ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

ActiveX script for disaster highlights IE security flaw

Rupert Goodwins ZDNet.co.uk

Published: 08 Apr 1997 20:32 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Internet Explorer users running Windows 95 may be open to a whole new range of Net-hosted attacks. A demonstration of a potentially lethal interaction between software components, detailed on our sister publication Windows Sources' Web site, has shown how software that has been certified by IE's Authenticode security system can be controlled by uncertified -- and uncertifiable -- Web scripts.

In brief, the problem arises when a utility or other program uses an OCX file or other component that can be controlled by a script. In this case Symantec's Norton Utilities 2.0 has a scriptable component called TUNEOCX.OCX: ActiveX-aware Web pages can detect this and feed it instructions. Because TUNEOCX.OCX is a legitimate module, installed as part of a shrink-wrap commercial package, it has full access to all local applications including email, DOS's FORMAT and FTP commands, and anything else that might be on the system. Scripts for it can be written in plain text resembling a simple DOS batch file, embedded in a Web page and passed directly to the component without any form of security authentication or user interaction. ActiveX's certification only applies to executables, and there is no other security provided on Windows 95.

This is the first instance of a problem long predicted. PC Magazine UK and ZDNet UK staff have often raised this and similar possibilities with Microsoft technical staff, to be told that such problems were hypothetical and very unlikely to occur in real life. In theory, any widely spread client software with scriptable ActiveX components is vunerable to this threat. There is no way of guarding against it short of disabling all ActiveX scripting within IE. Any plug-in which treats data from the Web as scripts, remain potential wormholes through which carelessly written or actively hostile actions may pass: Macromedia's Shockwave had just such potential, but has been recently fixed.

No wholly satisfactory solution for ActiveX on Windows 95 is in sight. Java components on any platform are inherently secure against script attacks, since the range of actions Java programs can perform is severely limited. Windows NT has inherent security that can be configured to protect the system from any software the user may run. The combination of Internet Explorer, Windows 95 and scriptable third-party software is and will remain potentially dangerous.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
49 out of 79 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Test Analyst, Experienced Agile, Luton - 36,000+

Identifying test conditions from project documentation and developing test cases and test scripts to cover those conditions. Manage and perform ...

IT Application Architect Middleware

Applicants should take the time to ensure that their CVs clearly describe by engagement or project: - the size of budget needed to deliver the ...

RF / DSP Failure Analysis Engineer - Tewkesbury - URGENT !!! SC ?

Purpose of this Position Failure Analysis of Product to System, unit and component level in order to implement both corrective and preventative ...

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains