Advertisement
Promo

Online business Toolkit

IE 5.5 exploit evades security feature

Will Knight ZDNet.co.uk

Published: 07 Sep 2000 15:26 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The latest in a long line of bugs to hit Microsoft's Internet Explorer will allow unauthorised access to files on a victim's computer, according to respected Bulgarian bug-hunter, Georgi Guninski.

The "IE 5.5 Cross Frame security vulnerability" uses JavaScript, a Web page scripting language, to bypass security features built into Internet Explorer. It allows the contents of a file to be sent back to Web server when a page containing the mischievous JavaScript is visited.

Guninski outlines this vulnerability on his Web site where he also provides a demonstration of the exploit in action. Although Microsoft is reportedly working on a fix, there is currently no patch. Guninski recommends users disable active scripting to be safe.

Security has become something of a regular concern for Microsoft's Internet Explorer browser and some experts believe this latest issue is an especially serious problem.

"It is very significant because cross site scripting was touted as a new security feature," says Greg Jones, senior security engineer with consultancy firm Information Risk Management. "They've [Microsoft] dug their own grave, to an extent."

The bug might also leave Microsoft particularly red faced considering that the software giant recently released Advanced Security Privacy, a Beta program designed to increase the security of Internet Explorer 5.5 and give users greater control over tracking features such as cookies.

Security experts stress the particular security hole poses only a minimal threat to Internet users. However, it may be better to be safe than sorry, they say. "You need to keep up to date with the news," advises Deri Jones, marketing manager for DTA Monitor. "The only way [companies] can really find out whether they are secure is to get security tested. That is where the rubber hits the road."

Take me to the Hackers News Special

What do you think? Tell the Mailroom m And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
46 out of 78 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters