On CBS MoneyWatch: 10 Most Expensive U.S. Colleges
BNET Business Network:
BNET
TechRepublic
ZDNet

By David Becker
Posted on ZDNet News: Jan 29, 2004 12:37:00 AM

A security services company warned of a new vulnerability in Microsoft's Internet Explorer Web browser that could allow Web surfers to be tricked into downloading malicious files.

Danish company Secunia posted details of the alleged flaw, which could be used in combination with an earlier "spoofing" flaw reported by the company.

A Microsoft representative said the company was investigating the report but was not aware of any exploits involving the supposed flaw. The representative also echoed previous criticisms of security researchers publicizing software flaws before software makers can adequately investigate and remedy the problems. "Microsoft continues to encourage the responsible disclosure of vulnerabilities," the representative said.

The new flaw could allow the owner of a malicious Web site to deliberately misidentify a downloadable file, so a malicious program file could be made to appear as if it were a secure file. Visitors might think they were downloading a document based on Adobe's portable document format (PDF), for instance, but actually receive a malicious, self-executing program such as the new MyDoom worm.

Secunia's advisory includes an online test showing how the flaw could be exploited. The company said it identified the hole in the current version 6 of Internet Explorer, but previous releases also could be affected. Secunia representatives did not immediately respond to a request for comment.

The alleged flaw could be particularly effective if used in combination with another IE hole identified by Secunia last month. That flaw lets Web site owners disguise the identity of their site by displaying a false address in the Internet Explorer address and status bars.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


Microsoft has yet to release a patch for that vulnerability, although it has posted a bulletin with tips for avoiding such "spoofed" sites. Among the tips are not clicking hyperlinks. "Rather, type the URL of your intended destination in the address bar yourself," Microsoft advises.

Microsoft's delay in addressing that flaw has drawn criticism from security experts and led an open-source programming group to create its own patch for the flaw.

Microsoft last year instituted a new policy for patching security holes, deciding to cluster fixes in a single monthly release rather than distributing piecemeal updates.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 36 Talkback(s)
Here, go check for yourself.
http://die.leox.com/DirSvc/security/originality/index.html

Browsers compared by the folks who find the vulnerabilities.... (Read the rest)
Posted by: Yen_z Posted on: 01/30/04 You are currently: a Guest | | Terms of Use
Funny Stuff  JoeMama_z | 01/28/04
So true  Richard Flude | 01/28/04
Does that work?  IT_User | 01/28/04
I think you're fairly safe...  Yen_z | 01/28/04
much safer if...  stephen732@... | 01/29/04
As M$ made IE & its OS inseparable as an anti-competitive imperative...  dicktaurus@... | 01/28/04
But wait. it gets better.  Immanuel Tranz-Mischen | 01/28/04
hahahahahaha  IT-man_z | 01/28/04
opps  JWatson77 | 01/28/04
ever try denying access to the particular executable?  JoeMama_z | 01/28/04
Since I.E. is "part of windows"  Rick_K | 01/28/04
Groundhog Day...  jeutkune | 01/28/04
Yaaaawwwwwnnnn  Bobby Sskcat | 01/28/04
uh yeah  MEMSmaker | 01/29/04
Troll, troll, troll your boat...  Bobby Sskcat | 01/29/04
Here, go check for yourself.  Yen_z | 01/30/04
How many people could be so stupid to use MS products???  DonnieBoy | 01/28/04
please  MEMSmaker | 01/29/04
?Unfixable?  Jack-Booted EULA | 01/28/04
IE can be uninstalled  Spoon Jabber | 01/28/04
but why would you?  MEMSmaker | 01/29/04
BUT..  Bobby Sskcat | 01/29/04
why wouldn't you ...  coffeenite | 01/29/04
Konqueror works nicely...  Spoon Jabber | 01/29/04
Don't bother with those sites  IT_User | 01/29/04
mozilla  Rembrandt Pussyhorse | 01/29/04
Yeah, think it's your settings  IT_User | 01/29/04
Video Problem  Yen_z | 01/30/04
Because it is valueless...  IT_User | 01/29/04
Question from a non-techie  copygod74 | 01/28/04
Unlikely  jfrankcarr | 01/28/04
not unlikely  stephen732@... | 01/29/04
Running in the background isn't surfing  jfrankcarr | 01/29/04
Answer  Mack DaNife | 01/29/04
Almost right  voska | 01/29/04
Just you  FilledOut | 01/30/04

What do you think?

advertisement
advertisement
Click Here

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here