Advertisement
Promo

Online business Toolkit

ActiveX script for disaster highlights IE security flaw

Rupert Goodwins ZDNet.co.uk

Published: 08 Apr 1997 20:32 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Internet Explorer users running Windows 95 may be open to a whole new range of Net-hosted attacks. A demonstration of a potentially lethal interaction between software components, detailed on our sister publication Windows Sources' Web site, has shown how software that has been certified by IE's Authenticode security system can be controlled by uncertified -- and uncertifiable -- Web scripts.

In brief, the problem arises when a utility or other program uses an OCX file or other component that can be controlled by a script. In this case Symantec's Norton Utilities 2.0 has a scriptable component called TUNEOCX.OCX: ActiveX-aware Web pages can detect this and feed it instructions. Because TUNEOCX.OCX is a legitimate module, installed as part of a shrink-wrap commercial package, it has full access to all local applications including email, DOS's FORMAT and FTP commands, and anything else that might be on the system. Scripts for it can be written in plain text resembling a simple DOS batch file, embedded in a Web page and passed directly to the component without any form of security authentication or user interaction. ActiveX's certification only applies to executables, and there is no other security provided on Windows 95.

This is the first instance of a problem long predicted. PC Magazine UK and ZDNet UK staff have often raised this and similar possibilities with Microsoft technical staff, to be told that such problems were hypothetical and very unlikely to occur in real life. In theory, any widely spread client software with scriptable ActiveX components is vunerable to this threat. There is no way of guarding against it short of disabling all ActiveX scripting within IE. Any plug-in which treats data from the Web as scripts, remain potential wormholes through which carelessly written or actively hostile actions may pass: Macromedia's Shockwave had just such potential, but has been recently fixed.

No wholly satisfactory solution for ActiveX on Windows 95 is in sight. Java components on any platform are inherently secure against script attacks, since the range of actions Java programs can perform is severely limited. Windows NT has inherent security that can be configured to protect the system from any software the user may run. The combination of Internet Explorer, Windows 95 and scriptable third-party software is and will remain potentially dangerous.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
49 out of 79 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters