Snails - Response on Threads Part 5

Status
Not open for further replies.

AttyPops

Vaping Master
ECF Veteran
Jul 8, 2010
8,708
135,218
Hc Svnt Dracones - USA EST
Roly, posted this thread and said if you can load the test site and it says vunerable, your browser is vunerable when making purchases online. I tried the test and I'm VUNERABLE. What should I do?

here's the thread:http://www.e-cigarette-forum.com/fo...heck-your-browser-security-freak-exploit.html

Microsoft is working on a fix. There were no active exploits in the wild that anyone know of. However, now that the word is out, there could be some NOW. So....NOW is the time to be careful. Don't go to sites where you have to put in sensitive information until the fix comes out.

Also, it's a browser thing too. So make sure you also update your browser.

The other OS makers (not windows) may already have a fix out. Depends on the OS I guess.
 

Sgt. Pepper

Vaping Master
ECF Veteran
Verified Member
Jan 10, 2011
4,192
51,221
I have windows 7 and I'm using IE as my browser. Microsoft says to do this while they are working on a fix:

Apply Workarounds

Workarounds refer to a setting or configuration change that does not correct the underlying issue but would help block known attack vectors before a security update is available.
• Disable RSA key exchange ciphers using the Group Policy Object Editor (Windows Vista and later systems only)

You can disable the RSA key exchange ciphers in Windows Vista and later systems by modifying the SSL Cipher Suite order in the Group Policy Object Editor.

To disable the RSA key exchange ciphers you have to specify the ciphers that Windows should use by performing the following steps:
1.At a command prompt, type gpedit.msc and press Enter to start the Group Policy Object Editor.
2.Expand Computer Configuration, Administrative Templates, Network, and then click SSL Configuration Settings.
3.Under SSL Configuration Settings, click the SSL Cipher Suite Order setting.
4.In the SSL Cipher Suite Order pane, scroll to the bottom of the pane.
5.Follow the instructions labeled How to modify this setting, and enter the following cipher list: it's a long list of stuff that I'm not going to attempt to do.:facepalm:
 
Last edited:

Sgt. Pepper

Vaping Master
ECF Veteran
Verified Member
Jan 10, 2011
4,192
51,221
Microsoft is working on a fix. There were no active exploits in the wild that anyone know of. However, now that the word is out, there could be some NOW. So....NOW is the time to be careful. Don't go to sites where you have to put in sensitive information until the fix comes out.

Also, it's a browser thing too. So make sure you also update your browser.

The other OS makers (not windows) may already have a fix out. Depends on the OS I guess.

thanks, atty. I posted a fix that Microsoft is suggesting, but I think i'll hold off trying to buy something for now online. I assume it won't take too long for Microsoft to get the fix.
 

Sgt. Pepper

Vaping Master
ECF Veteran
Verified Member
Jan 10, 2011
4,192
51,221
safe with xp pro ;)



pepper, what are you still doing with ie? :?:

a safe browser is your best defense atm and chrome, ff are deemed to be safe unless you run the wrong 3rd part add-ons ;)

because I like IE and its homepage. Plus, I use a email account from MS... that I pay for yearly. I've tried other browsers, but I don't like them. What can I do?
 
Last edited:

AttyPops

Vaping Master
ECF Veteran
Jul 8, 2010
8,708
135,218
Hc Svnt Dracones - USA EST
OK. Look....

IE is the most hacked browser out there. You can debate if it's truly the most vulnerable, or just the most targeted.
It is the FIRST one they go to for exploit testing. Maybe that's because it uses a lot of internal Windows stuff that the other browsers don't. Maybe it's because MS is a big target and IE comes pre-installed with Windows. Maybe it's because ______.

I don't just put all the blame on MS...heck, they've tried to plug holes...but facts are facts. They (MS) are even switching to a brand-new from scratch browser and dumping IE in the future. Trying to save face.

So I blame the hackers for sure. 99% of their fault. But hackers exist. And thus...as MS's IE is a favorite target...I use FF or chrome. I pretty much only use IE to install FF on a new OS.

That's my :2c:

The best way to avoid a punch is "Don't be there".
 

tiburonfirst

They call me 'Tibs"
ECF Veteran
Verified Member
Feb 23, 2010
26,883
260,375
because I like IE and its homepage. Plus, I use a email account from MS... that I pay for yearly. I've tried other browsers, but I don't like them. What can I do?

lol - download ff and have it ready in case you see something you absolutely gotta have :D

or stay solely with ie and save lots of money! :lol: because you better not do any ordering ;) ooops - and let's hope you don't do any online banking ..........
 
Status
Not open for further replies.

Users who are viewing this thread