 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Trenches &#187; Aurora</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/it-trenches/tag/aurora/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/it-trenches</link>
	<description></description>
	<lastBuildDate>Fri, 19 Nov 2010 14:37:59 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Google Aurora attack focused on IE6 &#8211; does anybody do autoupdates anymore?</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/google-aurora-attack-focused-on-ie6-does-anybody-do-autoupdates-anymore/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/google-aurora-attack-focused-on-ie6-does-anybody-do-autoupdates-anymore/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 21:57:42 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[attack]]></category>
		<category><![CDATA[Aurora]]></category>
		<category><![CDATA[fixes]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[malicious software]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[patch management]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/google-aurora-attack-focused-on-ie6-does-anybody-do-autoupdates-anymore/</guid>
		<description><![CDATA[Maybe you have heard about the recent news of the attacks against Google known as Aurora. If you haven&#8217;t take a look at the stories returned in the Google news search in the previous link. What strikes me as interesting about this attack is that the focus is on Microsoft&#8217;s Internet Explorer 6. Internet Explorer [...]]]></description>
				<content:encoded><![CDATA[<p>Maybe you have heard about the recent <a href="http://news.google.com/news?q=aurora+attack+google&amp;oe=utf-8&amp;rls=org.mozilla:en-US:official&amp;client=firefox-a&amp;um=1&amp;ie=UTF-8&amp;hl=en&amp;ei=cchYS9rBIIvSMvqCqc8E&amp;sa=X&amp;oi=news_group&amp;ct=title&amp;resnum=1&amp;ved=0CBEQsQQwAA" target="_blank">news of the attacks against Google known as Aurora</a>. If you haven&#8217;t take a look at the stories returned in the Google news search in the previous link.</p>
<p>What strikes me as interesting about this attack is that the focus is on Microsoft&#8217;s Internet Explorer 6. Internet Explorer 6 was <a href="http://en.wikipedia.org/wiki/Internet_Explorer_6#Release_history" target="_blank">released in August 2001</a>. Internet Explorer 7 was released in <a href="http://en.wikipedia.org/wiki/Internet_Explorer_7#Release_history" target="_blank">October 2006</a>. Internet Explorer 8 was released in <a href="http://en.wikipedia.org/wiki/Internet_Explorer_8#Release_history" target="_blank">March 2009</a>. So, the recent attacks focused on a 8+ year old application that has been superceded by two full revisions. Didn&#8217;t anyone use automatic updates to update their IE? What kept people from updating IE?</p>
<p>I know that Microsoft has released an <a href="http://support.microsoft.com/kb/978207" target="_blank">out-of-cycle update</a> to address the vulnerability. This is a cumulative update for all currently supported of Internet Explorer. So, will this update get applied to at-risk systems? Hmmm&#8230; I wonder since it appears that there is little movement off of older versions of Internet Explorer. The attacks were on well known organizations (Google, Adobe, Juniper). Why would they still be using this older version of IE? It seems like this would raise questions about Microsoft&#8217;s penetration of newer operating systems like Vista which would be running IE7.</p>
<p>IE7 had issues with compatibility and html standards. IE8 is much better. Is the compatibility issue so significant that organizations stayed on IE6 rather than moving to IE7 and/or IE8?</p>
<p><a href="#comments">Please share your thoughts.</a></p>
<p>Thanks for reading and let&#8217;s continue to be good network citizens!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/google-aurora-attack-focused-on-ie6-does-anybody-do-autoupdates-anymore/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
