ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Microsoft plugs six browser holes

Published: 12 Feb 2002 12:16 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft released a collection of software fixes on Monday to plug six security problems in its Internet Explorer browser, including one that could be exploited to take over a victim's computer.

The advisory deemed as critical a vulnerability in the way Microsoft's browser opens external documents, but about which the software giant would say little for the past two months.

"We have said that the issue is under investigation," said a representative for the software giant.

The software flaw took Microsoft by surprise when a 31-year-old Austin, Texas-based security researcher using the handle "ThePull" posted details of the problem to a security mailing list.

The collection of software fixes, known as a cumulative patch, also fixes two flaws in the way Internet Explorer handles HTML, opens files, and executes certain scripts. The patch is available from Microsoft's Web site.

The release comes 48 hours after two security researchers pointed out that the security hole found in December can be combined with last week's minor privacy flaw in MSN Messenger to hijack MSN accounts.

"The flaw allows a malicious programmer, Web site or email to impersonate you completely," said Thor Larholm, an Internet programmer for Danish portal Jubii and one of two researchers who found the problem. "You can, in essence, use this to remote-control a victim."

Users are urged to download the latest patch.

Larholm, along with British Web developer Tom Gilder, outlined the security slip-ups on their Web site, including the fact that Microsoft posted a set of fixes for the problem last Thursday, but took it down not two hours later.

A Microsoft representative said that an error in the way the patch was distributed caused the company to pull it down and conduct further testing. Any Windows user who had already downloaded the patch during the two-hour window is fine, the representative said.

Both security experts said they were disturbed by Microsoft's slow response, especially with respect to the December security problem found by ThePull.

"Even when Microsoft patches the current round of security holes, it's only a matter of time before someone comes up with another one," said Gilder. "Domain-security related holes are reasonably frequent, and when the next one pops up MSN will be wide-open again."

Finding this one wasn't that difficult, Larholm said. "We sat down for 10 minutes and came up with this."

Microsoft has embarked on an initiative to eliminate such vulnerabilities from its software and services. Recently, in a memo to every employee, chairman Bill Gates stressed that the software titan needs to put security over features.

Gilder said the jury's still out on whether Microsoft is doing just that.

"Microsoft has said a lot of wise words recently, but I've not yet seen many of these actually being put into practice," Gilder said.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
39 out of 75 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

Application Support Analyst

The key tasks for this role include fault diagnosis, second line incident management and the identification and implementation of fixes, work-arounds ...

Sales & Distribution Business Systems Partner ( SAP SD )

The role manages the identification, delivery and implementation of IT solutions, including providing business process and IT knowledge to the above ...

Fixed Income Electronic Trading - Java Development - Front Office

You will be expected to provide analysis of enhancements/fixes/new initiatives, and development of enhancements/fixes/new initiatives. One of my key ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains