ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Flaws in IE7 and Firefox raise alarm

Joris Evers CNET News.com

Published: 19 Feb 2007 09:53 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft and Mozilla are each working to tackle recently disclosed security flaws in the Internet Explorer and Firefox web browsers.

The vulnerabilities were described earlier this week in postings to a popular security mailing list by researcher Michal Zalewski. Each browser could enable miscreants to grab data via malicious websites, Zalewski said.

In addition, another Firefox flaw could let attackers change cookie files on the user's PC, he said.

In the case of Internet Explorer, the problem affects the latest version, IE7, and probably earlier releases, Zalewski wrote. Microsoft confirmed that the flaw could open up files stored on a PC's hard drive to an attacker, but only if the location of a given file is already known.

"In order to be successful, an attacker in advance would have to convince the user to enter the location of a file into an attacker's web page through social engineering," a Microsoft representative said in an email statement on Friday. The software giant is still investigating the issue and will take "appropriate action", the representative said.

Flaws in Firefox
Firefox is affected by two security holes, both described by Zalewski. One is similar to the Internet Explorer problem, while the other could let miscreants change cookie files stored on a PC running the vulnerable browser. Cookies are small files stored on a PC by websites, to remember login credentials and site preferences, for example.

"The impact is quite severe," Zalewski wrote, regarding the cookie problem, in a posting to the Full Disclosure mailing list on Wednesday. Because cookies can be changed by a malicious website, an attacker can change the way other sites are displayed or how they work, he wrote.

Firefox developers, co-ordinated by Mozilla, have already crafted a fix for this flaw, according to a bug entry on the organisation's website. The patch has not yet been made available to the browser's users. Mozilla typically releases updates with a number of fixes, and the next patch release could come soon, according to the site posting. The bugs affect the latest versions of the open-source browser, Zalewski wrote.

"The proposed fix seems to be OK and was provided swiftly," Zalewski wrote in an email interview on Friday. Last week, two other information-disclosure bugs in Firefox were publicised.

Meanwhile, smart internet users should be aware of the websites they visit. Firefox users can also install the "NoScript" add-on to prevent script code from running on websites. This blocks Zalewski's proof-of-concept exploit for the information disclosure bug and will also prevent many other attacks.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
35 out of 39 people found this useful


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Web Developer/Designer

Web Developer/Designer Salary: 19,203 - 21,087 per annum Based: Nottingham The successful Web Developer will: - Working alongside the Graphic ...

WEBSITE DEVELOPER - C# / ASP.NET - Maidenhead - 25 - 32k

My client based in Maidenhead is currently looking for a Website Developer to join the team who specialise in building websites for their clients. ...

QA Team Leader

Requirements - Commercial experience using automated testing tools (ideally EMPIRIX e-Load, eTester testing tools) - Commercial experience utilising ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment