On TechRepublic: 10 cool USB flash drive tricks
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Jun 28, 2004 10:11:00 PM

A major security hole discovered in Microsoft's Internet Explorer last week has become a golden marketing opportunity for alternative browsers such as Mozilla and Opera that are unaffected by the flaw.

To avoid falling prey to a concerted attack aiming to steal log-on information and passwords, some security experts advised Web surfers to either turn off some Internet Explorer (IE) features or switch to another browser as the best immediate fix. Unknown attackers who had taken control of several Web servers used the flaw last week to install a remote-access program, dubbed JS.Scob.Trojan, onto the PCs of visitors to those sites.

"I hope that Microsoft will come up with a patch soon," said Johannes Ullrich, chief technology officer for the Internet Storm Center, a site that monitors network threats. "Until they do, you basically have two choices: Disable JavaScript in Internet Explorer or install another browser."

News.context

What's new:
Some security experts have advised Web surfers to turn off some Internet Explorer features or switch browsers to avoid falling prey to a concerted attack aiming to steal log-on information and passwords.

Bottom line:
The IE flaw could tilt security-conscious companies and home users in favor of adopting an alternative browser--and perhaps chip away at Microsoft's 95 percent-plus share of the Web browser market.

For more info:
Track the players

Last week's broad attack has been blunted by Internet engineers that disconnected the Russian site that hosted the Scob Trojan horse program from the Web. However, the latest vulnerability could tilt security-conscious companies and home users in favor of adopting an alternative browser--and perhaps chip away at Microsoft's dominant share of the Web browser market.

At least 130 Web sites were still attempting to infect visitors as of Sunday, according to Internet security firm Websense, which discovered that more than 200 of its customers attempted to download the Trojan horse from the malicious Russian site in the past week. None of the servers were top-rated Web sites, but they all ran Microsoft's Internet Information Service 5.0 Web software and Secure Sockets Layer, or SSL, encryption, the firm said.

Non-Microsoft browsers, such as the Opera browser and the Mozilla and Firefox browsers made by the Mozilla Foundation, don't have many of the vulnerable technologies and tend to focus more on just providing Internet browsing features, keeping the project size smaller, said Hakon Wium Lie, chief technology officer of Opera Software, which makes the browser of the same name.

"Our code base is small, compared to other browsers, and by actively addressing problems that arise, we end up with a highly secure browser," Lie said.

Such a focus differs from Microsoft, which has chosen to tightly integrate IE into the operating system, in part to sidestep antitrust issues. A representative of the software giant was not available for comment.

The suggestion to use other browsers also underscores some security researchers' arguments that software diversity can improve security.

Borrowing a term from agriculture and the fight against pests, software developers and security experts have warned about the hazards of "monoculture." The term refers to the widespread farming of a single variety, making the entire crop vulnerable to a single pest. Historians pin such disasters as the Irish potato famine on monoculture.

Mozilla acknowledged that much of the value of using its software, or that of Opera, stemmed from the hazards of monoculture rather than any inherent security superiority.

Microsoft's browser currently dominates the Internet landscape, with more than 95 percent of Web surfers using the browser, according to WebSideStory, a Web analytics firm. Mozilla, on the other hand, makes up 3.5 percent, and Opera accounts for 0.5 percent of all users of the sites monitored by WebSideStory.

"Since there is such a disproportionate use of IE on the Internet right now, it does make it a very high-profile target," said Chris Hofmann, the Mozilla Foundation's director of engineering. "That's what people who are writing exploits are targeting, because that's where they get the biggest bang for the buck."

Hofmann called the war against software homogeneity one of the raisons d'etre of his group.

"If we were in a world where there were less of a monoculture for browsers, it would make it harder to design exploits that would affect that much of the marketplace," Hofmann said. "That's one of the driving forces of the Mozilla Foundation--to provide choices so that someone can't come up with an exploit that affects nearly the whole population."

IE a sitting duck?
But Mozilla claims some inherent security advantages as well. Internet Explorer is a fat target for attackers, in large part because it supports powerful, propriety Microsoft technologies that are notoriously weak on security, like ActiveX.

Security experts also noted that Web surfers using non-Microsoft operating systems, such as Linux or Apple Computer's Mac OS, were not affected by last week's attack.

Among security groups advising a browser switch is the U.S. Computer Emergency Readiness Team (US-CERT), the official U.S. body responsible for defending against online threats. The group on Friday advised security administrators to consider moving to a non-Microsoft browser among six possible responses.

"There are a number of significant vulnerabilities in technologies relating to" IE, the advisory stated. "It is possible to reduce exposure to these vulnerabilities by using a different Web browser, especially when browsing untrusted sites."

The advisory noted that Internet Explorer has had a great many security problems in several of its key technologies, such as Active X scripting, its zone model for security and JavaScript. However, the group pointed out that turning off certain features in IE increases the security.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


"Using another Web browser is just one possibility," said Art Manion, Internet security analyst with the CERT Coordination Center, which administers US-CERT. "We don't recommend any product over another product. On the other hand, it is naive to say that that consideration should not play into your security model."

CERT also noted that people who opt for non-IE browsers but who continue to run the Windows operating system are still at risk because of the degree to which the OS itself relies on IE functionality.

Mozilla's Hofmann recommended that Windows users who want to ditch Internet Explorer increase their security level in Windows' Internet options to help thwart those kinds of attacks. While Windows comes by default with those options on "medium," Hofmann said that setting them to "high" would have offered sufficient protection against last week's exploit.

He also encouraged Web developers to stop writing Web sites that rely on ActiveX. Game and photo-uploading sites are among the worst offenders, he said.

"We encourage people not to use these proprietary technologies that we've seen security vulnerabilities associated with," Hofmann said. "ActiveX is one of the biggest areas where these exploits have occurred, and from these recent exploits, you can see that exposing users and making that technology available has some real danger. Sites need to rethink what they're doing to protect users." A major security hole discovered in Microsoft's Internet Explorer last week has become a golden marketing opportunity for alternative browsers such as Mozilla and Opera that are unaffected by the flaw.

To avoid falling prey to a concerted attack aiming to steal log-on information and passwords, some security experts advised Web surfers to either turn off some Internet Explorer (IE) features or switch to another browser as the best immediate fix. Unknown attackers who had taken control of several Web servers used the flaw last week to install a remote-access program, dubbed JS.Scob.Trojan, onto the PCs of visitors to those sites.

"I hope that Microsoft will come up with a patch soon," said Johannes Ullrich, chief technology officer for the Internet Storm Center, a site that monitors network threats. "Until they do, you basically have two choices: Disable JavaScript in Internet Explorer or install another browser."

News.context

What's new:
Some security experts have advised Web surfers to turn off some Internet Explorer features or switch browsers to avoid falling prey to a concerted attack aiming to steal log-on information and passwords.

Bottom line:
The IE flaw could tilt security-conscious companies and home users in favor of adopting an alternative browser--and perhaps chip away at Microsoft's 95 percent-plus share of the Web browser market.

For more info:
Track the players

Last week's broad attack has been blunted by Internet engineers that disconnected the Russian site that hosted the Scob Trojan horse program from the Web. However, the latest vulnerability could tilt security-conscious companies and home users in favor of adopting an alternative browser--and perhaps chip away at Microsoft's dominant share of the Web browser market.

At least 130 Web sites were still attempting to infect visitors as of Sunday, according to Internet security firm Websense, which discovered that more than 200 of its customers attempted to download the Trojan horse from the malicious Russian site in the past week. None of the servers were top-rated Web sites, but they all ran Microsoft's Internet Information Service 5.0 Web software and Secure Sockets Layer, or SSL, encryption, the firm said.

Non-Microsoft browsers, such as the Opera browser and the Mozilla and Firefox browsers made by the Mozilla Foundation, don't have many of the vulnerable technologies and tend to focus more on just providing Internet browsing features, keeping the project size smaller, said Hakon Wium Lie, chief technology officer of Opera Software, which makes the browser of the same name.

"Our code base is small, compared to other browsers, and by actively addressing problems that arise, we end up with a highly secure browser," Lie said.

Such a focus differs from Microsoft, which has chosen to tightly integrate IE into the operating system, in part to sidestep antitrust issues. A representative of the software giant was not available for comment.

The suggestion to use other browsers also underscores some security researchers' arguments that software diversity can improve security.

Borrowing a term from agriculture and the fight against pests, software developers and security experts have warned about the hazards of "monoculture." The term refers to the widespread farming of a single variety, making the entire crop vulnerable to a single pest. Historians pin such disasters as the Irish potato famine on monoculture.

Mozilla acknowledged that much of the value of using its software, or that of Opera, stemmed from the hazards of monoculture rather than any inherent security superiority.

Microsoft's browser currently dominates the Internet landscape, with more than 95 percent of Web surfers using the browser, according to WebSideStory, a Web analytics firm. Mozilla, on the other hand, makes up 3.5 percent, and Opera accounts for 0.5 percent of all users of the sites monitored by WebSideStory.

"Since there is such a disproportionate use of IE on the Internet right now, it does make it a very high-profile target," said Chris Hofmann, the Mozilla Foundation's director of engineering. "That's what people who are writing exploits are targeting, because that's where they get the biggest bang for the buck."

Hofmann called the war against software homogeneity one of the raisons d'etre of his group.

"If we were in a world where there were less of a monoculture for browsers, it would make it harder to design exploits that would affect that much of the marketplace," Hofmann said. "That's one of the driving forces of the Mozilla Foundation--to provide choices so that someone can't come up with an exploit that affects nearly the whole population."

IE a sitting duck?
But Mozilla claims some inherent security advantages as well. Internet Explorer is a fat target for attackers, in large part because it supports powerful, propriety Microsoft technologies that are notoriously weak on security, like ActiveX.

Security experts also noted that Web surfers using non-Microsoft operating systems, such as Linux or Apple Computer's Mac OS, were not affected by last week's attack.

Among security groups advising a browser switch is the U.S. Computer Emergency Readiness Team (US-CERT), the official U.S. body responsible for defending against online threats. The group on Friday advised security administrators to consider moving to a non-Microsoft browser among six possible responses.

"There are a number of significant vulnerabilities in technologies relating to" IE, the advisory stated. "It is possible to reduce exposure to these vulnerabilities by using a different Web browser, especially when browsing untrusted sites."

The advisory noted that Internet Explorer has had a great many security problems in several of its key technologies, such as Active X scripting, its zone model for security and JavaScript. However, the group pointed out that turning off certain features in IE increases the security.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


"Using another Web browser is just one possibility," said Art Manion, Internet security analyst with the CERT Coordination Center, which administers US-CERT. "We don't recommend any product over another product. On the other hand, it is naive to say that that consideration should not play into your security model."

CERT also noted that people who opt for non-IE browsers but who continue to run the Windows operating system are still at risk because of the degree to which the OS itself relies on IE functionality.

Mozilla's Hofmann recommended that Windows users who want to ditch Internet Explorer increase their security level in Windows' Internet options to help thwart those kinds of attacks. While Windows comes by default with those options on "medium," Hofmann said that setting them to "high" would have offered sufficient protection against last week's exploit.

He also encouraged Web developers to stop writing Web sites that rely on ActiveX. Game and photo-uploading sites are among the worst offenders, he said.

"We encourage people not to use these proprietary technologies that we've seen security vulnerabilities associated with," Hofmann said. "ActiveX is one of the biggest areas where these exploits have occurred, and from these recent exploits, you can see that exposing users and making that technology available has some real danger. Sites need to rethink what they're doing to protect users."

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 107 Talkback(s)
RE: 9.5
Given the number of people who swallowed Mike's
post hook, line, and sinker, Mike either gets a
10 or someone has to figure out a way to limit
access to this site. Can you believe this?... (Read the rest)
Posted by: richdave Posted on: 04/26/06 You are currently: a Guest | | Terms of Use
Total overreaction as usual...  Mike Cox | 06/28/04
8.6  Jeff Spicoli | 06/28/04
Way to go!  Metson | 06/28/04
Borders?  Immanuel Tranz-Mischen | 06/28/04
RE: Way to go!  richdave | 04/26/06
7  toadlife | 06/28/04
yup  Metson | 06/28/04
Grow up Mike  betelgeuse68 | 06/28/04
2.3  Jeff Spicoli | 06/28/04
A little testy today are we betel?  Squawkbox | 06/29/04
RE: Grow up Mike  richdave | 04/26/06
Mike, normally I enjoy your humor...  BitTwiddler | 06/29/04
And you are probably...  bjbrock | 06/29/04
Darn Bit no sense of humor today  Squawkbox | 06/29/04
Abuse?  dharding | 06/29/04
That's YOUR  Spoon Jabber | 06/29/04
RE: Abuse?  richdave | 04/26/06
Mikey, do you think...  bjbrock | 06/29/04
Surely Mr. Cox is Funning Us  dl@... | 06/30/04
Third party....What?  cblythsr | 07/01/04
Troll much?  escoles@... | 07/01/04
resign than use Mozilla  Me_too | 07/01/04
Total Fatuousness in above post... Troll alert  jkozura_z | 07/01/04
RE: Total Fatuousness in above post... Troll alert  richdave | 04/26/06
Poor, poor, Mikey  cafeoui | 07/01/04
I can't believe what I'm seeing here.  CPT1985 | 07/01/04
RE: I can't believe what I'm seeing here.  richdave | 04/26/06
Total devastation  accessok | 07/03/04
Narrow Minded and a Shame  mtcook01 | 06/28/04
No kidding!  Martin Marvinski | 06/28/04
9.5  zijiang | 06/28/04
RE: 9.5  richdave | 04/26/06
9.5  Jeff Spicoli | 06/28/04
welcome to zdnet talkback...  ryusen | 06/28/04
Yep there is a secret to reading ZDNET talkback  Squawkbox | 06/29/04
Was this paid for my Mozilla group?  Enterprise Analyst | 06/28/04
You own a Mozilla group?  Martin Marvinski | 06/28/04
(NT)they'd have to have money to do that  zijiang | 06/28/04
Perhaps..  Jeff Spicoli | 06/28/04
Nope, I.E. really IS a security disaster!  Zogg | 06/29/04
weak  zijiang | 06/28/04
Instead of searching for alternate browsers  msteudel@... | 06/28/04
but who's fault is that?  ryusen | 06/28/04
Call you bank  voska | 06/29/04
Change the security in IE  Enterprise Analyst | 06/28/04
hmmmm...  ickusslime@... | 06/28/04
Yes but..  Jeff Spicoli | 06/28/04
Change the firewall settings  jdunn_z | 06/28/04
ROFL!  Chad_z | 06/29/04
Death to ActiveX  toadlife | 06/28/04
You are a smart man.  BitTwiddler | 06/29/04
Win, Win  Franklin_z | 06/28/04
You know what bothers me?  Immanuel Tranz-Mischen | 06/28/04
And just why is MS on top if it is so inferior?  balsover | 06/29/04
No whining here, just lots and LOTS of gloating... happy  Zogg | 06/29/04
Speaking of ugly sisters.....  mrb971@... | 07/08/04
One point...  Martin Marvinski | 06/29/04
Just why MS is on top while it is so inferior  PCcritic | 06/30/04
McDonalds sells the most hamburgers  jkosborn4 | 07/06/04
You fail to understand...  mlynch1234 | 07/01/04
Bravo for recognizing the middle ground  escoles@... | 07/01/04
Taking MS to task.  No_Ax_to_Grind | 06/28/04
Good move but...  Fred Fredrickson | 06/29/04
Looks like a duck  Spoon Jabber | 06/29/04
It's him all right  voska | 06/29/04
Yes it's me.  No_Ax_to_Grind | 06/29/04
Ok, just checking.  Spoon Jabber | 06/29/04
So how is Mozilla treating you?  tic swayback | 06/29/04
Not bad..  d_jedi | 06/29/04
Not too bad.  No_Ax_to_Grind | 06/29/04
Glad to see it  tic swayback | 06/29/04
some sites fail to render properly in Mozilla?  patinman@... | 07/01/04
Let's be fair...  escoles@... | 07/01/04
That's not the (standards compliant) browser's fault  20075880200550981536805084989909-zdavis | 07/02/04
About XP SP2 Patch  Robert Crocker | 06/29/04
Uhm... ZDNET articles unviewable with security turned up  waster | 06/29/04
Yes, because...  Spoon Jabber | 06/29/04
A non-story  Expatriate US Geek | 06/29/04
Laziness is just another reason monopolies can be bad.  Xunil_Sierutuf | 06/29/04
It's not the number in use...  BitTwiddler | 06/29/04
This problem is another Windows deficiency  whisperycat | 06/29/04
More Important! Write about the fix.  TrustMe_z | 06/29/04
They DID tell you how to fix the problem  bdg_z | 06/29/04
Yeah but what about the holes in the servers?  Squawkbox | 06/29/04
IE seems to be abandonware  rbethell | 06/29/04
Hence the reason  Linux User 147560 | 06/29/04
$799 too expensive?  ITGuy04 | 06/29/04
In case you haven't  Linux User 147560 | 06/29/04
most pc users are too stupid  DarthRidiculous | 06/29/04
i disagree with that.  ryusen | 06/30/04
Music to My Ears  Jkirk3279 | 06/30/04
Why people don't switch to Macs or Linux  home_user | 06/30/04
Why is it legal for a business to give away expensive software?  jayk_z | 06/30/04
Yep, you exploiters got MS on the ropes  FilledOut | 06/29/04
Zdnet comments require Javascript  Nigel Johnstone | 06/29/04
He could if he didn't use IE  escoles@... | 07/01/04
Criminals are the real problem.  DanielB | 06/29/04
What Fools................  bicky@... | 06/30/04
You don't know what you're talking about  escoles@... | 07/01/04
Sorry but no, you're still incorrect......wrong.....fooling yourself.......  bicky@... | 07/07/04
You never get Zdnet posters to look at the code exploiters  FilledOut | 07/01/04
About Bloody Time  escoles@... | 07/01/04
Listen to your boss  jw-evans | 07/01/04
Finally Switched to Mozilla  Feet2Fat2Shoe | 07/01/04
How to make IE completely safe...  Graphic Equaliser | 07/09/04
Bad link  Graphic Equaliser | 07/09/04
ROFLMAO...........Mozilla/Opera Safer Than IE????  bicky@... | 07/09/04

What do you think?

SmartPlanet

Click Here