<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>IE8 Security Part IX - Anti-Malware protection with IE8’s SmartScreen Filter</title><link>http://blogs.msdn.com/b/ie/archive/2009/03/25/ie8-security-part-ix-anti-malware-protection-with-ie8-s-smartscreen-filter.aspx</link><description>Over the last year, we&amp;rsquo;ve published two posts about how the IE8 SmartScreen &amp;reg; filter helps to prevent phishing and malware attacks. In this post, I&amp;rsquo;d like to share some real-world data on the protection provided to IE8 pre-release users</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>Security Intelligence Report Volume 6</title><link>http://blogs.msdn.com/b/ie/archive/2009/03/25/ie8-security-part-ix-anti-malware-protection-with-ie8-s-smartscreen-filter.aspx#9582640</link><pubDate>Fri, 01 May 2009 20:11:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9582640</guid><dc:creator>IEBlog</dc:creator><description>&lt;p&gt;The sixth edition of the Security Intelligence Report (SIR), Microsoft’s semi-annual report on the state&lt;/p&gt;
&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9582640" width="1" height="1"&gt;</description></item><item><title>re: IE8 Security Part IX - Anti-Malware protection with IE8’s SmartScreen Filter</title><link>http://blogs.msdn.com/b/ie/archive/2009/03/25/ie8-security-part-ix-anti-malware-protection-with-ie8-s-smartscreen-filter.aspx#9527532</link><pubDate>Wed, 01 Apr 2009 21:31:41 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9527532</guid><dc:creator>EricLaw [MSFT]</dc:creator><description>&lt;p&gt;@jjb2009: Please feel free to email me any examples; I'm happy to investigate.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9527532" width="1" height="1"&gt;</description></item><item><title>re: IE8 Security Part IX - Anti-Malware protection with IE8’s SmartScreen Filter</title><link>http://blogs.msdn.com/b/ie/archive/2009/03/25/ie8-security-part-ix-anti-malware-protection-with-ie8-s-smartscreen-filter.aspx#9527425</link><pubDate>Wed, 01 Apr 2009 20:48:30 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9527425</guid><dc:creator>jjb2009</dc:creator><description>&lt;p&gt;I wondered. I found a half dozen of their most dangerous sites (known to download malware, Mcafee said). Entered in IE8 and . . . SmartFilter does nothing! Of course, I wasn't infected with malware either so perhaps Mcafee as a LOT of false positives??&lt;/p&gt;
&lt;p&gt;An explanation of the difference or a FAQ might help because I know lots of people who use Mcafee siteadvisor on IE and FF and you can't persuade them SmartFilter takes care of the job -- and I'm still fuzzy on the difference. Mcafee claims it does an actual crawl of sites?? &lt;/p&gt;
&lt;p&gt;Pat on the back: &lt;/p&gt;
&lt;p&gt;I read Paul Thurott's review of IE8 -- it made him switch from FF to IE8, something I have done since you went official. It's like a new Microsoft! Perhaps I won't have to spend all my time having to search for &amp;quot;things MS can't do&amp;quot; -- there is less and less these days. (Total digression: No idea why Apple of MS don't have something like Clipmagic clipboard extender?). &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9527425" width="1" height="1"&gt;</description></item><item><title>re: IE8 Security Part IX - Anti-Malware protection with IE8’s SmartScreen Filter</title><link>http://blogs.msdn.com/b/ie/archive/2009/03/25/ie8-security-part-ix-anti-malware-protection-with-ie8-s-smartscreen-filter.aspx#9523848</link><pubDate>Tue, 31 Mar 2009 23:15:18 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9523848</guid><dc:creator>EricLaw [MSFT]</dc:creator><description>&lt;p&gt;@jjb2009: SmartScreen blocks navigation to (and downloads from) known-malicious sites.&lt;/p&gt;
&lt;p&gt;Note that McAfee's feature works differently than ours. &amp;nbsp;A key goal for SmartScreen is that false positives must be as low as possible.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9523848" width="1" height="1"&gt;</description></item><item><title>re: IE8 Security Part IX - Anti-Malware protection with IE8’s SmartScreen Filter</title><link>http://blogs.msdn.com/b/ie/archive/2009/03/25/ie8-security-part-ix-anti-malware-protection-with-ie8-s-smartscreen-filter.aspx#9523668</link><pubDate>Tue, 31 Mar 2009 22:01:42 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9523668</guid><dc:creator>jjb2009</dc:creator><description>&lt;p&gt;I'm confused: I have IE8 _and_ McAfee Siteadvisor. I like that it warns me with a read X that a site has dangerous downloads, or is linked to dangerous sites. Can SmartFilter do this? &lt;/p&gt;
&lt;p&gt;Also, a lot of the sites that McAfee reports as downloading &amp;quot;Red&amp;quot; (malware) come up with no peep from SmartFilter. When I &amp;quot;CHeck this website&amp;quot; the SmartFilter says everything is fine?! &lt;/p&gt;
&lt;p&gt;So, how do I know SmartFilter is REALLY working? I'd gladly junk McAfee Siteadvisor (yeah, yeah, the more &amp;quot;layers&amp;quot; the better but there is a performance hit). &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9523668" width="1" height="1"&gt;</description></item><item><title>re: IE8 Security Part IX - Anti-Malware protection with IE8’s SmartScreen Filter</title><link>http://blogs.msdn.com/b/ie/archive/2009/03/25/ie8-security-part-ix-anti-malware-protection-with-ie8-s-smartscreen-filter.aspx#9523049</link><pubDate>Tue, 31 Mar 2009 18:44:46 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9523049</guid><dc:creator>EricLaw [MSFT]</dc:creator><description>&lt;p&gt;@Vanoie: If you are running the 64bit version of Windows Vista, you must download the 64bit package of IE8. &amp;nbsp;(Note that this will also install the 32bit version as well).&lt;/p&gt;
&lt;p&gt;You can determine if you're running the 64bit version by visiting this page in IE: www.enhanceie.com/ua.aspx. &amp;nbsp;If your user-agent string (in red) contains tokens like &amp;quot;Win64&amp;quot; or &amp;quot;WOW64&amp;quot;, you need the 64-bit version.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9523049" width="1" height="1"&gt;</description></item><item><title>re: IE8 Security Part IX - Anti-Malware protection with IE8’s SmartScreen Filter</title><link>http://blogs.msdn.com/b/ie/archive/2009/03/25/ie8-security-part-ix-anti-malware-protection-with-ie8-s-smartscreen-filter.aspx#9521963</link><pubDate>Tue, 31 Mar 2009 11:35:27 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9521963</guid><dc:creator>Olivier</dc:creator><description>&lt;p&gt;@Vanoie Ball : do you have Vista 32 or 64 bits ?&lt;/p&gt;
&lt;p&gt;Which version of IE8 have you downloaded : 32 or 64 bits ?&lt;/p&gt;
&lt;p&gt;You have to download the correct version for your OS.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9521963" width="1" height="1"&gt;</description></item><item><title>re: IE8 Security Part IX - Anti-Malware protection with IE8’s SmartScreen Filter</title><link>http://blogs.msdn.com/b/ie/archive/2009/03/25/ie8-security-part-ix-anti-malware-protection-with-ie8-s-smartscreen-filter.aspx#9521344</link><pubDate>Tue, 31 Mar 2009 06:48:48 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9521344</guid><dc:creator>Vanoie Ball</dc:creator><description>&lt;p&gt;ok I have Vista and downloaded vista version and i guess it. I don't work! Here is the message:&lt;/p&gt;
&lt;p&gt;This installation does not support your system architecture (32/64bits).&lt;/p&gt;
&lt;p&gt;So what now??????&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9521344" width="1" height="1"&gt;</description></item><item><title>re: IE8 Security Part IX - Anti-Malware protection with IE8’s SmartScreen Filter</title><link>http://blogs.msdn.com/b/ie/archive/2009/03/25/ie8-security-part-ix-anti-malware-protection-with-ie8-s-smartscreen-filter.aspx#9518159</link><pubDate>Mon, 30 Mar 2009 11:43:35 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9518159</guid><dc:creator>Olivier</dc:creator><description>&lt;p&gt;@zzz : &amp;quot;For all the browsers on operating systems, the hardest target is Firefox on Windows&amp;quot; : you understand this means that Firefox is a security breach, do you ?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9518159" width="1" height="1"&gt;</description></item><item><title>re: IE8 Security Part IX - Anti-Malware protection with IE8’s SmartScreen Filter</title><link>http://blogs.msdn.com/b/ie/archive/2009/03/25/ie8-security-part-ix-anti-malware-protection-with-ie8-s-smartscreen-filter.aspx#9517691</link><pubDate>Mon, 30 Mar 2009 03:32:13 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9517691</guid><dc:creator>Rob</dc:creator><description>&lt;p&gt;zzz, I'm sure MS has learned that it's pointless to try to correct the inaccuracies in stories that are published in the media when those stories are specifically written with dramatic headlines (rather than correctness) in mind.&lt;/p&gt;
&lt;p&gt;Firefox, you might remember, DID fall at the pwn2own contest, but it fell on Mac (which is the real loser at the contest). &amp;nbsp;On Windows, Firefox/Chrome uses dep/NX and ASLR, like IE does. &amp;nbsp;All three browsers help prevent this type of attack from succeeding on Windows. &amp;nbsp;(As hAl points out, the dep bypass that was used at the contest doesn't actually work in the version of ie that was released.)&lt;/p&gt;
&lt;p&gt;Even then, the design of the contest is pretty flawed because it treats all potential code execution flaws as equal. &amp;nbsp;Both IE and Chrome run with restricted rights (called &amp;quot;sandboxing&amp;quot; in Chrome and &amp;quot;Protected Mode&amp;quot; in IE.) &amp;nbsp;But Firefox has neither, meaning that if the bad guy DOES manage to bypass dep and ASLR, they get to run with full user permissions and trash the machine.&lt;/p&gt;
&lt;p&gt;Chrome's sandbox is somewhat better than IE's (it prevents &amp;quot;read&amp;quot; of the system) but also somewhat worse than IE's (it runs plugins like Flash outside the sandbox with full trust).&lt;/p&gt;
&lt;p&gt;While some note that Chrome didn't fall at the contest, it's also worth remembering that no one bothered to try, which does /not/ necessarily mean that it would have been hard to do so but rather that picking on targets like Safari (which got hacked twice) was simply easier.&lt;/p&gt;
&lt;p&gt;The story here that zdnet and other should have written is that Windows browsers are simply safer than Mac browsers because they have protections like ASLR and dep.&lt;/p&gt;
&lt;p&gt;Having typed all that, the /real/ point of all of this is that these types of &amp;quot;drive by&amp;quot;/&amp;quot;backdoor&amp;quot; attacks are not really very common. &amp;nbsp;Much more common is when users get suckered into downloading malicious &amp;quot;through the front door&amp;quot; because soc. engineering is really effective. &amp;nbsp;And MS' point with this blog post is that social eng. attacks are far less likely to be successful in IE because smartscreen is better than the competition.&lt;/p&gt;
&lt;p&gt;But that's not the story you'll read in the media because it's a boring headline, and boring headlines don't sell ads.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=9517691" width="1" height="1"&gt;</description></item></channel></rss>