ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Microsoft complains about 'irresponsible' security revelation

Dan Ilet ZDNet.co.uk

Published: 10 Nov 2004 12:28 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft has slammed the people responsible for publishing details of the vulnerability that has lead to the creation of the bofra virus.

The software giant, which has yet to release a patch for the flaw, said that the vulnerability was not reported in a responsible fashion.

In a prepared email statement from a Microsoft spokesperson, the company said: "Microsoft is concerned that this new report of a vulnerability in Internet Explorer was not disclosed responsibly, potentially putting computer users at risk. We continue to encourage responsible disclosure of vulnerabilities. "

"We believe the commonly accepted practice of reporting vulnerabilities directly to a vendor serves everyone's best interests, by helping to ensure that customers receive comprehensive, high-quality updates for security vulnerabilities with no exposure to malicious attackers while the patch is being developed."

The bofra virus, which antivirus companies initially believed to be a MyDoom variant, emerged on Monday after the vulnerability it was based on was published last week on a Web chat forum.

On Friday security firm Secunia issued an advisory on the vulnerability, saying that the flaw was 'extremely critical'. Chief technology officer for the company Thomas Kristensen said that 'Ned', the individual who initially found the bug, stumbled across it when testing browsers when using a publicly available tool. The tool crashed IE, so he posted a question on an Internet forum asking others to look at why the program had failed. With some additional research from others in the community, it came to light that the IFRAME flaw was causing the crash.

"Microsoft is right that those who disclose this kind of thing are irresponsible," said Kristensen. "But in this case, it's slightly different because he [Ned] published the first part and they [the other researchers] published the second part. And he didn't do it -- it was done with a tool. If you find a crash in a browser, you might not know if it's serious or not. He might not have been able to test that."

The bofra virus sends out hundreds of emails from an infected machine. The reader on the target machine follows a link sent in the email, which leads to a Web site hosted on the original infected PC. The IE exploit on that Web site turns the computer into another infected machine, and the cycle starts again. All version of the worm also open a back door to the infected computers.

Microsoft has yet to release a patch for the IE vulnerability, but advised users to upgrade to Windows XP SP2, which is apparently unaffected by the flaw.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
88 out of 190 people found this useful


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Security Consultant - Immediate start

The desired candidate will have the following skillset: * Network Vulnerability Internal & External Testing * Configuration of Cisco switches / ...

Information Security Engineer - C++ or Java - London and EMEA

You will be performing security audits, risk analysis, application-level vulnerability testing and security code-reviews on a wide variety of ...

Systems Administrator/ MCSE/ Server2003/ AD/ Exchange/ London/Retail

Systems Administrator/ MCSE/ Server2003/ AD/ Exchange/ MOM/ WINS/ TCP/IP/ Shift Work/ Patch Management/ Print Server Management. My client is looking ...

Sentry Posts Blog

Working@Home: Keeping Secure

National Work from Home Day has come and gone, with an estimated five million people skiving to enjoy the comforts of their home. However, even though employees sat comfortably, IT... More

Post a comment

Privacy International director launche...

Simon Davies, who has been involved with campaigning on privacy issues for a number of years, is launching a privacy consultancy firm called 80/20. Half of all profits will be donated... More

Post a comment

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation