Advertisement
Promo

Security threats Toolkit

Mystery 'researchers' are revealing IE flaws

Dan Ilet ZDNet.co.uk

Published: 19 Nov 2004 13:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security company Secunia says is perplexed by the motives of 'researchers' who recently published details of Internet Explorer 6.0 vulnerabilities and exploits on the Web.

The company said it did not know why people were particularly keen to publicly expose holes in IE before informing Microsoft. The researchers announce their findings online, sometimes anonymously, and their activities hover somewhere between the publicly documented work of the professional security companies, and the hacking community.

"This is a new researcher and I don't know what his reasons are," Thomas Kristensen, CTO of Secunia. "But it's available out there on exploit. He's got a sample of how it's done. With this vulnerability it's necessary to prove how it works. But this tends to be the trend with IE vulnerabilities. The researchers build the exploit before the fix can be released. Why that is, I don't know."

Kristensen said Secunia was talking to Microsoft to help the company fix the problem.

"We have talked to Microsoft. They are working on the case. They need some time to look at this, but we won't disclose details of how they are working on the patch."

Earlier this week, Microsoft lashed out at researchers for failing to act responsibly by not disclosing vulnerability details to it first.

Three vulnerabilities were discovered in IE 6.0, which Secunia published advisories about after it found them posted on a Web site by a researcher called 'cyber flash'. Kristensen said it was the company's policy not to reveal vulnerability details until a fix had been provided -- unless they were already in the wild.

Earlier this month, the software giant chastised another group of researchers for publishing details of an IE buffer overflow vulnerability on the Web before it had a chance to fix the problem.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
43 out of 105 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters