On CBS.com: Sexy women of CBS
BNET Business Network:
BNET
TechRepublic
ZDNet

July 2nd, 2008

Microsoft to ratchet IE8 security another notch in Beta 2

Posted by Ed Bott @ 10:05 am

Categories: Security, Internet Explorer

Tags: Microsoft Internet Explorer 7, ActiveX Control, Microsoft Corp., Beta, Site, IE8, Microsoft Windows, ActiveX/COM/COM+/DCOM, Phishing, Web Browsers

Sometime in August, Microsoft plans to release Beta 2 of Internet Explorer 8. Yesterday, I spoke with Austin Wilson, Director of Windows Client Product Management at Microsoft, about some of the security-related changes due in this milestone, and got a preview of the changes announced today.

The most noticeable change is the SmartScreen Filter, which replaces the Phishing Filter found in IE7. It uses the same reputation-based filter as its predecessor, but adds a few tweaks to make it easier to spot social engineering attempts. IE8 adds domain highlighting (as shown below) to frustrate phishing attempts that use long, complex URLs to make a link appear to go to a legitimate domain.

Changes to address bar in Internet Explorer 8

Part of the work involves simplifying the interface for displaying potentially dangerous websites. In IE7, for example, the address bar turns yellow when you encounter a suspicious site and red when you attempt to visit a site that is reported as unsafe. In IE8 the yellow bar is gone, replaced by a dialog box. The green address bar for sites that use Extended Validation certificates remains.

When you try to visit a site that is listed in the database of known unsafe sites, the background of the browser window turns blood red and this stern warning appears:

New SmartScreen anti-phishing filter in Internet Explorer 8

The SmartScreen filter in IE8 also extends protection to download attempts, blocking access to servers that are known to be serving up malware

The concepts behind that work should be familiar to anyone who’s used a competing browser, such as the just-released Firefox 3. Corporate customers and security professionals should be more interested in architectural changes designed to block access to vulnerabilities in ActiveX controls and take advantage of Data Execution Prevention features.

The ActiveX changes (some of which were announced in May) allow controls to be locked to a specific site and to be offered on a per-user basis. The former prevents a hostile website from being able to call an existing ActiveX control (such as one installed by the system builder or with another program, or one downloaded from a different, presumably safe web page). The user (or a system administrator, using group policy) has to opt-in to those controls and can lock them for use only on a specific site.

ActiveX controls can also be offered on a per-user basis, bypassing the need for UAC prompts and lessening the possibility that one user can install a control that compromises the entire system or other user accounts.

In IE7, Data Execution Protection is disabled for the browser process by default, primarily for compatibility reasons. IE8 enables DEP on Windows Vista SP1, Windows XP SP3, and Windows Server 2008. As a result, any page or add-in that tries to use a buffer overflow or other exploit to write executable code to an area of memory that is reserved for data will crash that browser tab (but shouldn’t take down other tabs).

Finally, IE8 is designed to protect from some forms of server-based attacks as well. The most noteworthy change is code that blocks common forms of cross-site scripting exploits. According to Wilson, IE8 will detect Type-1 (reflection) attacks and block script from being injected to web a server via URL.

I’ll have a more detailed look at these changes when the beta code is available next month.

Ed Bott is an award-winning technology writer with more than two decades' experience writing for mainstream media outlets and online publications. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 13 Talkback(s)
What a maroon...
Are you saying that from the specification you have seen there are no holes no issues which concern you. Is IE8 going to be a perfectly secure product.

Dude... When will you learn?

THERE IS NO SUCH THING AS A PERFECTLY SECURE PROGRAM! ... (Read the rest)
Posted by: Wolfie2K3 Posted on: 07/03/08 You are currently: Logged In | Log out
Microsoft Press Release martin23   | 07/02/08
Sheesh, Martin Ed Bott  ZDNet | 07/02/08
Some People's Kids dsx1962@...   | 07/02/08
Don't feel that I'm picking on you... dsx1962@...   | 07/02/08
RE: Microsoft to ratchet IE8 security another notch in Beta 2 marks055@...   | 07/02/08
RE: Microsoft to ratchet IE8 security another notch in Beta 2 martin23   | 07/03/08
So what you want is ... Ed Bott  ZDNet | 07/03/08
RE: Microsoft to ratchet IE8 security another notch in Beta 2 martin23   | 07/03/08
You really need to learn Ed Bott  ZDNet | 07/03/08
Ed your right - for once martin23   | 07/03/08
Announcements and analysis Ed Bott  ZDNet | 07/03/08
What a maroon... Wolfie2K3   | 07/03/08
About Talkback moderation Ed Bott  ZDNet | 07/03/08

What do you think?

5 Trackbacks

The URI to TrackBack this entry is:
http://blogs.zdnet.com/Bott/wp-trackback.php?p=484

  • Dew Drop - July 3, 2008
    Silverlight / WPF. Consuming ASMX Web Services with Silverlight 2 (Martin Mihaylov); Composite Application Guidance Is Live (Glenn Block); Updating Silverlight.js (Tim Heuer); Microsoft: Silverlight Is Searchable, Too (Mary Jo Foley) ...

    Trackback by Alvin Ashcraft's Morning Dew — July 3, 2008 @ 12:38 pm

  • Internet Explorer 8 Beta 2 - Will focus on security improvements
    Two recent ZDNet blog posts highlight forthcoming security improvements for the next beta release of IE 8. The release to testers is planned for August. These improvements will make IE8 a worthwhile upgrade when it is released in the ...

    Trackback by Prepare for Corporate Layoffs — July 29, 2008 @ 9:53 pm

  • Internet Explorer 8 Beta 2 - Will focus on security improvements
    The release to testers is planned for August. These improvements will make IE8 a worthwhile upgrade when it is released in the future. Internet Explorer 8 Beta 2 - Will focus on security improvements http://blogs.zdnet.com/security/?p=1396 http://blogs.zdnet.com/Bott/?p=484 QUOTE: When Microsoft's Internet Explorer 8 hits the Beta 2 milestone in August, the browser makeover will feature a full-fledged anti-malware blocker and new protections against some forms of cross-site scripting attacks

    Trackback by Anonymous — August 16, 2008 @ 3:10 am

  • Microsoft to ratchet IE8 security another notch in Beta 2
    Microsoft to ratchet IE8 security another notch in Beta 2 by ZDNet’s Ed Bott — Sometime in August, Microsoft plans to release Beta 2 of Internet Explorer 8. Yesterday, I spoke with Austin Wilson, Director of Windows Client Product Management at Microsoft, about some of the security-related changes due in

    Trackback by Anonymous — August 16, 2008 @ 3:10 am

  • Internet Explorer 8 Beta 2 - Will focus on security improvements
    The release to testers is planned for August. These improvements will make IE8 a worthwhile upgrade when it is released in the future. Internet Explorer 8 Beta 2 - Will focus on security improvements http://blogs.zdnet.com/security/?p=1396 http://blogs.zdnet.com/Bott/?p=484 QUOTE: When Microsoft's Internet Explorer 8 hits the Beta 2 milestone in August, the browser makeover will feature a full-fledged anti-malware blocker and new protections against some forms of cross-site scripting attacks

    Trackback by Anonymous — August 19, 2008 @ 3:13 am

advertisement

Recent Entries

advertisement
Click Here

Archives

ZDNet Blogs

CIO Sessions

advertisement
Click Here