ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Microsoft's Gopher hole deepens

Joe Wilcox, CNET News.com CNet

Published: 13 Jun 2002 09:08 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft issued a "critical" security alert about a hole in its Internet Explorer browser that could allow hackers to use an outdated Internet protocol to seize control of people's computers.

As previously reported, the exploit uses Gopher, an all-but-obsolete Internet protocol for fetching data from remote computers. Finnish security company Online Solutions uncovered the vulnerability on 20 May and alerted the public last week.

But the threat is much worse than first revealed by Online Solutions. The hole also exists in some Microsoft server products. Microsoft deemed the threat critical for client computers running Internet Explorer 5.01, 5.5 and 6.0 and for Internet or intranet servers running Proxy Server 2.0 or ISA Server 2000.

In the service bulletin, issued late Tuesday, Microsoft noted that older versions of its server products could be vulnerable, but the company said it didn't do any testing "because previous versions are no longer supported". Likewise, older Internet Explorer versions could be vulnerable. Microsoft does not offer fixes for these older versions.

The problem results from an "unchecked buffer in the code which handles information returned from a Gopher server," Microsoft explained in the security bulletin.

Gopher has largely disappeared from use, replaced for the most part by the HTTP protocol accessed using Web browsers.

But IE still supports the archaic protocol, which can be used to exploit a buffer overflow bug and expose a client computer to a server running malicious code. A hacker could then seize control of the client computer, with full ability to access data, copy files or install programs, among other tasks.

The hole is especially problematic because an IE user doesn't have to connect to a Gopher server; code inserted in a Web page or an HTML email could redirect the person's computer to such a server.

With server products, the impact could be more serious, with the attacker able to take complete control over the server. The hacker could reformat the hard drive or create new administrator accounts for accessing the server as a seemingly legitimate user, with full access to features or network services.

Existing security settings could thwart or diminish the threat, however, such as any setting that blocks Gopher. "If a user were prevented by security policies from deleting files or changing security settings, the attacker's code would also be prevented from those actions," the bulletin states.

Still, even the strictest security settings might not be enough to prevent an attack. Microsoft noted, for example, that people with Outlook e-mail settings set to the "Restricted Zone" would still be vulnerable via HTML email.

Microsoft has yet to issue patches for the security hole but is offering instructions for a temporary fix to the problem. One solution for servers is to block access to TCP port 70, which prevents Gopher protocol access.

IE users must take the more cumbersome approach of manually blocking Gopher access. One can do this by going to the Tools menu and accessing the "LAN Settings" under "Connections". Uncheck the "automatically detect settings" box and check the "use Proxy server for your LAN" box. Under the "Advanced Tab", make sure the "use the same proxy server for all protocols" box is unchecked. Finally, go to the Gopher text field and enter "localhost" and "1" in the port setting box.

Microsoft offers further instructions about the temporary fixes in the 11 June security bulletin.

This newly reported vulnerability is just one in a recent string of Microsoft security problems, despite increased emphasis on security following a companywide memo from chairman Bill Gates in January.

Last week, Microsoft issued a security alert for ASP.NET, a collection of software for building Web-based applications. Other recent Microsoft security glitches include a pair of problems affecting how IE handles cookie files; an IE cross-scripting bug; a buffer overflow exposing MSN Messenger and Windows Messenger to hackers; and a potential breach of MSN Messenger's chat features; among others.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
34 out of 77 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

ASP.NET web developer - 3 month contract - West Yorkshire

ASP.NET web developer ASP.NET web developer with previous experience of php and ruby is required for a 3 month contract. Essential skills: - ASP.NET, ...

Classic ASP / ASP.NET / Web Developer Needed

I am currently working for a FTSE 100 company based in East Grinstead who are looking to take on a .net developer permanently. My client are a ...

C# Developer C#, ASP.NET, SQL Server, SharePoint - Oxfordshire REF:2103

C# Developer C#, ASP.NET, SQL Server, SharePoint - Abingdon, Oxfordshire, South East UK - REF:2103 Would you like to hone your C# / ASP.NET / SQL ...

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains