ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Bofra exploit ticks away at Microsoft

Dan Ilet ZDNet.co.uk

Published: 26 Nov 2004 12:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

After more than two weeks of investigating the IFRAME Bofra exploit, Microsoft has yet to announce when it will be able to fix the problem.

The software giant was unable to provide any further answers to ZDNet UK as to when it expects to resolve the flaw for its customers. In a prepared email statement from the company, a spokesperson said: "Microsoft is actively investigating new public reports of a criminal attack, known as Bofra, attempting to exploit a vulnerability in Internet Explorer's treatment of an HTML element known as IFRAME." The spokesman added that Microsoft is working to forensically analyse the malicious code in Bofra and "will work with international law enforcement to identify and bring to justice those responsible for this malicious activity".

The exploit affects Internet Explorer 6.0 on Windows 2000 and XP SP1. Computers running SP2 are said not to be affected by the exploit.

Earlier this week, several Web sites were hit with banner ad Bofra exploits that directed users to other sites and downloaded malicious code onto their machines.

Analyst company Gartner has predicted that hackers will increase their use of the banner ad attack because of its wide-spread effectiveness.

The software giant added: "Microsoft is taking this vulnerability very seriously; accordingly an update to correct the vulnerability is currently in development. We will release the security update when the development and testing process is complete, and the update is found to effectively correct the vulnerability."

Microsoft has attacked independent researchers who made the IFRAME flaw publicly available. Within a few days of its publication, hackers had created an exploit for the vulnerability.

The company said that people who believe they have been attacked should contact their local law enforcement agency.

 

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
78 out of 162 people found this useful



Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Windows desktop analyst - 1st & 2nd line support, XP,AD, Exchange 2003

Desktop support analyst- 1st / 2nd line support Windows XP, 2003, AD, Exchange, Blackberry, Desktop / User Support - 60 user - Financial Great ...

Senior Support Engineer - Windows 2003, AD, Exchange - Gloucester

The ideal candidate will be have a skill set to include as many of the following: Windows 2003, Exchange 2003, AD, UNIX, TCP/IP, VoIP, IAS and VoIP. ...

Messaging Support Analyst (AD,TREND protection,Exchange) BANKING

You will be supporting Microsoft Exchange, Windows Server, AD, TREND (virus protection) Blackberry Enterprise Server, MindAlign & Mailmarshal. Highly ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment