Security Blog

The latest news and insights from Google on security and safety on the Internet

MHTML vulnerability under active exploitation

2011 m. kovo 11 d.
Share on Twitter Share on Facebook
Google

27 komentarai :

Unknown rašė...

Wouldn't a better recommendation be to simply *stop using internet explorer*? It's really sad that Microsoft can't patch issues like this in a far more timely fashion.

2011 m. kovo 12 d. 13:10
Nvrstpnvrstppg rašė...

Is there a pattern to the activists being attacked - what are the issues they're active on, any common thread?

2011 m. kovo 12 d. 13:32
Frej rašė...

That is serious... Now it's not only website developers affected. I hope the day when IE legacy stops casting a bad light over MS is soon to come.

2011 m. kovo 12 d. 14:21
Anonimiškas rašė...

my daughters gmail account was hacked and she was using Internet explorer

2011 m. kovo 12 d. 14:49
Unknown rašė...

Use Google Chrome for the fastest or Firefox for the user friendly experience and don't use IE, we don't.
Fred

2011 m. kovo 12 d. 22:30
plexor rašė...

As I become more paranoid about my safety everywhere, it seems as though the biggest threat is from the Net - or more precisely - the ongoing threat caused by people who use Microsoft products from Browsers to Servers.
The only apparent solution would be to punish people for using these products the way irresponsible people are finally being punished for texting while driving.

2011 m. kovo 13 d. 22:06
Reverend Magdalen rašė...

I second the request for more information about what specific type of activist is being targeted. This information could be vital to protecting people in future. Please share at least the general topic of the activism.

2011 m. kovo 14 d. 03:23
Greg Zeng rašė...

Crippleware (SAFARI, CHROME, CHROMIUM, MOILLA, etc cannot save web pages in one compressed file: mht.

IE & its shells (Cray, Green, Maxthon, etc) probaly are affected by the IE bug as well.

Only truly effective browser is freeware, mistakenly labelled as shareware. It is available on Symbian, Linux, Android, Windows, etc. OPERA.

2011 m. kovo 14 d. 08:44
P J rašė...

@Greg Zeng

That's funny :) Because this is operating system's hole then opera is also affected ;)

2011 m. kovo 14 d. 12:08
Anonimiškas rašė...

@P J I'm pretty sure only internet explorer (all versions, including the ie shells mentioned above) is affected, source: http://www.h-online.com/security/news/item/Microsoft-warns-of-cross-site-scripting-in-Windows-1180179.html

2011 m. kovo 14 d. 13:00
Unknown rašė...

Is it *all* political activists? Is it a campaign against one particular flavor?

2011 m. kovo 20 d. 10:41
vu3mes rašė...

hi

i had two accounts with google mail which i had been using for years now. yesterday i could not access both the accounts and when it was open i had a warning that the accounts were acessessed by an ip no. based in china and duely instructed me to change my passwords. in the inbox i could see the mass mail circualted using my id which was returned non delivered by some addressees.

2011 m. kovo 21 d. 07:02
Anonimiškas rašė...

Why is anyone using Internet Expolder ? Why is google telling people to use a insecure browser in the first place ??? Seriouisly google if you are going to help at least get it right.

2011 m. kovo 21 d. 09:02
Unknown rašė...

internet explorer is targeted because its the most popular browser. if everyone changed to firefox for example, do you think that attacks would suddenly stop? if you do your totally nieve and unrealistic. Internet explorer is popular, and whether you agree with that or not its not good enough to blame microsoft for the actions of those who will attack them. If firefox had the same market share - then firefox would be under attack. Microsoft bashing is all well and good, but at least have a coherant argument!

2011 m. kovo 21 d. 09:07
Unknown rašė...

@Plexor
Are you for real? Punish people for using IE?
People had to use IE in the past, which, quite rightly was fought and won against. Now to punish people for using IE is worse! Say someone uses IE and doen't have a GMail account? Say someone finds a way to hack into ALL browsers, does everyone get punished?
Microsoft are to blame and should be punished, not the users.

Frank.

2011 m. kovo 21 d. 09:25
Unknown rašė...

"We’ve noticed some highly targeted and apparently politically motivated attacks against our users"

China against human-rights activists..?

2011 m. kovo 21 d. 09:32
Unknown rašė...

I've found that any Microsoft product I've used has eventually encountered technical issues. While I understand the price of an iMac or another Apple product can sometimes be prohibitive, I've been using an iMac for several years and encountered very few issues - when I have the issue has been easily resolved. Safari all the way!

2011 m. kovo 21 d. 09:53
Unknown rašė...

i wonder how many microsoft bashers here are actually using a microsoft operating system, and often use other microsoft software...

as far mac's being safe - indeed the are more secure - but again - only because the number of worldwide users are so so much smaller than those using microsoft products. Someone who is set to attack a group of users will obviously go for the largest user base, to cause the most disruption. Macs, safari, firefox are only safe because microsoft is taking the hit for you, not because the software or hardware is any better or more intelligently created. Im well aware of microsofts shortfalls, but i think everyone should imagine a world without microsoft products, sure there linux and all the different flavours thereof, but can you seriously imagine most of the population trying to be productive on a unix box?? absolutly wony happen. unix and linux are excellent - for specific uses. for a user friendly, easy to learn based market- no they arent fit for that purpose.

2011 m. kovo 21 d. 10:52
卢海玲 rašė...

Chinese government is becoming the new hidden Nazi now. It is torturing ,murdering and fooling its own ordinary citizen inside china. It has more than a quarter of a million internet polices doing all kinds of attacks, stealing info from other countries. The Chinese government is the biggest hiker organization in the world, it going to rule the world by its Mafia rules. All the west countries should work together to fight with it now in order to save everyone include chinese in the world.

2011 m. kovo 21 d. 11:47
Unknown rašė...

Why use gmail? It seems gmail is targeted cause it weak. I have 1 hotmail and 2 yahoo accounts.

2011 m. kovo 21 d. 12:47
Unknown rašė...

@ James,

Safari is not any more secure than other browsers - people simply don't target it like IE is targeted. At PWN2OWN a MacBook Pro was hacked in 5 seconds via a Safari security hole.

http://news.themacfeed.com/2011/03/safari-security-hole-in-only-5-seconds/

2011 m. kovo 21 d. 13:02
amdgangster@gmail.com rašė...

People in China(here) use gmail because they belive the service of the world's best company is reliable.Google people ,please don't let us down.People may be put in a black jail because they offended the system,that's not a joke.I just don't know where the history is aheading...Anyway,we enjoyed youtube through自由门very much...the world is awesome!

2011 m. kovo 21 d. 20:34
rpr rašė...

Bob said: "internet explorer is targeted because its the most popular browser ... If firefox had the same market share - then firefox would be under attack."

Have a look at http://en.wikipedia.org/wiki/Usage_share_of_web_browsers The page says that in Feb 2011 the usage shares of most popular browsers were: IE 43.55%, FF 29%, Chrome 13.89%. So, the popularity of IE is not much larger than that of FF, but still IE is much more exploited for cyber attacks. I conclude that IE is much more vulnerable.

2011 m. kovo 25 d. 14:32
Unknown rašė...

in the past day i had to change my password 3-4 times, somebody is accessing my e-mail and signing up for things, one that i know of so far. who is finding my passwords and not allowing me on unless i change it every time?
please help, i'm sick of it.

2011 m. kovo 29 d. 22:26
GP rašė...

You can't blame users for using the standard browser shipped with the OS. We should have some kind of a regulatory body that has the authority to fine companies for security vulnerabilities in their products. You can't just make people agree to a long list of terms and conditions and then not take responsibility for your incompetency.

2011 m. balandžio 1 d. 13:32
Jon Carnes rašė...

Bob - you live in a dream world. Me telling you that won't change you though as you have massively consumed the MS kool-aid.
My company is 90% Unix/Linux and the users don't have any issues with the technology. Most of them don't even *know* they are running Linux.

2011 m. balandžio 9 d. 10:25
Srk9 rašė...

gp, the answer here is for people to stop using Windows. Google should encourage people to use modern operating systems that have package managers like Ubuntu Linux.

