ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Bug hunters find 'cookie' hole in IE

ZDNN, US ZDNet US

Published: 12 May 2000 08:39 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Computer bug-hunters have pointed out a way to snare personal information from a "cookie" file if the victim uses Microsoft Internet Explorer and clicks on a disguised string of JavaScript code. Microsoft said it was working on a patch for the security hole. The potential vulnerability was reported Thursday by Bennett Haselton and Jamie McCarthy on the Peacefire.org Web site.

Haselton, who organised Peacefire as an anti-censorship group for young people, has worked on methods to circumvent content-blocking software in the past. More recently, he has pointed out a series of Web-based vulnerabilities involving Hotmail email accounts as well as Microsoft and Netscape browsers.

This glitch involves the way Microsoft Internet Explorer interprets Web addresses, known as uniform resource locators or URLs, for providing access to cookie information. Cookies are short text files stored on your computer that contain data on preferences or perhaps even passwords for particular Web sites.

Here's how the cookie-stealing technique works, as explained by Haselton: When a user connects with a Web site, the browser looks at the address you type in (for example, www.amazon.com) to determine whether it should provide access to a particular cookie. In this example, the Amazon.com Web server would be given access to the Amazon.com cookie.

Haselton constructed a JavaScript program to demonstrate how Internet Explorer could be fooled into thinking that it was opening access to cookie information for a particular site, when it was actually allowing the cookie to be sent to the Peacefire.org server.

He replaced the slashes and a question mark in a long Internet address with an alternate string of hexadecimal characters -- such as "%2f" and "%3F." Those characters were interpreted in such a way that the browser connected with Peacefire's site, but opened access to another specified site's cookies. A user would have to be coaxed into clicking on a button or a link that would activate the cookie-stealing code.

Haselton acknowledged that cookies don't generally store a user's most sensitive personal information, such as credit card numbers. However, some free email sites such as Hotmail and Yahoo! use cookies to authenticate users if they were already logged in to the sites.

"You could gain access to their account until the next time that they log out," Haselton told ZDNN. When the user logs out, that clears the cookie file. Cookies are also used by e-commerce sites to keep track of a user's "shopping cart." Amazon.com's cookie could provide information about a person's taste in reading material, although the user's actual purchases are not recorded in the cookie, Haselton said.

A determined break-in artist could harvest information from cookies for sites such as NYTimes.com, decipher the usernames and passwords, then try using that same login information at other Web sites, he said.

There was no sign Thursday that the technique was being used "in the wild" for malicious purposes. The vulnerability was found in Internet Explorer for Windows 95, 98 and NT, but not in the version of the Microsoft browser for Macintosh or Unix.

Microsoft said that the security hole could cause trouble, but that there were ways to avoid problems.

"Microsoft is committed to protecting customers' information," the company said in a statement, "and we are developing a patch that eliminates a security vulnerability involving the handling of cookies by IE. We expect to deliver the patch shortly. A security bulletin will be published at www.microsoft.com/technet/security/default.asp to discuss the issue and advise customers how to obtain and apply the patch."

The company pointed out that "customers who have used the IE Security Zones feature to disable Active Scripting on sites they don't trust could not be affected by this vulnerability."

Haselton and McCarthy advised Internet Explorer users to disable JavaScript until the fix was in. A spokeswoman for Microsoft said the company had no comment on that advice.

Concerns about online security have taken a higher profile since this month's worldwide distribution of the "Love" bug email worm.

How much innovation are we getting in Microsoft's world? Nada. Zip. Zilch. Microsoft Word will put a squiggly line under a misspelled word, but that "innovation" took about five years to develop. John Dvorak says the company's scorched-earth policy is dooming it.

What do you think? Tell the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
45 out of 85 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:















Related Jobs

Web Project Manager/Web Services Architect 150 - 180 p/d 12months

Knowledge of, JavaScript, ; Familiarity with scripting languages such as J2EE, Power Shell, Python or Perl; Familiar with the MS technologies such as ...

Perl Developer-Perl, JavaScript, MySQL, SOAP, Apache, Perl Developer

You will have excellent web skills; HTML and JavaScript, a good exposure to PHP, Ajax, CSS and XML. Market Leader seeks experienced Perl Developer to ...

JavaScript / AJAX / Web 2.0 development role

They are using technologies such as XSLT, CSS and JavaScript and XML. They are looking for someone who is a VERY technically adept at JavaScript and ...

Sentry Posts Blog

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment

Trades Unions against ID Cards

The Trades Union Congress (TUC) has backed up airport workers protesting against ID cards, the Financial Times reports. In a letter to Home Secretary Jacqui Smith, the TUC said it... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains