Does my Blog Helps You?

Tuesday, January 19, 2010

Zero-day: Number 1 search Engine Attack via Internet Explorer

Everyone is talking about China because of Google's decision to reevaluate its business operations due to its attack to their systems as one of te primary reasons.
It has been reported that the said attack distinctively targets Gmail accounts of Chinese human rights advocates in the United States, Europe and China.

Other search engines have similar report cases such as Yahoo! Dow Chemicals, and Northrop Grumman.

Security researches found thattargeted attcks use several vectors. In some cases, email messages loaded with malicious file attachments were sent to users. An exploit code taking advantage of the recently-patched vulnerability in Adobe Reader and Acrobat (CVE-2009-4324) was used to drop malware on affected systems.

Some of the attack's use of previous undetected vulnerabilty of Internet Explorer except 5.01 (CVE-2010-0249). In its recent Security Advisory, Microsoft acknowledged that this bug was indeed used to launch attacks against Google and other organizations, and recommended several workaround solutions to help reduce the impact of this bug on IE users.

In some recent work-around, I guess we could try using other web browser like Firefox. So I recommend update your browser or aplications with its latest patch. As I could see most of the malware now attack users which are not yet patch.

No comments: