Security Blog

The latest news and insights from Google on security and safety on the Internet

MHTML vulnerability under active exploitation

March 11, 2011
Share on Twitter Share on Facebook
Google

27 comments :

Unknown said...

Wouldn't a better recommendation be to simply *stop using internet explorer*? It's really sad that Microsoft can't patch issues like this in a far more timely fashion.

March 12, 2011 at 1:10 PM
Nvrstpnvrstppg said...

Is there a pattern to the activists being attacked - what are the issues they're active on, any common thread?

March 12, 2011 at 1:32 PM
Frej said...

That is serious... Now it's not only website developers affected. I hope the day when IE legacy stops casting a bad light over MS is soon to come.

March 12, 2011 at 2:21 PM
Anonymous said...

my daughters gmail account was hacked and she was using Internet explorer

March 12, 2011 at 2:49 PM
Unknown said...

Use Google Chrome for the fastest or Firefox for the user friendly experience and don't use IE, we don't.
Fred

March 12, 2011 at 10:30 PM
plexor said...

As I become more paranoid about my safety everywhere, it seems as though the biggest threat is from the Net - or more precisely - the ongoing threat caused by people who use Microsoft products from Browsers to Servers.
The only apparent solution would be to punish people for using these products the way irresponsible people are finally being punished for texting while driving.

March 13, 2011 at 10:06 PM
Reverend Magdalen said...

I second the request for more information about what specific type of activist is being targeted. This information could be vital to protecting people in future. Please share at least the general topic of the activism.

March 14, 2011 at 3:23 AM
Greg Zeng said...

Crippleware (SAFARI, CHROME, CHROMIUM, MOILLA, etc cannot save web pages in one compressed file: mht.

IE & its shells (Cray, Green, Maxthon, etc) probaly are affected by the IE bug as well.

Only truly effective browser is freeware, mistakenly labelled as shareware. It is available on Symbian, Linux, Android, Windows, etc. OPERA.

March 14, 2011 at 8:44 AM
P J said...

@Greg Zeng

That's funny :) Because this is operating system's hole then opera is also affected ;)

March 14, 2011 at 12:08 PM
Anonymous said...

@P J I'm pretty sure only internet explorer (all versions, including the ie shells mentioned above) is affected, source: http://www.h-online.com/security/news/item/Microsoft-warns-of-cross-site-scripting-in-Windows-1180179.html

March 14, 2011 at 1:00 PM
Unknown said...

Is it *all* political activists? Is it a campaign against one particular flavor?

March 20, 2011 at 10:41 AM
vu3mes said...

hi

i had two accounts with google mail which i had been using for years now. yesterday i could not access both the accounts and when it was open i had a warning that the accounts were acessessed by an ip no. based in china and duely instructed me to change my passwords. in the inbox i could see the mass mail circualted using my id which was returned non delivered by some addressees.

March 21, 2011 at 7:02 AM
Scott Grayban said...

Why is anyone using Internet Expolder ? Why is google telling people to use a insecure browser in the first place ??? Seriouisly google if you are going to help at least get it right.

March 21, 2011 at 9:02 AM
Unknown said...

internet explorer is targeted because its the most popular browser. if everyone changed to firefox for example, do you think that attacks would suddenly stop? if you do your totally nieve and unrealistic. Internet explorer is popular, and whether you agree with that or not its not good enough to blame microsoft for the actions of those who will attack them. If firefox had the same market share - then firefox would be under attack. Microsoft bashing is all well and good, but at least have a coherant argument!

March 21, 2011 at 9:07 AM
Unknown said...

@Plexor
Are you for real? Punish people for using IE?
People had to use IE in the past, which, quite rightly was fought and won against. Now to punish people for using IE is worse! Say someone uses IE and doen't have a GMail account? Say someone finds a way to hack into ALL browsers, does everyone get punished?
Microsoft are to blame and should be punished, not the users.

Frank.

March 21, 2011 at 9:25 AM
Unknown said...

"We’ve noticed some highly targeted and apparently politically motivated attacks against our users"

China against human-rights activists..?

March 21, 2011 at 9:32 AM
Unknown said...

I've found that any Microsoft product I've used has eventually encountered technical issues. While I understand the price of an iMac or another Apple product can sometimes be prohibitive, I've been using an iMac for several years and encountered very few issues - when I have the issue has been easily resolved. Safari all the way!

March 21, 2011 at 9:53 AM
Unknown said...

i wonder how many microsoft bashers here are actually using a microsoft operating system, and often use other microsoft software...

as far mac's being safe - indeed the are more secure - but again - only because the number of worldwide users are so so much smaller than those using microsoft products. Someone who is set to attack a group of users will obviously go for the largest user base, to cause the most disruption. Macs, safari, firefox are only safe because microsoft is taking the hit for you, not because the software or hardware is any better or more intelligently created. Im well aware of microsofts shortfalls, but i think everyone should imagine a world without microsoft products, sure there linux and all the different flavours thereof, but can you seriously imagine most of the population trying to be productive on a unix box?? absolutly wony happen. unix and linux are excellent - for specific uses. for a user friendly, easy to learn based market- no they arent fit for that purpose.

March 21, 2011 at 10:52 AM
卢海玲 said...

Chinese government is becoming the new hidden Nazi now. It is torturing ,murdering and fooling its own ordinary citizen inside china. It has more than a quarter of a million internet polices doing all kinds of attacks, stealing info from other countries. The Chinese government is the biggest hiker organization in the world, it going to rule the world by its Mafia rules. All the west countries should work together to fight with it now in order to save everyone include chinese in the world.

March 21, 2011 at 11:47 AM