Forum Home
Press F1
 
Thread ID: 42163 2004-02-02 19:01:00 New update (KB832894) MrBeef (342) Press F1
Post ID Timestamp Content User
212402 2004-02-02 19:01:00 Cumulative Security Update for Internet Explorer 6 Service Pack 1 (KB832894)



i just went on this morning and went to windows update and found this critical update. What does this one cover...is it the spoofing web addys?
MrBeef (342)
212403 2004-02-02 20:40:00 MrBeef,

See the following MS TechNet article February Security Update (www.microsoft.com)

Cheers, Babe.
Babe Ruth (416)
212404 2004-02-02 22:27:00 See www.microsoft.com TonyF (246)
212405 2004-02-02 23:28:00 this link (www.microsoft.com) gives detailed info on the vulnerabilities and fixes.

It may have nothing to do with it but, I updated IE (even though I rarely use it now) on the advice at an MS site that stated even if you do not use IE the update is crtitcal. After applying the IE patch and catching up with an office update my Mozilla Firebird bookmarks were gone except for the defaults and, 'updated, Imported IE Favourites. My home page had also been changed to the default and most of the customised Toolbars and some plugins are kaput. I searched high and low for the original bookmarks but they were nowhere to be found. Fortunately I had a month old backup to restore from so have lost only a few mainly work related ones. BTW, Thunderbird seems to be ok. It send and receives and the address book is iintact.

Before applying any patches, backup.

I would be interested to know if anyone else has had this or similar problems.

Cheers Murray P
Murray P (44)
212406 2004-02-03 04:28:00 > Before applying any patches, backup .
>
> I would be interested to know if anyone else has had
> this or similar problems .

Thanks for that warning Murray . I just downloaded that patch as well (after backing up the Phoenix folder under Application data first), but my MozillaFirebird was not affected at all by that update . All bookmarks, extensions and skins are still fine .

Sounds like your profile for MozillaFirebird was corrupted . Did you take a look in the Phoenix folder Phoenix\Profiles\name(or default)\random_8_letters . slt for your bookmarks . html?
Jen C (20)
212407 2004-02-03 04:45:00 No problems here with Firebird after downloading the patch for IE.

DD.
dumdum (4965)
212408 2004-02-03 04:50:00 As a matter of interest, is it normal practice to do a backup before d/loading and installing these patches?
sorry this was meant to be included in the previous post.
Cheers
DD.
dumdum (4965)
212409 2004-02-03 07:40:00 > As a matter of interest, is it normal practice to do a backup before d/loading and installing these patches?

Its always a good idea to back everything up before installing or updating anything , software and hardware included, if you have anything on your HDD worth saving. ;-)

Most of us take the risk however and then grumble when it all turns to custard. :D
Fire-and-Ice (3910)
212410 2004-02-03 08:39:00 Thanks for that Fire. dumdum (4965)
212411 2004-02-03 10:15:00 Anyone who has installed the latest update and is having a problem logging into a site that requires a username and password can thank Microsoft for for the inconvenience.

The Microsoft patch has disabled a standard form of authentication which is widely used across the internet.
If HTTP or HTTPS URLs contain user information in the scripting code to manage state information, they will need to be changed to use cookies instead of user information.

This from www.microsoft.com ( [url) security bulletin[/url]



Does this Security Update contain any other changes to functionality in Internet Explorer?
Yes. This Internet Explorer cumulative update also includes a change to the functionality of a Basic Authentication feature in Internet Explorer. The update removes support for handling user names and passwords in HTTP and HTTP with Secure Sockets Layer (SSL) or HTTPS URLs in Microsoft Internet Explorer. The following URL syntax is no longer supported in Internet Explorer or Windows Explorer after you install this software update:

http(s)//usernamepassword@server/resource.ext

For more information about this change, please see the Frequently Asked Questions section for this specific issue in this bulletin or Microsoft Knowledge Base article 834489.

Additionally, this update will disallow navigation to "usernamepassword@host.com" URLs for XMLHTTP. Microsoft is currently creating an update to MSXML that will address this issue specifically for XMLHTTP and we will provide more information in this bulletin when the update becomes available.

Does the update contain any other security changes?
The update also refines a change made in Internet Explorer 6 Service Pack 1, which prevents web pages in the Internet zone from navigating to the Local Machine zone. This change was introduced to mitigate the effects of potential new cross domain vulnerabilities. The changes introduced in this update are further enhancements of the Internet Explorer 6 Service Pack 1 restrictions.
Jim B (153)
1 2