ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Microsoft IE bug leaves users vulnerable to phishing

Ingrid Marson ZDNet.co.uk

Published: 14 Jun 2004 13:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The US Computer Emergency Readiness Team (US-CERT), the net security watchdog, released a security alert on Friday warning of a flaw in Microsoft's Internet Explorer which allows attackers to run programs on a user's computer.

The flaw is in IE's cross-domain security model, which keeps frame content from different sources separate. This means that attackers could run programs and view files using the privileges of the user running IE.

Graham Cluley, senior technology consultant at Sophos, said on Monday that there are no reports so far of viruses or hackers exploiting this vulnerability; however, home users and businesses should be careful while "Microsoft feverishly puts the fix together".

"The flaw is not banking-specific," Cluley said, however, phishers could exploit the flaw to run a key logger, capturing Internet-banking passwords typed on the computer's keyboard. Key loggers can be installed on the computer by worms or Trojans, Cluley warned.

This is more difficult to avoid than the standard phishing attack that involves users entering their details into a fraudulent Web site, having been directed there by a spoofed email.

US-CERT advises that users disable Active scripting and ActiveX controls, maintain antivirus software and do not click on unsolicited links.

A spokesperson for Microsoft on Monday said that the company is currently investigating this bug and will put out a patch as soon as possible. Meanwhile they have updated their advice on how users can "Help ward off hackers and attackers".

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
73 out of 133 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Sentry Posts Blog

Toshiba touts Quantum Key Distribution

Toshiba research scientists have developed a method of distributing quantum keys more efficiently, the company has claimed in a statement: "[Quantum Key Distribution -- ] QKD --... More

Post a comment

Virtual Teams: Small Business Innovati...

Virtual Teams: Small Business Innovation Author: Eric Everson, Founder – MyMobiSafe.com As the founder of MyMobiSafe.com, I’ve found that because of our presence in the industry... More

Post a comment

Mobile Security and Innovation: An Ope...

Mobile Security and Innovation: An Open Case Author: Eric Everson, Founder MyMobiSafe.com The times are changing in the mobile industry as “big wireless” in the US Markets are calling... More

Post a comment