IE an Intranet Attack Vector?
    IE has always had the rap of being an insecure browser, something  that I believe will change as more IE folks move to the more robust IE 8. (Side  note: Over 50 Redmond Report readers helped me craft a May cover story about IE  8 which says, in short, that test versions of the browser were a mess but the  final product is stable and sweet -- and more secure.) 
Regardless of the extra measures, IE 8 and earlier versions have  one big flaw, at least according to one security firm: There are four core  security settings and the one for internal networks, intranets, is too lax. This  could allow scumbag loser hacker creeps to creep into your network and have  their way. The saving grace? The hackers need some detail on how your intranet  interface looks.
I wouldn't mind more of us using honeypots to lure these  hackers in, solid forensics to find out who they are, and law enforcement to  nab 'em. Even better, how about a few Navy Seals? Should more be done to  identify hackers and would you implement technology that helps? Calm, rational  and off-your-rocker commentary welcome at [email protected].
 
	
Posted by Doug Barney on April 15, 2009