Hacking attacks on the most popular applications are inevitable but what makes the latest Internet Explorer 7 exploit interesting is that it’s left Microsoft floundering to get a fix – and the problem is snowballing.

MS reckons some 0.2% of worldwide users may have been exposed to the dodgy websites that exploit the IE vulnerability but the trend is not good: they received a 50% increase in the number of reports in just one day over last weekend.

And its not just IE7. Other versions of the IE browser used by an estimated 75% of web users are also “potentially vulnerable”.

Some sources claim that up to 10,000 sites have been compromised since last week. Though most are thought to be porn sites, clearly there are some in that vast number that are not. The actual exploit is a trojan that attempts to grab computer games’ passwords (which apparently people are prepared to pay for) though the chief concern is that it could be used to also pick up users’ financial and private data.

So how can you protect yourself if you’re running IE (apart from giving any naughty sites a miss for a while)?

Some security pundits are advising a switch over to alternative browsers such as Google Chrome, Apple Safari or Mozilla FireFox. Personally not a problem as I run multiple browers but a bit drastic even for the individual nevermind for a business with more than a handful of employees.

You could also check out the Microsoft Security Advisory but this really only tells you to keep Windows up to date plus some other information that won’t be of use to the non-technical.

Best bet is to :

  • Stick to visiting trusted sites ie brand names, that are more likely to be on the look-out for the exploit
  • Make sure you have antivirus software and its definitions are up to date
  • Make sure your firewall is enabled (Windows has one). I also like using the Norton Security Scan – it’s a free online tool that identifies vulnerabilities in your firewall setup. Spooky but very useful.
  • Look out for the IE service pack when it arrives and update…