On CBS.com: Six show girls attacked
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos, News.com
Posted on ZDNet News: Jul 7, 2004 12:32:00 PM

A computer science researcher has highlighted the shortcomings of Microsoft's latest patch for its Internet Explorer browser by identifying another way that online vandals could run malicious programs on a Web surfer's computer.

Microsoft on Friday released a fix that's designed to protect computers from one of three flaws that, together, could be used to digitally slip past a PC's security through the browser. This weekend, however, a security researcher identified another flaw that could serve the same purpose and that isn't fixed by Microsoft's patch.

"They chose to address only one part of the problem," said Jelmer Kuperus, a computer science student in the Netherlands who posted the code for the work-around. "They should have seen this one coming."

This marks the third time in a month that Microsoft has had to play catch-up to researchers' public disclosures about insecurities in Internet Explorer. In early June, Kuperus found a Web site that used two previously unknown vulnerabilities, plus the recently patched one, to install adware on victims' computers. Additionally, security researchers discovered last week that a milder vulnerability, which Microsoft had fixed in early versions of the browser, reappeared in later versions.

Microsoft acknowledged the latest issue and said more fixes would be forthcoming.

"The company is working to provide a series of security updates to Internet Explorer in coming weeks that will provide additional protection for customers," a company representative told CNET News.com. The company will also "continue to actively investigate these reports."

The most recent flaw is not new--security researchers first discussed the issue in January, Kuperus said. It had originally been considered minor, but the flaw is significant because it can be used in conjunction with the two other vulnerabilities, which were found at the beginning of June. Together, all three add up to easy access to Windows computers running Internet Explorer.

"Most exploits we are seeing developed today are composed of multiple vulnerabilities, (each one) bypassing a specific security feature of Internet Explorer," Kuperus said. "Individually, many of these issues often are fairly harmless, but combined they can pose serious risk."

Both the original and the latest vulnerabilities exist in a library of components and scripting features known as ActiveX. The older flaw is in ADODB.Stream, while the latest vulnerability is in the Application.Shell component.

Vulnerabilities in IE have become so common that some security researchers are recommending that people adopt alternate browsers. The Computer Emergency Response Team, the official U.S. body responsible for defending against online threats, also advised security administrators to consider moving to a non-Microsoft browser, as one of six recommended responses.

Microsoft recommends that users go to the company's Protect Your PC site for the latest information.

  • Talkback
  • Most Recent of 133 Talkback(s)
Re: Maybe not...
modify an x86 emulator, specifically for IE, and run it in a sandbox environment (similar to Java).

That would at least stop the spread of viruses and adware.
________________________
(Read the rest)
Posted by: Me_too Posted on: 07/11/04 You are currently: Logged In | Log out
Is this new? Spoon Jabber   | 07/07/04
Of course it's new... new day, new flaw..! Xunil_Sierutuf   | 07/07/04
Mozilla is great, love tabbed browsing FilledOut   | 07/07/04
I don't like tabbed browsing FirstNLastN   | 07/07/04
Done that... didn't like it. el1jones   | 07/07/04
Opera is another choice rbochan   | 07/07/04
Me neither.. d_jedi   | 07/07/04
Opera can do that randomletter   | 07/08/04
Poof! Yagotta B. Kidding   | 07/07/04
I love tabbed browsing carmanintx   | 07/07/04
Don't use it then. Immanuel Tranz-Mischen   | 07/07/04
Terrorist Researchers dend   | 07/07/04
8.0 Martin Marvinski   | 07/07/04
tabbrowser extension dend   | 07/07/04
Why? Linux User 147560   | 07/07/04
Umm... Martin Marvinski   | 07/07/04
MS is the energizer bunny of flaws! Xunil_Sierutuf   | 07/07/04
This is why... Michael Kelly   | 07/07/04
Flaws fixed faster Linux User 147560   | 07/07/04
Flaws In MS agottschald   | 07/07/04
Why not just release SP2 early? soma@...   | 07/07/04
No it's not better Linux User 147560   | 07/07/04
Umm... can it get any worse? Xunil_Sierutuf   | 07/07/04
True, why break a tradition now.. Xunil_Sierutuf   | 07/07/04
Beta testing... Martin Marvinski   | 07/07/04
Everyone is expecting SP2... bjbrock   | 07/07/04
Joe and Jane internet user rbochan   | 07/07/04
I believe you are quite right. agottschald   | 07/07/04
Another layer of unsecure computers will be created & unaddressed Squawkbox   | 07/07/04
why not just do a better job of educating Joe and Jane? ryusen   | 07/07/04
The Drum Roll Is Getting Stronger - CLASS ACTION CLASS ACTION RobertoSalazar   | 07/07/04
Bring on the common sense instead SublimeDaze   | 07/07/04
There is nothing sensical about... bjbrock   | 07/07/04
The problem with class action lawsuits ryusen   | 07/07/04
The problem with class action lawsuits richdave   | 07/07/04
chicken or egg? ryusen   | 07/07/04
Hmm.. d_jedi   | 07/07/04
Lawsuit might be baseless Allstar_z   | 07/10/04
Switching Would Be Stupid.... chrislovesdana   | 07/07/04
Hey, can I get some of that... Spoon Jabber   | 07/07/04
I think that "stuff"... bjbrock   | 07/07/04
After 10 years... bjbrock   | 07/07/04
Ugh, I can'e believe how wrong people are jsilve1   | 07/07/04
Awww what is a few years amongst friends? Squawkbox   | 07/07/04
You are being overly critical SilentTygur   | 07/07/04
the problem eLurker   | 07/07/04
Mozilla's been around longer OhMyGosh   | 07/07/04
actually... ryusen   | 07/07/04
You're right, but... Immanuel Tranz-Mischen   | 07/07/04
good point but... ryusen   | 07/07/04
NOT switching would be stupid jsilve1   | 07/07/04
Reliability is FAR more important than innovation martyj   | 07/07/04
LOL Linux User 147560   | 07/07/04
2 apps SC-man   | 07/07/04
Really cdjmattmiller@...   | 07/07/04
debugging rbochan   | 07/07/04
Again: You don't know what you're talking about escoles@...   | 07/07/04
Yes, but look at the facts... riff7raff   | 07/07/04
Yes, but look at the facts... richdave   | 07/07/04
Is that you, Mike? Daisy Fontana   | 07/07/04
I just get some ID10+ error... php_developer   | 07/07/04
Wanna be Mike Cox bchesmer   | 07/07/04
Switch browsers -yes! mhoyle   | 07/08/04
Business as usual tic swayback   | 07/07/04
Re: Business as usual issthatso   | 07/07/04
i think you are holding apple in too high a light... ryusen   | 07/07/04
You're right. Immanuel Tranz-Mischen   | 07/07/04
you missed my point... ryusen   | 07/08/04
SP2 won't fix a basic design flaw issthatso   | 07/07/04
If it did fix XP's problems what about the legacy ware out there? Squawkbox   | 07/07/04
Every move by MS just opens more holes! George Mitchell   | 07/07/04
MS wasn't allowed to fix certain "security holes" toomuchgreeatea@...   | 07/07/04
Microsoft : The hackers target of choice riff7raff   | 07/07/04
Hmmm Spoon Jabber   | 07/07/04
MS products are still easier to use Eggs Ackley_z   | 07/07/04
Than *what*?! escoles@...   | 07/07/04
...I don't think so! settantta   | 07/07/04
RTFP Eggs Ackley_z   | 07/08/04
Switching Browsers tgrkss   | 07/07/04
Aww c'mon - think of something more stupid Eggs Ackley_z   | 07/07/04
If this is Mike Cox, then you get 1.5 score (NT) Judas I.   | 07/07/04
Just to prove it, anecdotally ... Eggs Ackley_z   | 07/07/04
Re: Switching browsers and Mozilla rkelleher_1   | 07/07/04
Sorry, man, you don't know what you're talking about. escoles@...   | 07/08/04
Ya right... bchesmer   | 07/07/04
At first I thought you were skeptic tank   | 07/07/04
more is not alway the right reason. agottschald   | 07/08/04
<sigh> Alright, one more time: IE IS FUNDAMENTALLY INSECURE escoles@...   | 07/08/04
The answer is don't use IE woody_z   | 07/07/04
BINGO Partisan   | 07/08/04
Microsoft is MACRO INCOMPETENT! martyj   | 07/07/04
Six year-old child needed andy88488   | 07/07/04
which websites? toadlife   | 07/07/04
Incompatible Websites andy88488   | 07/08/04
More please zen_dogen   | 07/08/04
Then use IE for those sites. Next? escoles@...   | 07/08/04
If.... Monkey_MCSE   | 07/07/04
The M$ way DarthRidiculous   | 07/07/04
Utopian Thinking andy88488   | 07/08/04
A fully-compatible emulation of IE Me_too   | 07/07/04
Maybe not... Allstar_z   | 07/10/04
Re: Maybe not... Me_too   | 07/11/04
Fully Compatible Yagotta B. Kidding   | 07/07/04
Internet Explorer tazwalker@...   | 07/07/04
IE Favorites Eggs Ackley_z   | 07/07/04
Exactly Monkey_MCSE   | 07/07/04
Microsoft recommends what? Me_too   | 07/07/04
"They should have seen this one coming." Yagotta B. Kidding   | 07/07/04
Only a Crackhead would switch at this point. chrislovesdana   | 07/07/04
I think I may have found the true definition of Idiot... Monkey_MCSE   | 07/07/04
I sure won't switch TWRX   | 07/07/04
You finally got one right! IT_User   | 07/07/04
Thank you... Partisan   | 07/08/04
Enterprise Analyst Expatriate US Geek   | 07/07/04
IE is still the main browser Enterprise Analyst.   | 07/07/04
By all means, keep using it, please. Immanuel Tranz-Mischen   | 07/07/04
Only if we were so lucky! Linux User 147560   | 07/07/04
IE is the main browser ... ONLY because MS ILLEGALLY tied it to the OS. Bit's_Conscience   | 07/07/04
Main browser for what? IT_User   | 07/07/04
You left out.... Partisan   | 07/08/04
Not as good as your usual posts Expatriate US Geek   | 07/08/04
IE - A security hole pretending to be an app wonderbored   | 07/07/04
CLASS ACTION LAWSUIT for GROSS NEGLIGENCE !!! Bit's_Conscience   | 07/07/04
The Final Solution. agottschald   | 07/07/04
of course its never the hackers fault... zijiang   | 07/07/04
Who said it cleared them? IT_User   | 07/07/04
Wake up agottschald   | 07/07/04
Computer Emergency Response Team, jgoodman_z   | 07/08/04
What's new? tslocum7   | 07/08/04
FireFox 0.9 ROCKS...IE SUCKS!!! itanalyst   | 07/08/04
May I have the envelope please? Squawkbox   | 07/09/04
Even Slate recommends FireFox/Mozilla. . . boomslang_z   | 07/09/04
Blame the web developers... Allstar_z   | 07/10/04

What do you think?

advertisement
advertisement