cALLus
No favorite files added yet
(Aug 22, 2006 - 11:15 AM)
IE7 is better than Firefox because IE7 has the protected mode in Windows Vista.
IE7 in Windows Vista incorporates additional security measures, most significantly "Protected Mode", whereby the browser runs in a sandbox with even lower rights than a limited user account. As such, it can write to only the Temporary Internet Files folder and cannot install start-up programs or change any configuration of the operating system without communicating through a broker process. This is expected to increase the security of the system considerably.
(Aug 22, 2006 - 9:35 AM)
Trend Micro says this is not a 0-day exploit, but exploit an old flaw (MS06-012).
“This Trojan is not a zero-day exploit. It attempts to exploit the Microsoft Office Remote Code Execution Using a Malformed Routing Slip Vulnerability. It is seen that this Trojan has a similarity with other malware exploiting the said Vulnerability. Note that the shell code of the sample is actually located in the routing slip record. However, the shellcode does not manifest the said behavior.”
http://www.trendmicro.co...ROPPER%2EBH&VSect=T
According to Stephen Toulouse, a program manager in the MSRC (Microsoft Security Response Center), the vulnerability has already been resolved by an update.
"Our initial investigation is that this is not a new zero-day at all," Toulouse said in an e-mail exchange with eWEEK.