2011 m. birželio 3 d. 18:47

Rašyti komentarą

  

Etiketės


  • #sharethemicincyber
  • #supplychain #security #opensource
  • AI Security
  • android
  • android security
  • android tr
  • app security
  • big data
  • biometrics
  • blackhat
  • C++
  • chrome
  • chrome enterprise
  • chrome security
  • connected devices
  • CTF
  • diversity
  • encryption
  • federated learning
  • fuzzing
  • Gboard
  • google play
  • google play protect
  • hacking
  • interoperability
  • iot security
  • kubernetes
  • linux kernel
  • memory safety
  • Open Source
  • pha family highlights
  • pixel
  • privacy
  • private compute core
  • Rowhammer
  • rust
  • Security
  • security rewards program
  • sigstore
  • spyware
  • supply chain
  • targeted spyware
  • tensor
  • Titan M2
  • VDP
  • vulnerabilities
  • workshop


Archive


  •     2026
    • bal.
    • kov.
    • vas.
    • saus.
  •     2025
    • gruod.
    • lapkr.
    • spal.
    • rugs.
    • rugp.
    • liep.
    • birž.
    • geg.
    • bal.
    • kov.
    • vas.
    • saus.
  •     2024
    • gruod.
    • lapkr.
    • spal.
    • rugs.
    • rugp.
    • liep.
    • birž.
    • geg.
    • bal.
    • kov.
    • vas.
    • saus.
  •     2023
    • gruod.
    • lapkr.
    • spal.
    • rugs.
    • rugp.
    • liep.
    • birž.
    • geg.
    • bal.
    • kov.
    • vas.
    • saus.
  •     2022
    • gruod.
    • lapkr.
    • spal.
    • rugs.
    • rugp.
    • liep.
    • birž.
    • geg.
    • bal.
    • kov.
    • vas.
    • saus.
  •     2021
    • gruod.
    • lapkr.
    • spal.
    • rugs.
    • rugp.
    • liep.
    • birž.
    • geg.
    • bal.
    • kov.
    • vas.
    • saus.
  •     2020
    • gruod.
    • lapkr.
    • spal.
    • rugs.
    • rugp.
    • liep.
    • birž.
    • geg.
    • bal.
    • kov.
    • vas.
    • saus.
  •     2019
    • gruod.
    • lapkr.
    • spal.
    • rugs.
    • rugp.
    • liep.
    • birž.
    • geg.
    • bal.
    • kov.
    • vas.
    • saus.
  •     2018
    • gruod.
    • lapkr.
    • spal.
    • rugs.
    • rugp.
    • liep.
    • birž.
    • geg.
    • bal.
    • kov.
    • vas.
    • saus.
  •     2017
    • gruod.
    • lapkr.
    • spal.
    • rugs.
    • liep.
    • birž.
    • geg.
    • bal.
    • kov.
    • vas.
    • saus.
  •     2016
    • gruod.
    • lapkr.
    • spal.
    • rugs.
    • rugp.
    • liep.
    • birž.
    • geg.
    • bal.
    • kov.
    • vas.
    • saus.
  •     2015
    • gruod.
    • lapkr.
    • spal.
    • rugs.
    • rugp.
    • liep.
    • birž.
    • geg.
    • bal.
    • kov.
    • vas.
    • saus.
  •     2014
    • gruod.
    • lapkr.
    • spal.
    • rugs.
    • rugp.
    • liep.
    • birž.
    • bal.
    • kov.
    • vas.
    • saus.
  •     2013
    • gruod.
    • lapkr.
    • spal.
    • rugp.
    • birž.
    • geg.
    • bal.
    • kov.
    • vas.
    • saus.
  •     2012
    • gruod.
    • rugs.
    • rugp.
    • birž.
    • geg.
    • bal.
    • kov.
    • vas.
    • saus.
  •     2011
    • gruod.
    • lapkr.
    • spal.
    • rugs.
    • rugp.
    • liep.
    • birž.
    • geg.
    • bal.
    • kov.
    • vas.
  •     2010
    • lapkr.
    • spal.
    • rugs.
    • rugp.
    • liep.
    • geg.
    • bal.
    • kov.
  •     2009
    • lapkr.
    • spal.
    • rugp.
    • liep.
    • birž.
    • kov.
  •     2008
    • gruod.
    • lapkr.
    • spal.
    • rugp.
    • liep.
    • geg.
    • vas.
  •     2007
    • lapkr.
    • spal.
    • rugs.
    • liep.
    • birž.
    • geg.

Feed

Follow
Give us feedback in our Product Forums.
  • Google
  • Privacy
  • Terms