Welcome!

Welcome to Satlover forums, full of great people, ideas and excitement.

Please register if you would like to take part. link..

Register Now

Alert: Don't Use Hotmail Email Accounts for registration

Collapse

Before Access to all Forums and Trial accounts you must need to activate your account Email address

MS vulnerability

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • mahrkpat
    Experienced Board Member
    • Jun 2012
    • 1493

    MS vulnerability

    A vulnerability found in Microsoft's Internet Explorer allows hackers to
    track the movements of your mouse cursor across the screen, which
    could in turn reveal data entered on virtual keyboards.

    Virtual keyboards and keypads can be used to reduce the chance of a
    keylogger recording every keystroke and therefore being able to "read"
    your passwords. However Spider.io discovered that Internet Explorer
    versions 6 to 10 make it possible for your mouse cursor to be tracked
    anywhere on screen, even if the IE tab is minimized. You can see a
    video demonstration of the vulnerability embedded in this post, or you
    can try it yourself at this__http://iedataleak.spider.io/demo (provided
    you are browsing with IE).

    On a separate note vulnerability in windows 8 will keep windows
    tech's busy over Christmas.

    [QUOTE]Justin Angel, an engineer working on Finnish phonemaker Nokia
    Oyj.'s Windows Phone team, has made the curious decision of going
    public with details of security flaws in partner Microsoft Corp.'s
    Windows 8, which allow users to pirate games.

    Windows 8 users can grab games via Windows Store. Paid titles
    typically come with a "Trial" option, which allow users to play a level
    or two of the game, before being prompted to purchase the title if
    they want to keep playing. The trial process is controlled by a
    Microsoft API.

    But Mr. Angel reveals a fatal flaw in the scheme: Microsoft stores
    the key/hash in plaintext and the algorithm to encrypt/decrypt the
    data next to the app itself. In other words, while not for the novice,
    power users can write small programs to decrypt the program's
    permissions, write new permissions to make the game look
    legitimately purchased, and then re-encrypt the permissions.

    By exploit the flaws users cannot only get games for free, but they
    can rid themselves of ads, albeit in a somewhat unethical manner.

    But Mr. Angel does not stop there. He also shows off more security
    flaws, showing how JavaScript injection attacks can be used to gain
    access (for free) to in-app purchases. As an example he uses such
    an attack to unlock purchasable levels in the popular game Cut The
    Rope.[/QUOTE]
    Liked my post then push the sigpic button.
  • pan1300
    Experienced Board Member
    • Apr 2012
    • 1663

    #2
    Re: MS vulnerability

    hi mahrkpat

    Thanks, any idea if just MS IE is involved (so are eg google chrome and mozilla firefox more safe?). Think we once had a thread here about the 'best' provider, but don't think we discussed the 'safest' ones.

    Comment

    • mahrkpat
      Experienced Board Member
      • Jun 2012
      • 1493

      #3
      Re: MS vulnerability

      [QUOTE=pan1100;256363]hi mahrkpat

      Thanks, any idea if just MS IE is involved (so are eg google chrome and mozilla firefox more safe?). Think we once had a thread here about the 'best' provider, but don't think we discussed the 'safest' ones.[/QUOTE]

      It is just I.E 6.0 to 9.0 that is why you need Internet Explorer to see
      the vulnerability in the demo, the scary thing is it still tracks even
      when I.E is minimised therefore after looking at some info on the
      internet you might carry on working not knowing you are giving out
      data all the time.
      Liked my post then push the sigpic button.

      Comment

      • duhoki
        Experienced Board Member
        • Aug 2011
        • 876

        #4
        Re: MS vulnerability

        We most not forget that IE is not unsafer then most of the other browser, but IE is the most wanted for hackers to hack same for many other microsoft applications, why? because it is widely used by company and privat users. Many company uses IE as default browser, not because they want it but because all applications the providers is developing is amde to work 100% with IE, and most of the employes is known with IE. However IE have over time had to many vulnerability and its just wait and see what the worl ahve to bring.

        Comment

        • sossenheim-ffm
          Member
          • Oct 2012
          • 81

          #5
          Re: MS vulnerability

          Actually all Browsers are very unsafe but IE is the most because as you said company's and private person are using it often.
          But in few companys like in mine we got a IT section and they developed an own browser.
          It's very fast stable and should be to 97 percent safe.
          Before we used IE and got hacked few times.
          If I helped you please press thanks button!

          Comment

          • microchick
            Experienced Board Member
            • Apr 2012
            • 1162

            #6
            Re: MS vulnerability

            If all the browsers are unsafe then how you gonna browse the internet. There are always good and bad things about any products. And If you ask a few people all will give you a different answer about their browsers but no one knows why one is better than the other. It all comes down to personal choice.
            If you like my post, please don't hesitate to click on "Thanks"button. Thank you

            Comment

            • Satphoenix
              Experienced Board Member
              • Oct 2012
              • 999

              #7
              Re: MS vulnerability

              One possible way to have better security is to surf with browsers which use the noscript funtion (firefox, chrome). In firefox it's very easy, in chrome you have to do a few things by hand. Any other browsing means a lot of ads and danger!
              If you want to make God laugh, tell him your plans!

              Comment

              • mahrkpat
                Experienced Board Member
                • Jun 2012
                • 1493

                #8
                Re: MS vulnerability

                MS reacted to this and pointed out it was unfair to single out just I.E.

                [QUOTE]Microsoft has confirmed that it's investigating and plans to "adjust this behavior," although it takes issue with Spider.io both focusing on IE and decrying two ad analytics firms that are supposedly exploiting the flaw today. The Redmond team argues that other browsers have "similar capabilities" and that Spider.io has ulterior motives, being an ad analytics firm itself -- it allegedly wants to knock down two competitors that it doesn't think are playing fair.[/QUOTE]
                Liked my post then push the sigpic button.

                Comment

                • microchick
                  Experienced Board Member
                  • Apr 2012
                  • 1162

                  #9
                  Re: MS vulnerability

                  you might wish to consider not using IE to store passwords. It is much less secure than a 3rd party Password Manager such as Last Pass. It is a Password Manager,a form filler and is much more secure than IE.
                  If you like my post, please don't hesitate to click on "Thanks"button. Thank you

                  Comment

                  • mahrkpat
                    Experienced Board Member
                    • Jun 2012
                    • 1493

                    #10
                    Re: MS vulnerability

                    Sometimes it seems more convenient to let the computer save your
                    passwords and worry about the consequences later but best not to
                    store sensitive passwords on your computer there are vulnerabilities
                    appearing all the time.
                    Got a Samsung Smart t.v then be very worried it has vulnerability which
                    allows a hacker access to your home network data files when you have
                    the t.v connected to the internet.
                    Liked my post then push the sigpic button.

                    Comment

                    • joseram2000
                      Board Senior Member
                      • Nov 2010
                      • 271

                      #11
                      Re: MS vulnerability

                      If they activate a program similar to workspace macro that records all mouse movements be possible and not unreasonable.

                      Comment

                      • bonilla
                        Board Senior Member
                        • Aug 2012
                        • 251

                        #12
                        Re: MS vulnerability

                        Security software companies must be smiling ear to ear as they read the news briefs coming off the transom. Microsoft said today that an undetermined number of computers in its Mac software business unit got infected with malware. The company said the number of infected PCs was small but that there was no indication customer data had been compromised. :)
                        We'll see what it is about in a few days!
                        If you like my post, please don't hesitate to click on "Thanks"button. Thank you

                        Comment

                        Working...