Results 1 to 5 of 5
- 10-18-2009 #1
ms09-054: IE and firefox attack surface
The Security Research & Defense blog provided additional information on the attack surface for the IE Security Bulletin MS09-059:
http://www.microsoft.com/technet/sec.../ms09-059.mspx
In other words, if you happen upon a malicious website, with the Windows Presentation Foundation (WPF) plug-in enabled in Firefox, your computer is vulnerable.
Recommendations:
Internet Explorer
Although XBAP is disabled in IE8 on Win2k8 and Win2k3, that is not the case for IE7 or other operating systems. To disable this setting, edit the security settings in the Internet Zone as follows:
Launch Internet Explorer --> Click Tools --> Security Tab --> in Internet, click Custom level. Under .NET Framework --> XAML browser applications, Change the setting to Disable.

Firefox:
The WPF plug-in was installed in Firefox with .NET Framework 3.5. To disable the plug-in, do the following:
Click Tools --> Add-ons --> Click the Plugins Tab.
Select “Windows Presentation Foundation”, and click “Disable”

By Corrine MVP
Credits:
http://securitygarden.blogspot.com/2...k-surface.html
- 10-18-2009 #2
Thanks for the Internet Explorer disable guide. M$ should be a shame of themselves. They know it is a security hole, but they did not disable it in their update. Let says there are many people do not know about this issue. They always use IE as their browser. They will get screwed eventually. I can't just stand M$ for playing with people computer. Firefox rocks because they disable it.
This user has not enabled signature viewing, if you wish to view this user's signature please upgrade to a Raymond Gold account.
- 10-18-2009 #3
no its MS and Mozilla's fault
i also tweaked IE like this - thanks - but for me this is actually MS and Mozilla's fault: MS who send you the bug AND Mozilla who didnt block it (the installation). what if all other developers start to send you sneaky patches (addons, plugins, etc) like this??? - this is a Firefox security problem Mozilla is going to HAVE to fix.
btw if anyone knows a safe way - i mean i dont want to do a full .net reinstall - to remove the Windows Presentation Foundation plugin please let me know (i dont want this crap in my box). the .NET Framework Assistant is easy to remove.Last edited by noaccount; 10-18-2009 at 07:29 PM.
- 10-18-2009 #4
It's already been fixed way back on Tuesday! Maybe you just forgot to turn on your Windows Automatic Updates. IE user should have always update their IE client to its latest version to ensure protection.
Patch Tuesday
It just so happened that FF blocked the affected plugin to ensure that all users were protected from threat ( despite MS update fix ). Which is a good move.Updated October 16, 2009 - updated blog post to clarify that Firefox users are protected from CVE-2009-2529 if they install the MS09-054 update.Last edited by ceyfer; 10-18-2009 at 06:22 PM.
"positive anything is better than negative nothing"
- 10-18-2009 #5
lol this is ie7 tweak i didnt read it properly yesterday - this is not for me.
these plugins should have never gotten installed in the first place, this is a scandall!
Similar Threads
-
Free Microsoft Security Tool for Windows - Attack Surface Analyzer
By sujay in forum Spyware/VirusesReplies: 10Last Post: 05-16-2011, 05:07 AM -
Clean up surface under Laptop keyboard?
By Alboguy in forum HardwareReplies: 13Last Post: 04-12-2010, 09:00 PM -
Firefox gains market share – One more reason to FORget Firefox?
By safeguy in forum General ForumReplies: 4Last Post: 01-09-2010, 06:36 PM -
Network Attack!
By BlackMamba88 in forum NetworkReplies: 5Last Post: 06-27-2009, 10:53 PM -
IP attack!!!
By black2 in forum General ForumReplies: 8Last Post: 04-05-2008, 01:49 PM


LinkBack URL
About LinkBacks





Reply With Quote

