Posts Tagged ‘Internet Explorer’

After day 1 of Pwn2Own, web browsers appear to have taken a big hit, but Google’s Chrome appears to have come out unscathed.

It didn’t take long, with Safari 4 on Mac OS X Snow Leopard the first victim thanks to the work of Charlie Miller. Millers set up a remote exploit at a web site through which a conference organisers MacBook was taken control after surfing to it.

Internet Explorer 8 on Windows 7 was next, with a similar exploit allowing Peter Vreugdenhil to take control of an organisers laptop once they browsed to a website with the infected code.

Firefox 3 was also exploited on Windows 7 using a memory corruption vulnerability, with another exploit that allows a remote attacker access to a users PC.

Both Opera and Google Chrome were not hacked, with Charlie Miller stating “there are bugs in Chrome but they’re very hard to exploit. I have a Chrome vulnerability right now but I don’t know how to exploit it. It’s really hard. They’ve got that sandbox model that’s hard to get out of. With Chrome, it’s a combination of things — you can’t execute on the heap, the OS protections in Windows and the Sandbox.”

All systems were patched and updated to their latest versions, with the exploits used to remain a secret until browser makers can update their browsers.

Microsoft has clearly been heard at work, and announced today at MIX10 the availability of Internet Explorer 9 “test drive” (IE9) Developer Preview.

The browser, which is clearly still in its early stages, is missing the expected Internet Explorer interface such as tabs and address bar, but it does allow users to test and see the new JavaScript and rendering engine in action.

Available at ietestdrive.com, the browser includes support for some HTML5 and CSS3 features, including the new video element and CSS3 border radius tags.

Video tag support appears to be limited to the H.264 and MPEG4, while audio is limited to MP3 and AAC, totally ignoring the OGG format for both video and audio.

Microsoft really seems to be pushing standards compliance, and performance with this relase, and it shows. While not perfect, the browser is already leaps and bounds ahead of its predecessor, IE8. With the aid of the new JavaScript engine (codenamed Chakra), the early release browser is able to complete the SunSpider JavaScript benchmark test with a score of 598.80, slightly faster than Firefox 3.6. The browser also scores 55/100 in the ACID3 test, while IE8 only scores 20/100.

Internet Explorer 9 will be limited to only Windows Vista and Windows 7 users, while XP users will miss out on release.

All round, Microsoft really seem to be putting in a lot of effort with Internet Explorer 9, and it really shows. The Internet Explorer 9 “test drive” is available from the Internet Explorer 9 Test Drive website.

Microsoft has announced that it has discovered a new zero-day exploit in Internet Explorer.

The vulnerability is being exploited in the wild, and allows remote malicious code to install itself on a users system.

Currently, it appears only Internet Explorer 6 and 7 are affected while Internet Explorer 8 is safe this time around.

No word from Microsoft on when we will see a patch, but users are urged to upgrade to Internet Explorer 8 to protect them from the current vulnerability.

After reports two weeks ago that Microsoft’s Browser Ballot screen for the European Union was not as random as first seemed, Microsoft have updated the algorithm used to determine a browsers random position.

“We can confirm that we made a change to the random icon order algorithm in the browser choice screen for Europe,” said Microsoft spokesman Kevin Kutz.

IBM software architect Rob Weir who has been testing the randomness of the browser screen said he noticed a change last week. “Sometime last week — I don’t know the exact date — Microsoft updated the code for the browser choice website with a new random shuffle algorithm” Weir wrote on his blog.

From Weir’s early testing, the update appears to have solved the problem, with each browser now just as likely to appear in position number one.

Weir has created a test page, where users are able to test the ballot screens randomness for themselves.

Microsoft is looking to push Internet Explorer 9 at this years MIX conference, with a Customer Technology Preview build of the browser expected to be released to the public at the same time.

Two sessions at MIX 2010 give clues as to what we might see in the new browser; HTML5 Now: The Future of Web Markup Today and Future of Vector Graphics for the Web.

“Couple these clues with a post from the IE team on its official blog late last year about increased JavaScript rendering speeds and CSS support, and the team’s recent push to provide better support for SVG graphics and animations, it looks like IE 9 will present a huge step forward for Microsoft into the realm of HTML5, CSS 3 and other modern technologies that drive the most forward-thinking web apps” wrote Scott Gilbertson.

This is good news for browser users, with signs that Microsoft is taking its falling browser market share seriously. It suggests Microsoft are trying to bring the browse back to the forefront of browser technology, something we have not seen since the release of Internet Explorer 6 back in 2001.

After news last week that Google will be removing support for Internet Explorer 6 in its Google Sites and Google Apps applications, a spokesperson from Google has also confirmed to ComputerWorld that the company also plans to drop support for IE6 from Gmail.

“We plan to stop supporting older browsers for the rest of the Google Apps suite, including Gmail, later in 2010,” said a Google spokesman.

The move seems a little risky, with Internet Explorer 6 still holding 20% of the browser market according to statistics from Market Share by Net Applications.

Microsoft has also weighted in on the debate. “We support this recommendation to move off Internet Explorer 6,” said Microsoft spokesman Brandon LeBlanc.

Full repercussions of this decision will not be known until later in this year when Google offically drops IE6 support. It is hoped that this move could help speed up the rate in which corporations are moving to newer versions of Windows and Internet Explorer.

A cut-off date for Internet Explorer 6 is still not known.

Microsoft’s Internet Explorer is again at risk, just days after the company closed another serious security flaw in its web browser.

A new security advisory was posted by Microsoft last Wednesday, notifying users of a potential flaw in Internet Explorer which could allow third-parties access to data.

“Our investigation so far has shown that if a user is using a version of Internet Explorer that is not running in Protected Mode an attacker may be able to access files with an already known filename and location” said the advisory from Microsoft.

At this stage, there are no reported attacks using this vulnerability, but it is bound to be only a matter of time.

A patch is expected in a few days, on Tuesday 9th February 2010.

Time appears to slowly be running out for Microsoft’s Internet Explorer 6 (IE6), as Google has announced plans to drop support for the browser in its Google Sites and Google Docs applications.

“Many other companies have already stopped supporting older browsers like Internet Explorer 6.0 as well as browsers that are not supported by their own manufacturers” said Google Apps Senior Product Manager Rajen Sheth.

Not to feel left out, Google is also dropping support for Firefox 2, Chrome 3, and Safari 2.

“While you’ll still be able to access these Google applications, newer features may not be available and some features may even stop working” said Sheth.

Support for these older browsers is due to end on March 1st. Web users are urged to upgrade their web browsers before this time.

Microsoft has filled a patent that reveals it is looking at revamping the tabbed browsing experience with Internet Explorer 9.

The patent appears to be an enhancement of the quick tabs found in IE8,which allows users to see all tabs and close them individually. This parent covers:

  • Drag and move the tabs within the Quick Tabs interface.
  • Tab thumbnails will enlarge on mouse-hover.
  • In case your tab row was over flowing with tabs and in Quick Tabs you were to hover the mouse on a tab not currently visible on the tab bar, the overflow icons would change appearance.

Will it be enough to stop IE from loosing market share? Only time will tell.

A technical preview of Internet Explorer 9 is expected by mid March 2010.

Much faster than originally expected, Microsoft have released a patch to address the vulnerability found in all versions of Internet Explorer.

“This security update resolves seven privately reported vulnerabilities and one publicly disclosed vulnerability in Internet Explorer. The more severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights” said a note from Microsoft.

The update includes fixes for IE5.01, IE6, IE7, and IE8 on platforms from Windows 2000 to the newely released Windows 7.

The updated is rated critical and will be pushed out to all users who have Windows Update turned on. Alternatively, system administrators can find out more information plus download links in the Security Bulletin MS10-002.