ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

IE flaw introduces new form of infection

Published: 23 Aug 2004 08:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

An independent researcher warned that an Internet Explorer vulnerability could turn drag-and-drop into drag-and-infect, even on computers updated with Microsoft's latest security patch.

The flaw affects the latest version of Internet Explorer running on Windows XP, even after the latest major update -- known as Service Pack 2 -- is applied. An attacker using the flaw could install a program on a victim's computer after convincing the person to visit a malicious Web site and click on a graphic.

The attacker's program would be placed in the Windows startup folder and would run the next time the user restarted the computer. The security researcher who discovered the flaw, known by the online nickname "http-equiv," posted an example to show the power of the flaw.

"If you look at the Web page, all you see are two red lines and an image; drag the image across the two lines and drop it," he said. "What you have actually done is drop (a program) into your startup folder. Next time you switch the computer on it runs the program."

Security information company Secunia believes the program that takes advantage of the issue could be simplified to only require a single click from the user. Secunia rated the flaw as "highly critical," its second-highest rating of vulnerability threats.

Microsoft said the issue did not pose a serious risk to users because it requires an attacker to trick people into visiting a Web site and taking some action at the site.

"Given the significant amount of user action required to execute an attack, Microsoft does not consider this to be a high risk for customers," a company representative said, adding that the software giant's security experts are continuing to research the issue.

Security researchers predicted that vulnerabilities would quickly be found in Windows XP Service Pack 2, or SP2. The drag-and-drop flaw is perhaps the most serious found to date in computers that have been patched with Microsoft's major security update.

Service Pack 2 promises to add better security to Windows XP's handling of network data, program memory, browsing activity and email messages, by changing the system's code and configuration. A revamped firewall, for example, attempts to prevent malicious applications on a PC from connecting to the Internet by requiring that the user give specific permission for each attempt.

The SP2 software, which took almost a year to develop, is seen by many as a response to the attack launched by the MSBlast worm on 11 August, 2003. Almost 26 days before, Microsoft had issued a patch for the security hole exploited by the worm. However, many people did not install the fix, even though there was widespread expectation that a virus would be created to take advantage of the flaw.

Ironically, this time around, most people have not had a chance to update their computers with the security patch. The update became available only on Wednesday and will require almost a month to reach every Windows XP user who wants the software, Microsoft said.

Even so, security researcher "http-equiv" believes that the software giant's latest patch does its job.

"The patch really does lock down the machine nicely, and whatever anyone finds now will be completely different to the previous year's findings," he said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
90 out of 185 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Linux Systems Administrator - Linux Windows XP, Network Connectivity

Linux Administrator - Linux Redhat Systems Administrator Windows XP, Network Connectivity, Backup, DR, Market Data (not essential Reuters / Icap). ...

3rd Line Support (Windows Server 2003, Windows XP, MS Exchange, AD)

I am looking for a 3rd Line Support Engineer for a contract role in Southampton, Hampshire. To be considered for this opportunity you must be able to ...

Flash Action Script Developers Merseyside - Contract

Flash Action Script Developers Merseyside My client based in Merseyside seeks two talented freelance Flash and ActionScript developers. Key Skills ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment