About
Subscribe
  • Home
  • /
  • Security
  • /
  • Re the Internet Explorer attack code used to hack Google - there is an alternative that would avoid such cal...

Re the Internet Explorer attack code used to hack Google - there is an alternative that would avoid such calamities!

Johannesburg, 29 Jan 2010

SecureData Security, part of JSE-listed SecureData Holdings and the sub-Saharan distributor for Shavlik Technologies, the market leader in simplifying and automating critical-to-perform and manage IT operations, recently commented on the latest Microsoft out-of-band patch that repairs a zero-day flaw in Internet Explorer.

“Microsoft recently released a new out-of-band patch designed to address the serious undiscovered flaw in Internet Explorer that was used to launch a zero-day attack against Google users in China,” commented Jason Miller, data and security team leader, Shavlik Technologies. “The exploit allowed hackers to trick users into installing malware on targeted machines, which could then be used to steal data.

“The attack looks like a message that's sent from a trusted source via e-mail or social media, so when the user clicks on a link or file, it triggers the hack. The exploit opens a back door, which then compromises the machine of the target. This attack was designed to exploit PCs, netbooks and laptops using Internet Explorer version 6 running on Windows XP. By issuing this out-of-band patch now, Microsoft has cut the time hackers could use to exploit the vulnerability in advance of the 9 February Patch Tuesday bulletin releases.”

Shavlik reports that users of Shavlik NetChk Protect and its Shavlik NetChk Agent are protected against this flaw. The Shavlik NetChk Agent, which integrates Sunbelt Software's award-winning VIPRE antivirus + antispyware engine, detects the exploit code and blocks it from executing. IT administrators can use the Shavlik NetChk console to quickly and easily determine that VIPRE threat signature files and engines are up-to-date. Once the out-of-band patch is released, the Shavlik NetChk Agent will deploy the patch. The Shavlik NetChk Agent reduces agent bloat by using a single agent to provide patch management and antivirus + antispyware.

Shavlik NetChk Protect is consistently ranked the best solution available for simplifying and automating critical IT operations for Microsoft Windows environments. Shavlik reports that corporate computing users running Windows Vista or Windows 7 would be challenged to exploit the flaw effectively due to advanced security protections already built into these newer versions of the Windows OS.

“However, just because it's more difficult to exploit this flaw, doesn't mean that Windows Vista and Windows 7 users also shouldn't apply this patch immediately,” added Miller.

Share

Shavlik NetChk Protect

To simplify and automate critical to perform and manage tasks, IT managers choose Shavlik NetChk Protect, the industry's top solution for lowering operational costs and increasing visibility and control. NetChk Protect simplifies and automates identifying and fixing gaps in 'must do' tasks such as asset discovery, patch management, configuration management, and antivirus + antispyware, resulting in an enterprise that is ready to spend less - time, budget, and IT staff - on these critical to perform and manage tasks across physical systems and virtual machines.

For further information, please contact Doros Hadjizenonos at tel. +27 11 790 2500; fax +27 11 790 2599; e-mail dorosh@securedata.co.za

Shavlik Technologies

Shavlik Technologies is the market leader for simplifying and automating critical-to-perform and manage IT operations including patch management, antivirus + antispyware, configuration management, asset management, and policy and compliance auditing. Shavlik's innovative approach to simplifying and automating enterprise wide system management frees up IT staff for initiatives that grow your business without sacrificing the visibility and control needed to ensure system availability and security.

With thousands of customers worldwide, Shavlik is trusted to provide solutions that can be relied upon to identify gaps and automatically and reliably fix systems that are missing patches or don't conform with the corporate-defined configuration baseline.

SecureData

SecureData is a specialist, value-added distributor of perimeter, application, network, endpoint, storage and identity information security solutions and risk management solutions for the African sub-continent and Indian Ocean islands. A cross-section of the available solutions from SecureData illustrates wide coverage of the following information security and risk management domains: business continuity, security appliances and devices, hardware authentication, identity and access management, security and vulnerability management, secure content management, threat management and security services.

SecureData's information security and risk management solutions include best-of-breed solutions, devices and appliances for the perimeter, data centres, applications, network, endpoints, messaging and Web. In addition, as a value-add to vendor, channel and customer, SecureData also provides a full complement of support, pre-sales and professional services around the solutions positioned in each discrete security vertical.

For more information, visit SecureData at http://www.securedata.co.za.

Editorial contacts