4 ms·
Microsoft issues Internet Explorer zero-day warning
- InclinedPlane 16y agoWhy do people insist on using the term "zero-day"? It means nothing other than an unpatched vulnerability.
- m0nastic 16y agoApparently, the etymology of the term goes back to the Warez days, as mentioned in Jason Scott's (awesome, by the way) Defcon talk: http://vimeo.com/15400820 http://vimeo.com/15400820 While the term means something differed when applied to a vulnerability (the Warez definition comes from how many days after software was released before the crack was available), it's similar.
- deleted 16y ago[deleted]
- dangrossman 16y agoNot quite. It means a vulnerability that was being exploited before the software developer was aware of the exploit. If Microsoft issued a warning about a vulnerability they didn't know was already being exploited, it's not a zero-day exploit. If Mcirosoft was informed of the vulnerability a week ago and it's being exploited today, it's not a zero-day exploit. If Microsoft issued a warning about a vulnerability they already patched but saw being exploited because the patch isn't widely installed yet, it's not a zero-day exploit.
- InclinedPlane 16y agoTell that to everyone using the term "zero-day", they don't seem to be aware.
- mmastrac 16y agoThis one is a guaranteed way to get infected by malware. It even has an active proof-of-concept exploit that will launch arbitrary executables: http://www.exploit-db.com/exploits/15746/ http://www.exploit-db.com/exploits/15746/ Don't let family and friends surf with IE!
- trotsky 16y agoAside from the obvious, if you are responsible for any hosting or internet presence services that have a free option and allow you to serve arbitrary or unsanitized CSS you should probably keep an eye out for people using your platform for drive by attacks.