Anonymous threatens and warns to take the U.S. ‘off the cyber map’
By : Sachin Kumar Sahu
Anonymous was praised for its recent cyberattacks on North Korea,
however the hacking collective has shown that it is a friend to no one.
The group late last month declared its latest target and this time it
isn’t a communist regime or oppressive government, but rather the United
States. The group stated that on May 7th, Anonymous will start phase 1 of Operation USA,
which is a response to acts of “multiple war crimes in Iraq,
Afghanistan, Pakistan” and “in your own country.” The group is
protesting the Obama Administration’s uses of targeted drone attacks
that have resulted in the deaths of “hundreds of innocent children and
families.”
“Anonymous is speaking it’s mind, don’t try to blind the worlds eyes,” the group wrote in a message on PasteBin.
“We have a voice that we will use, you tried to take from us with the
power you abused. You will lose that power by the time Anonymous is done
with your nation. Your intentions are ill in aim. The Internet hate
machine has came [sic] from our shadows shining light on corruption and
having Lulz, and now United States of America, you are in the cross
hairs of Anonymous.”
Operation USA, or OpUSA, threatens to take America “off the cyber
map” with several “doxes, DNS attacks, defaces, redirects, DDOS attacks,
database leaks and admin take overs.” The group hints that its first
targets will be major banks, suggesting people switch “from a big bank
to a local union.” Individuals associated with Anonymous even claim to
have accessed Michelle Obama’s social security number, although no proof
of the incident was provided.
The Department of Homeland Security acknowledged that a group of
mostly Middle Eastern and North African-based criminal hackers were
preparing to attack several high-profile U.S. websites, although such
attacks may be no more than a public nuisance.
Anonymous has threatened various government agencies including the
FBI, NSA and NATO, along with banking websites belonging to Bank of
America, Chase, Citi, Wells Fargo and Capital One.
- Via: www.cnbc.com, www.bgr.com
- Source: Anonymous [1], Anonymous [2]
Facebook Purchases Parse To Offer Mobile Development Tools
By : Sachin Kumar Sahu
Facebook has just acquired Parse, marking its entry into a whole new business category: paid tools and services for developing mobile apps.The company is buying the mobile-backend-as-a-service startup (yes, the industry acronym is mBaaS) in a deal that we’ve heard is worth $85 million. [Update: And we're hearing that excludes retention.] Neither company is commenting on the size of the deal, except that Facebook said it’s not “material.”
Parse was
founded about two years ago by a small group of seasoned Googlers and Y
Combinator alums who got together to build a useful set of back-end
tools for mobile developers. They originally called their back-end
service, the “Heroku” of mobile in a homage to what was one of YC’s
biggest exits to date — the $212 million sale of Heroku to
Salesforce.com. They offer services that help mobile developers store
data in the cloud, manage identity log-ins, handle push notifications
and run custom code in the cloud.Facebook won the deal amid what we’ve heard was a competitive process with many of other Valley’s other biggest potential buyers. Parse CEO and co-founder Ilya Sukhar said that he chose Facebook over other suitors — without naming names — because the company was a better cultural fit.
“I don’t think any of the other conversations created anywhere near the excitement level that we had for Facebook,” he said in an interview.
Why Parse? Facebook is in a big push to become more relevant than ever to mobile developers. It doesn’t own its own mobile OS like Apple or Google. It doesn’t make its own devices.
Instead, it’s a horizontal social and identity layer that runs through thousands of apps of iOS and Android, in deep custom integrations in devices made by hardware makers like HTC, and in its latest project, Facebook Home.
In that sense, Facebook has to prove value to mobile developers in other ways. Facebook integrations can make apps stickier when users add friends, and the company’s mobile app install ads help developers acquire new users.
Now
through the Parse deal, the company will be able to offer back-end
services for data storage, notifications and user management. This is a brand new kind of revenue stream for Facebook,
as the company is keeping Parse’s freemium revenue model. Parse
currently has over 60,000 apps and roughly the same number of
developers. They focus on monetizing the top 10 percent of their
clientele.“This fills out one of the pillars of Facebook platform that we’ve been thinking about for awhile,” said Facebook’s Director of Product Management Doug Purdy. “Since 2007, the Facebook platform has been about being an identity mechanism with sharing. But over the course of the last six months, we’ve been thinking about how we can help applications get discovered and how they can be monetized.”
He added, “In order to provide the best experience possible, developers also need to build a whole host of infrastructure. Parse is a natural fit. They’ve really just abstracted away a lot of the work necessary to get an app up and running.”
The deal is a big exit for Parse, which had raised just $7 million to date from investors including Ignition Partners, Start Fund, Google Ventures, Menlo Ventures, SV Angel, Data Collective, Yuri Milner, Aaron Iba, Garry Tan, Justin Kan, Chris Fanini, Sean Knapp, Don Dodge and David Rusenko.
As for Parse users, the company says apps won’t be affected in any way, that developers won’t have to integrate Facebook and that existing contracts will be honored. Parse has a freemium model with a basic free version for up to 1 million requests or pushes per month and a limit of 20 bursts per second. A lowest paid version is $199 a month with 15 million requests a month, 5 million pushes per month and a burst limit of 40 per second. Then there’s an enterprise version where the rates are negotiable.
In the long-run, by getting closer to the development process Facebook could increase the likelihood that third-party apps integrate with them and buy their ads. When added to the direct fees Facebook will collect from Parse subscribers, the acquisition could become a critical part of how Facebook earns money from the burgeoning app economy.
Parse has come a long way. In just under two years, we’ve gone from a rough prototype to powering tens of thousands of apps for a very broad spectrum of customers.And here’s Facebook’s statement from Director of Product Management Doug Purdy:
Some of the world’s best brands trust us with their entire mobile presence, and a growing number of the world’s brightest independent developers trust us with their next big thing. We couldn’t be happier.
As stewards of a good thing, we’re always thinking about the next step in growing Parse to become a leading platform in this age of mobile apps.
These steps come in all sizes. Most are small and incremental. Some are larger. Today we’re excited to announce a pretty big one.
Parse has agreed to be acquired by Facebook. We expect the transaction to close shortly. Rest assured, Parse is not going away. It’s going to get better.
We’ve worked with Facebook for some time, and together we will continue offering our products and services. Check out Facebook’s blog post for more on this.
Combining forces with a partner like Facebook makes a lot of sense. In a short amount of time, we’ve built up a core technology and a great community of developers. Bringing that to Facebook allows us to work with their incredible talent and resources to build the ideal platform for developers.
We think this is the right way to accomplish what we set out to do. We’re excited about the future of Parse!
Ilya, Kevin, and James
Last week, we hosted our first Mobile Developer Conference, where we launched several new products to help mobile developers integrate Facebook: Open Graph for mobile, better Facebook Login, and new developer tools. Today, we’re making it even easier to build mobile apps with Facebook Platform by announcing that we have entered into an agreement to acquire Parse, a cloud-based platform that provides scalable cross-platform services and tools for developers.The buy seems largely motivated by Facebook's continued interest in conquering mobile, an effort that recently culminated in the release of Facebook Home. Parse provides the social network with a new way to go about its mobile-first mission; it offers the company instant access to a pool of mobile developers who might be more motivated to weave Facebook hooks into their applications. Facebook also will, by continuing to sell and manage Parse's backend services, pick up an entirely new revenue stream and become a service provider of a different kind.
By making Parse a part of Facebook Platform, we want to enable developers to rapidly build apps that span mobile platforms and devices. Parse makes this possible by allowing developers to work with native objects that provide backend services for data storage, notifications, user management, and more. This removes the need to manage servers and a complex infrastructure, so you can simply focus on building great user experiences.
We’ve worked closely with the Parse team and have seen first-hand how important their solutions and platform are to developers. We don’t intend to change this. We will continue offering their products and services, and we’re excited to expand what Facebook and Parse can provide together.
Parse offers a free plan for developers with smaller application audiences, but sells a paid service that starts at $199 per month.
Source :- www.developers.facebook.com, www.techcrunch.com, www.news.cnet.com
Anonymous hacker's bring down North Korean websites for a second time in a week
By : Sachin Kumar Sahu
Hackers associated with the group Anonymous earlier this month demanded that North Korean leader Kim Jong Un step down from power and adopt democracy. The demands went unanswered and the group has subsequently launched a variety of attacks aimed at North Korea’s online properties. Hackers defaced social media accounts and other websites belonging to Pyongyang and mocked Kim Jong Un with images associating him with a pig. Now, for the second time in less than two weeks, Anonymous members have taken down nearly a dozen new North Korean websites.
In an earlier attack, Anonymous hackers were able to seize control of
North Korea’s Twitter and Flickr accounts, although the latter has
since been deleted. Members have continued to post on the Twitter
account, however, suggesting that North Korean officials have not yet
regained control.
Central news and information site Uriminzokkiri has once again been taken offline, as well as English language news sites minjok.com, jajusasang.com and paekdu-hanna.com. A handful of other North Korean websites were also defaced with the photoshopped image of Kim Jong Un used in earlier attacks.

Anonymous members perviously claimed to have stolen more than 15,000 passwords from Uriminzokkiri users. In an earlier statement, the group revealed that it was working with “operatives” inside North Korea who are aiding in its attacks. As tensions between the U.S., South Korea and North Korea reach an all time high, the hacking collective has vowed to initiate additional cyberattacks in the coming weeks.
Source :- www.bgr.com
Tomb Raider : The Game : 2013
By : LAKSHAYTomb Raider : The Game
The Good
- Story believably builds Lara up from unsure academic to confident adventures.
- Fascinating setting with a rich sense of history
- Intense combat that offers a good deal of flexibility
- Controls make physically overcoming the island's terrain a pleasure
- Good assortment of tombs to raid, relics to collect, and puzzles to solve.
The Bad
- Forgettable multiplayer component
- Outside of Lara's character arc, story is predictable.
When adventurer extraordinaire Lara Croft raided her first tomb back in 1996, she brought with her an exhilarating feeling of isolation and discovery. Over the years, Lara has continued to venture into parts unknown, taking dark turns and frequently tangling with the supernatural as the series evolved alongside the burgeoning third-person action adventure genre. The gameplay of this series reboot takes a few cues from a current titan of the genre--Nathan Drake and the Uncharted series--but don't let that familiarity put you off. This origin story is a terrific adventure that balances moments of quiet exploration with plenty of rip-roaring action to keep you enthralled from start to finish.
As Tomb Raider begins, Lara is more an academic than an adventurer. But when she's shipwrecked on an island full of ancient secrets and deadly cultists, she has little choice but to learn how to survive. Lara endures a great deal of punishment early in the game, and though no small amount of that anguish is physical, it's an unpleasant moment in which a man tries to force himself on her that's most harrowing. But as unpleasant as it is, it marks an important turning point in Lara's understanding of just how hard she has to fight to survive. Rather than crumbling under the weight of her physical and emotional struggles, she emerges from them a stronger person.
It's empowering to witness Lara's journey from the understandably fearful individual she is when she first arrives on the island to the justifiably confident survivor she becomes. Later in the game, when she has proven to the resident cultists that she's not the easily cowed person they mistook her for, she turns the psychological tables on them, letting loose battle cries to strike fear into their hearts. Aspects of the story that fall outside of Lara's character arc aren't as strong; there's a twist of sorts that occurs late in the game that you see coming hours ahead of time, for instance, and the central villain offers little in the way of nuance. But as an introduction to the legendary Lara Croft, Tomb Raider's tale is a success; she emerges as a strong, charismatic and human figure, and you're left eager to see what the future holds for her.
![]() |
| You'd better get used to killing fast, Lara. You're gonna be doing a lot of it. |
Lara's origin story deserves an extraordinary setting, and the island where Tomb Raider takes place does not disappoint. Centuries ago, it was home to a kingdom called Yamatai. Many shrines, temples, statues and other remnants of that history remain, and often, you just want to take in these places, slowly advancing through the darkness, eager to discover what's just outside the light of your torch. The island is a beautiful place, but not every discovery is a pleasant one; Yamatai's dark history is vividly communicated in piles of bones and far more grisly things. On the PC, the lovely sights are even lovelier and the horrifying sights are more horrifying than on consoles. The PC port was handled by Nixxes, and just as their PC release of Sleeping Dogs improved significantly on the visuals of the console versions, the sharp textures in Tomb Raider's PC release make it the definitive way to experience this game.
The ancient structures of Yamatai now coexist alongside bunkers built during World War II, the wreckage of planes brought down by the storms that surround the island, and the shantytowns and makeshift machinery of the island's current inhabitants. It's a fascinating hodgepodge of the beautiful and the utilitarian; the buildings are believably nestled in their rough natural surroundings, and appear appropriately weathered, damaged, and rusty. The island really feels like a place where people have lived and where great and terrible things have happened. It's a place with many facets; it has claustrophobic caverns and breathtaking vistas, and phenomena like gentle snowfalls, torrential downpours, and fierce, howling winds make it alternately seem like a tranquil place, and a brutal one.
![]() |
| You can enable TressFX if you want to see Lara's hair behave in mysterious ways. |
It's immediately clear that one thing the island is not is safe, so it's a good thing that Lara soon gets her hands on a bow. You acquaint yourself with using it by hunting animals; Lara doesn't have hunger levels you need to manage or any such thing, but the deer, rabbits, crabs and other creatures that call the island home make it feel much more alive. For reasons of their own, the cult that currently occupies the island doesn't exactly welcome you with open arms, so it's not long before you need to turn that bow (and, soon, a pistol, rifle, and shotgun) on humans. Combat is varied and suspenseful; some situations give you the opportunity to take a stealthy approach, sneaking up behind enemies to perform silent kills, or firing arrows into walls to distract them and picking them off from a distance with well-aimed arrows while their comrades aren't looking. During one particularly tense battle in a fog-shrouded forest, patrolling foes hunt you with flashlights; if you can manage to stay unseen, you can shift from prey to predator, using their cones of light to pinpoint their positions and eliminating them one by one.
Then, there are the all-out firefights. When your presence is known, enemies are smart and aggressive about flushing you out from cover with grenades and Molotovs, which forces you to keep moving and act boldly. Many enemies attack from a distance while others get in close, so you need to be constantly on your toes, switching between your weapons on the fly and evading foes who attack with melee weapons. Dodging and countering melee attacks is easy, but the savage animations of Lara's counters make eliminating those foes who make the mistake of getting too close to you consistently satisfying.
Source :- www.wikipedia.com, www.asia.gamespot.com,
DmC-Devil May Cry Review
By : LAKSHAYThe character action genre hasn't been this stylish or crazy in a good long while
![]() |
| There's enough combat variety here to support multiple playthroughs. |
To be fair, on paper, everything about Devil May Cry sounds like the tritest video game pap: a bloody war between angels and devils, endless hordes of demonic enemies straight from your favorite '80s heavy metal album art, and all of it punctuated by Scandinavian "hellektro" outfit Combichrist's thudding soundtrack. And then there's Dante, remade in the image of a club-kid layabout who's so sneeringly self-satisfied he defies any attempt you might make to identify with him. I pretty much went into the game consciously expecting to hate all of this, or at least view it as the sort of eye-rolling embarrassment video games are usually so good at delivering.
Then, oddly, I started feeling a guilty pleasure at how much I was actually enjoying the spectacle. Then later I gave up the guilt and just flung myself wholeheartedly into the cyclone of nonsense. I think it became easy to like Devil May Cry because it seems somewhat aware of itself; the game is so damn committed to having fun with its absurdity, you can't help having fun along with it. Dante may be a smirking wiseass, but his lines are witty enough and delivered with so much panache, you quickly grow to like him anyway. And he makes a great foil for his brother Vergil, who's more of an uppity, refined ideologue fighting the good fight against the demons. Dante talks a constant stream of shit to Vergil and just about anyone else who gets in his way, and there's something uncomfortable and a little dissonant about a 50-foot ancient grub-demon screeching "FUCK YOOOOOUUUUU!!!" right back at him. The best sort of dumb fun is the kind that knows how dumb it is, and I consistently got the sense from Devil May Cry knew that the entire time I was playing it.
![]() |
| When acting is required, it's amazing how effective real actors can be. |
Lest we forget this is also a video game: Devil May Cry is in fact a greatly entertaining character action game, as fast-paced and diverse as I could have wanted. The game starts you off with Dante's familiar sword and dual pistols, but you quickly start to collect angel and demon weapons, which fill light and heavy attack categories respectively. Switching between melee weapons, and the three firearms you end up with, just takes a tap of the d-pad. You only have a single attack button which wields your sword by default, and you switch to the equipped angel or devil weapon instantly by holding the left or right trigger and hitting that same button. The game finds a lot of interesting ways to make you stay on your toes, with enemies that only fully coalesce when one type of weapon is equipped, or floors that will hurt you if you aren't holding the same-colored weapon. More importantly, if you're quick enough, it's possible to involve three, four, or five different weapons in a single combo, and the game is constantly running a tally on the side of the screen rating how stylishly you're fighting, all the way up to triple-S.
The more style you rack up, the more new abilities and moves you can unlock (from a list of dozens), and since you lose a couple of letter grades every time you get hit, you're really incentivized to play as cleanly as possible. The combat isn't overwhelmingly hard on the default difficulty, though it isn't a cakewalk, but if you're really serious about this kind of game, play it on hard from the outset. There are another four difficulty levels waiting for you to unlock them after that. The game is built to be replayed repeatedly; you can jump back into any mission on any difficulty whenever, and there are plenty of places you just can't access without the right abilities the first time through. All of your completion totals get rated and slapped onto leaderboards if you want to keep up with how your friends are doing. In short, the between-mission trappings, the glue that holds the levels themselves together, feel thoroughly modern in this game.
![]() |
| The inventive visual and level design just keeps on coming. |
I brought no personal baggage to Ninja Theory's take on Devil May Cry, having played and enjoyed the original game way back when but then steering clear of the series after its poorly received second entry. Whether you're a longtime fan (with an open mind) or a total newcomer just looking for a solid character action game, it's hard to imagine anyone feeling overly dissatisfied with this new game. It's almost wholly successful at what it tries to do, and seems like the start of a promising new direction for what was otherwise a nearly forgotten franchise.
Source :- By Brad Shoemaker on ww.giantbomb.com, www.wikipedia.com
Nokia reportedly prepping new aluminum Nokia Lumia phone with upgraded PureView camera
By : Sachin Kumar Sahu
Nokia (NOK) is reportedly developing a new Lumia smartphone with an improved design and an upgraded PureView camera. The Verge cited multiple unnamed sources on Wednesday when claiming that a new Windows Phone code-named “EOS” is being planned by Nokia. The phone will reportedly feature an aluminum case in place of the plastic Nokia has used on its Lumia phones thus far, and it will feature an upgraded PureView camera said to be similar to the one found on Nokia’s PureView 808 smartphone.
The 808′s camera was a 41-megapixel unit, though the report does not
specify the upcoming Lumia phone’s megapixel count. AT&T (T) will carry Nokia’s new Windows Phone latest this year, according to the report.
Source :- www.bgr.com
Tag :
Mobiles,
New Release,
Microsoft puts an end to the exploit in IE 8, 7 and 6 with Security Update 2799329
By : Sachin Kumar Sahu
Microsoft is today putting an end to the vulnerability found in old
versions of Internet Explorer (6-8) that allowed an attacker to execute
harmful code in a target computer, if the user was tricked by a
specially crafted website.Soon after the security hole was found, the software giant quickly made available a temporary workaround in a form of patch that they call “Fix it”. However, the security update released today should permanently close the door, for good, to this issue.
The company reports that only a small number of users have been affected by the exploit, but acknowledges that if could potentially affect more users in the future. Because of its future impact the update has been labeled as “Critical” and it will be installed automatically to all those users who have Automatic Update enabled. Microsoft also is advising users to upgrade to IE9 and 10 when possible to stay even more protected from this particular security hole.
Note that if you previously installed the “Fix it”, you don’t need to uninstall it before applying the new update, but you may want to uninstall the patch after, as it could slowdown IE start-up time.
If you prefer to manually install the Security Update (2799329), you can download it here.
Please watch the video below for an overview of this security update, and you can find more information on the Microsoft Security Bulletin summary webpage.
Source :- www.pureinfotech.com, www.blogs.technet.com
Google+ now has 400 million total users, 100 million active monthly users
By : Sachin Kumar Sahu
Google (GOOG) on Monday announced a new milestone for its Google+
social networking platform. Vic Gundotra, the company’s senior vice
president of engineering, revealed that Google+ is now home to more than
400 million members and, despite arguments that claim the service is a ghost town,
it now attracts 100 million active monthly users. “It was only a year
ago that we opened public sign-up, and we couldn’t have imagined that so
many people would join in just 12 months,” Gundotra wrote. Facebook (FB), Google’s main competitor in the social space, has more than 900 million active monthly users.
Source :- www.bgr.com
Tag :
Internet,
Updates to fix Internet Explorer and Windows 8 Flash exploit released today
By : Sachin Kumar Sahu![]() |
| Internet Explorer Logo |
The security hole discovered late last weekend, as we mentioned before, could allow malicious users to harm Windows machines by means of spacial design of Flash animation.
The second security update (described in Microsoft Security Advisory 2755801) is to fix the Flash exploit found on Windows 8′s IE10. This was a security issue that could cause Adobe Flash to crash, while allowing unauthorized to the computer. Even though the operating system hasn’t been released, there are already many companies and people developing software with the Release to Manufacture or RTM version — Microsoft plans to make Windows 8 available to the public on October 26th, right after the launch event the day before in New York City.
The patches are now available for Windows 8, Windows 7, Vista and Windows XP via Microsoft’s Windows update service.
Source :- www.pureinfotech.com , Microsoft Security Bulletins
Microsoft releases a temporary ‘fix it’ for Internet Explorer vulnerability.
By : Sachin Kumar Sahu![]() |
| INTERNET EXPLORER LOGO |
The exploit, discovered during the weekend, could allow a malware to bypass security protocols via Flash and affect XP, Vista and Windows 7 machines. In a new article the company stated that there is a fix now for it and it is easy to apply: “This is an easy, one-click solution that will help protect your computer right away. It will not affect your ability to browse the web, and it does not require a reboot of your computer.”
While the fix it (Microsoft Fix it 50939 and 50938) delivers a protection against the security hole, Microsoft recommends to IE users that it is highly important to install the forthcoming security update set for Friday via Windows Update. To get all the steps on how to install Microsoft Fix it for Internet Explorer follow these instructions.
Source :- www.pureinfotech.com
Protect yourself from Internet Explorer 9, 8, 7, 6 security bug
By : Sachin Kumar Sahu![]() |
| INTERNET EXPLORER LOGO |
About the new IE bug, well… It is a security hole that was discovered days ago and it could potentially compromise PCs running Windows 7, Vista, XP SP3 and below, if users browse malicious web pages designed to take advantage of this Internet Explorer’s weakness.
In an article from Microsoft Security Advisory the company is offering details about the problem and it is also advising users to protect themselves from this vulnerability until an update for IE is release.
Four different workaround to deal with the bug
What you should always be doing is advice first:1>> Make sure that you have an antivirus and anti-spyware solution installed and up-to-date, and also make sure that you are using a firewall, either use the one built-in Windows or use a third-party solution.
2>> It is also suggested to install the Enhanced Mitigation Experience Toolkit or EMET from Microsoft. The utility is designed to help protect from weakness in software being easily exploited, by adding an extra layer of security that function as an obstacle that whoever writes the malicious software must bypass first.
3>> Another option is to modify your Internet and Local Intranet security settings to High. If you want to do this. Open Control Panel, in the search box type Internet Options, from the list results open the Internet Properties, navigates to the Security tab and in the “Security level for this zone” position the slider to High for both zones. Click Apply and then OK.
4>> Active Scripting can also be used by setting it to notify in both Local Intranet and Internet. To accomplish this task once again open the Internet Properties and in the Security tab, select the Internet zone, click the Custom Level button. Then scroll down and under the Scripting section, set the Active scripting option to Prompt, and click OK. Remember to do the same for the Local Intranet zone.
According to the company these workarounds could help prevent users from loading websites that can harm their computers with this security hole.
Changing the settings will actively trigger an unpleasant message every time the user stumble upon a web page that make use of the ActiveX control prompting to allow or block the web page. However, you can always opt not to use Internet Explorer, until a fix is release. Options are all around, you can use Google Chrome or Firefox as alternative web browsers among others. This is a pretty easy thing to do if you are a normal user, but the challenge comes when companies depend on IE to access their web applications.
Source :- wwwpureinfotech.com
Microsoft advice steps to protect yourself from Internet Explorer 0'day security bug
By : Sachin Kumar SahuWith no fix available yet, Microsoft has a few words of wisdom for users who don't want to be bit by the newly-discovered bug.
![]() |
A malware attack exploiting Internet Explorer 9.
(Credit:
Rapid7)
|
Uncovered this past weekend, the security hole could compromise the PCs of IE users who surf to a malicious Web site. Microsoft said it's already aware of attacks that have tried to take advantage of this weakness.
Since no fix is yet available, it's up to users of IE to protect themselves. A new Microsoft Security Advisory offers several recommendations.
To start, the usual advice always applies. Make sure you're running updated antivirus and antispyware software and that you're using a firewall, either a third-party utility or the one built into Windows.
You can also install the Enhanced Mitigation Experience Toolkit from Microsoft. EMET tries to ward off attacks on software holes by putting up a wall of security obstacles that the malware writers must circumvent. EMET can be configured specifically for Internet Explorer as well as other applications.
Another option is to push the Internet and local Intranet security settings in IE to "high." To do this, launch Internet Explorer, click the Tools menu, and then select Internet Options. Click the Security tab and then select the Internet zone. Under the Security level for this zone, move the slider to High. Click the Local Intranet zone and again push the Security level to High.
Users can also set Active Scripting to "prompt" in both the Internet and Local Intranet zones. To do this, again select Internet Options from the Tools menu in IE. Click the Security tab. Click the Internet zone and then select Custom Level. Scroll down to the Scripting section and set Active Scripting to Prompt. Repeat the same steps for the Local Intranet zone.
As Microsoft warns, tweaking these settings could prevent access to certain Web sites.
Even changing the setting to "prompt" will trigger an annoying message anytime you hit a Web site that uses ActiveX controls asking if you want to allow or block the site.
Microsoft's own Windows update sites -- *.windowsupdate.microsoft.com and *.update.microsoft.com -- rely on ActiveX control to install available updates.
You can add sites that you trust to the Trusted sites zone through Internet Options. But this can be time-consuming since you have to add them on an individual basis.
As a result, the easiest option is to just not use Internet Explorer, at least not while this exploit remains in the wild. Individual users can switch to Firefox, Chrome, or another browser. Organizations that have standardized on Internet Explorer face a tougher challenge. So the onus now is on Microsoft to fix this hole as quickly as possible.
You can learn more about the security flaw and possible workarounds through Microsoft's Security Advisory.
Source :- www.cnet.com by Lance Whitney











