ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Mystery 'researchers' are revealing IE flaws

Dan Ilet ZDNet.co.uk

Published: 19 Nov 2004 13:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security company Secunia says is perplexed by the motives of 'researchers' who recently published details of Internet Explorer 6.0 vulnerabilities and exploits on the Web.

The company said it did not know why people were particularly keen to publicly expose holes in IE before informing Microsoft. The researchers announce their findings online, sometimes anonymously, and their activities hover somewhere between the publicly documented work of the professional security companies, and the hacking community.

"This is a new researcher and I don't know what his reasons are," Thomas Kristensen, CTO of Secunia. "But it's available out there on exploit. He's got a sample of how it's done. With this vulnerability it's necessary to prove how it works. But this tends to be the trend with IE vulnerabilities. The researchers build the exploit before the fix can be released. Why that is, I don't know."

Kristensen said Secunia was talking to Microsoft to help the company fix the problem.

"We have talked to Microsoft. They are working on the case. They need some time to look at this, but we won't disclose details of how they are working on the patch."

Earlier this week, Microsoft lashed out at researchers for failing to act responsibly by not disclosing vulnerability details to it first.

Three vulnerabilities were discovered in IE 6.0, which Secunia published advisories about after it found them posted on a Web site by a researcher called 'cyber flash'. Kristensen said it was the company's policy not to reveal vulnerability details until a fix had been provided -- unless they were already in the wild.

Earlier this month, the software giant chastised another group of researchers for publishing details of an IE buffer overflow vulnerability on the Web before it had a chance to fix the problem.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
43 out of 104 people found this useful


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Team Manager - Intensive

Delivery of optimal customer service Fanatical SupportTM - Minimisation of downtime via proactive technical intervention - Technical and customer ...

Service Delivery Manager - Customer Development & Food solutions - IT Manager - St. David\'s Park, Teeside , North West

Recognises, and actively seeks ways to exploit information technology to address complex business, organisational and technical issues, of both a ...

ICT Manager - NSQI (Part-time

University of Bristol ICT Manager - NSQI (Part-time) 36,912 pro rata The Nanoscience and Quantum Information building is an exciting new ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment