IE unsafe for three-quarters of 2006
By Rene Millman,
Internet Explorer was unsafe to use for over three-quarters of the year, according to a security researcher.
Research carried out by Brian Krebs found that for 284 days in 2006, Microsoft's browser remained unpatched.
"For a total 284 days in 2006 (or more than nine months out of the year), exploit code for known, unpatched critical flaws in pre-IE7 versions of the browser was publicly available on the internet," he said on his blog.
"Likewise, there were at least 98 days last year in which no software fixes from Microsoft were available to fix IE flaws that criminals were actively using to steal personal and financial data from users."
He said there were ten cases last year where instructions detailing how to leverage "critical" vulnerabilities in IE were published online before Microsoft had a patch to fix them.
He said the situation contrasted with that of Firefox where this browser experienced a single period lasting just nine days last year in which exploit code for a serious security hole was posted online before Mozilla shipped a patch to remedy the problem.
Krebs said criminals specialising in internet fraud continued to ply much of their trade with the aid of security flaws in the Microsoft browser last year. In late December 2005, experts tracked organised criminals hacking into sites and seeding them with code that installed password-stealing spyware on machines used by anyone who merely visited the sites with IE.
"Microsoft initially downplayed the severity of the attacks, until it became clear that the threat was fairly widespread and that thousands of customers had already been attacked in the span of a few days," said Krebs. "The threat was seen as so severe that a large number of security experts urged users to download and install a patch produced by a third party until Microsoft developed an official fix."
You may also like...
advertisement
Latest Security Features
Q&A: The ID card commissioner talks cards and controversy
We spoke to ID card commissioner Sir John Pilling about his thoughts on the identity scheme and why we might all think he's a bit of prat down the line.
- So you've been hacked, now what?
- The problems facing Internet Explorer
- Year in Review: 2009 in your words
- Top 10 security predictions for 2010
- Year in Review: Top tech stories of 2009
- The worst IT disasters of 2009
- Five free security software suites
- How to stay safe shopping online
- Is it time to switch to IPv6?
Latest Security Reviews
Symantec Backup Exec 2010 review
Rating: ![]()
advertisement
Most popular
- Your Views: Google Street View across the UK
- Reviews round-up: Windows Phone 7 and Firefox Mobile
- Q&A: Conrad Wolfram on communicating with apps in Web 3.0
- Why is Microsoft accelerating Service Pack 1?
- Palm 'disapointed' by results, Pre sales
- Google updates Chrome, awards security bonus
- Report: Macs cost less to run than Windows PCs
- A guide to BlackBerry Messenger 5.0
- Windows Phone 7 review ? hands on
- HTC Legend review
Latest News Videos in Security
Video: Why security is everybody's responsibility
Rik Ferguson, senior security advisor at Trend Micro says it's up to all of us to make security work.
Whitepapers
Want more background on today's hottest IT trends?
Visit IT PRO's whitepaper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





