Forum Moderators: open
Computer code that could be used to hijack Windows PCs via a yet-to-be-patched Internet Explorer flaw has been posted on the Net, experts have warned.The code was published on public Web sites, where it is accessible to miscreants who might use it to craft attacks on vulnerable Windows computers. Microsoft is investigating the issue, the company representative said in a statement Thursday.
Microsoft says that Windows users should disable ActiveX and active scripting controls.
Attack code targets new IE hole [news.com.com]
Microsoft says that Windows users should disable ActiveX and active scripting controls.
The Microsoft Security Respose Advisory # 925444 indicates the following.
At Risk:
Microsoft Internet Explorer on Windows 2000 Service Pack 4, on Windows XP Service Pack 1, and on Windows XP Service Pack 2.
Not At Risk:
Customers who are running Windows Server 2003 and Windows Server 2003 Service Pack 1 in their default configurations, with the Enhanced Security Configuration turned on, are not affected.
Any software that achieves significant market acceptance will be subject to hack attempts.
Their have been recommendations to turn off activeX several times in the past. It didn't seem too many people listened in the past.