ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Netscape flaw worse than 'Back Orifice'?

Bob Sullivan, MSNBC ZDNet.co.uk

Published: 08 Aug 2000 09:54 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The flaw is rather straightforward -- programmers can tell a Java applet included in the browser to display a directory of what is on the victim's hard drive. Victims must visit a Web page that has been designed with the malicious code to be vulnerable.

The vulnerability was discovered recently by a security expert and posted to the BugTraq mailing list Friday night. In his message, Dan Brumleve released an example of the vulnerability and called it Brown Orifice, an allusion to the infamous computer vandal tool Back Orifice.

But "Brown Orifice" only allows computer vandals to view and read a victim's files, whereas Back Orifice allows an intruder to actually take complete control of a victim's computer remotely.

However, security expert Chris Rouland thinks the Netscape flaw may be a more serious problem than Back Orifice. "With Back Orifice, people had to do something to infect themselves. With this, everyone who uses Netscape has this problem," he said.

A spokesperson for Netscape confirmed the company was looking into the flaw.

"We are working to quickly evaluate and address this... In the interim, users can protect themselves by simply turning off Java."

Netscape users select edit, then preferences, then advanced options, and then uncheck enable Java and enable Javascript.

The flaw affects most versions of Netscape, including Linux and Windows versions. The problem lies in four Java components which can be tricked to turn a standard PC into a Web server, and then allow that Web server to display the contents of its hard drive.

"I'm surprised [the problem] is still in there," Brumleve, 22, said. "It's kind of obvious, really."

The second half of the flaw involves two parts of Java called "Netscape.Net.URLInputStream", and Netscape.Net.URLConnection". They are designed to allow programmers to display Web pages within the browser -- but Brumleve discovered the applets can just as easily be told to display local files instead.

On Brumleve's demonstration page, he offers visitors a chance to see the vulnerability in action by volunteering to submit their computers to it. Hundreds have apparently taken him up on the offer, as there are many links to computers that have allegedly been accessed using this method, starting at midday Sunday. But none of the links worked when visited at midday Monday.

There are a number of vulnerabilities that allow some kind of malicious access to a victim's computer through a specially crafted Web page -- none has become a widespread problem rising to the level of a computer virus, which can spread on its own.

Still, Elias Levy, who administers the BugTraq list, described the bug as "somewhat powerful" and potentially dangerous.

"In this day and age the line between Web pages and emails is blurring," he said. "You can run a Web page from the preview pane in Microsoft Outlook, for example."

Take me to the Summer of Hacking Special

Take me to Hackers

What do you think? Tell the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
61 out of 136 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

Business Analyst - Wealth Management / Private Banking

You will serving as a subject matter expert, assisting in workshops, identify service gaps, assist clients with analysis and development of workflows ...

Communication Engineer - Utilities - Smart Metering

Purpose of the role is to provide expert advice and support on communication methods and protocols, including WAN, LAN and LPR that can be employed ...

Graduate Opportunities with Prophet Plc - C++ Programmers

Graduate opportunities with Prophet Plc Job Title: C++ Programmers Location: Meriden, nr Birmingham and Coventry Salary: Competitive, with benefits ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments