009 at 06:22 PM.
    "positive anything is better than negative nothing"


  5. #5
    Tech God
    Points: 27,433, Level: 98
    Level completed: 9%, Points required for next Level: 917
    Overall activity: 0.7%
    Achievements:
    31 days registered3 months registered1 year registeredTagger Second ClassTagger First Class

    Join Date
    Sep 2009
    Posts
    2,046
    Liked
    0 times
    lol this is ie7 tweak i didnt read it properly yesterday - this is not for me.
    these plugins should have never gotten installed in the first place, this is a scandall!

 

 

Similar Threads

  1. Replies: 10
    Last Post: 05-16-2011, 05:07 AM
  2. Clean up surface under Laptop keyboard?
    By Alboguy in forum Hardware
    Replies: 13
    Last Post: 04-12-2010, 09:00 PM
  3. Replies: 4
    Last Post: 01-09-2010, 06:36 PM
  4. Network Attack!
    By BlackMamba88 in forum Network
    Replies: 5
    Last Post: 06-27-2009, 10:53 PM
  5. IP attack!!!
    By black2 in forum General Forum
    Replies: 8
    Last Post: 04-05-2008, 01:49 PM
All times are GMT +8. The time now is 11:50 PM.