Advertisement
Promo

Security threats Toolkit

New Windows XP SP2 vulnerability exposed

Munir Kotadia ZDNet Australia

Published: 22 Nov 2004 12:50 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

According to security Web site K-otik, which is no stranger to controversy, it may be possible to create a custom "Error 404" message to disguise an executable file as 'safe' HTML code.

Error 404 messages are usually displayed when the browser cannot locate an Internet address.

According to K-otik, which has published exploit codes that take advantage of the flaw, it is possible to craft a special error message that is able to bypass a security function in IE that was created to warn users before they download potentially harmful content.

The advisory on K-otik's Web site states that although there is some user interaction required to exploit the vulnerability, it may be possible to fool a user into downloading and executing a malicious file by using a simple social engineering technique.

According to the advisory, a malicious Web site could prompt all its visitors with a standard grey dialogue box welcoming a user to the site before allowing access to the site's content. If a user clicks on the welcome box they could unknowingly install a file that gives control of their computer to a third party.

"IE attempts to intercept risky code and prompts a security warning message but it seems to allow custom HTTP errors to filter through those security checks. It may be possible to execute the downloaded file by simply forcing the user to press the Enter key," the advisory said.

On November 15, security firm Finjan claimed it had discovered ten flaws in Windows XP SP2 that could allow attackers to "silently and remotely take over an SP2 machine when the user simply browses a Web page".

According to Finjan, hackers could bypass XP SP2's notification mechanism about downloading and execution of .exe, which could let them download files without warning the user.

The code published on K-otik's Web site seems to exploit the same flaw.

At the time, Microsoft said it was investigating Finjan's claims but tried to play down the severity of the flaws.

In a statement, a Microsoft spokesperson said: "Our early analysis indicates that Finjan's claims are potentially misleading and possibly erroneous regarding the breadth and severity of the alleged vulnerabilities in Windows XP SP2."

Microsoft was unable to comment on K-otik's advisory and could not confirm if both companies has stumbled across the same flaw.

Munir Kotadia reported from Sydney for ZDNet Australia. For more ZDNet Australia stories, click here.

Jo Best of silicon.com contributed to this report.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
82 out of 161 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters