On mySimon: Luke Skywalker Doll
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Jul 7, 2004 12:32:00 PM

A computer science researcher has highlighted the shortcomings of Microsoft's latest patch for its Internet Explorer browser by identifying another way that online vandals could run malicious programs on a Web surfer's computer.

Microsoft on Friday released a fix that's designed to protect computers from one of three flaws that, together, could be used to digitally slip past a PC's security through the browser. This weekend, however, a security researcher identified another flaw that could serve the same purpose and that isn't fixed by Microsoft's patch.

"They chose to address only one part of the problem," said Jelmer Kuperus, a computer science student in the Netherlands who posted the code for the work-around. "They should have seen this one coming."

This marks the third time in a month that Microsoft has had to play catch-up to researchers' public disclosures about insecurities in Internet Explorer. In early June, Kuperus found a Web site that used two previously unknown vulnerabilities, plus the recently patched one, to install adware on victims' computers. Additionally, security researchers discovered last week that a milder vulnerability, which Microsoft had fixed in early versions of the browser, reappeared in later versions.

Microsoft acknowledged the latest issue and said more fixes would be forthcoming.

"The company is working to provide a series of security updates to Internet Explorer in coming weeks that will provide additional protection for customers," a company representative told CNET News.com. The company will also "continue to actively investigate these reports."

The most recent flaw is not new--security researchers first discussed the issue in January, Kuperus said. It had originally been considered minor, but the flaw is significant because it can be used in conjunction with the two other vulnerabilities, which were found at the beginning of June. Together, all three add up to easy access to Windows computers running Internet Explorer.

"Most exploits we are seeing developed today are composed of multiple vulnerabilities, (each one) bypassing a specific security feature of Internet Explorer," Kuperus said. "Individually, many of these issues often are fairly harmless, but combined they can pose serious risk."

Both the original and the latest vulnerabilities exist in a library of components and scripting features known as ActiveX. The older flaw is in ADODB.Stream, while the latest vulnerability is in the Application.Shell component.

Vulnerabilities in IE have become so common that some security researchers are recommending that people adopt alternate browsers. The Computer Emergency Response Team, the official U.S. body responsible for defending against online threats, also advised security administrators to consider moving to a non-Microsoft browser, as one of six recommended responses.

Microsoft recommends that users go to the company's Protect Your PC site for the latest information.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 133 Talkback(s)
Re: Maybe not...
modify an x86 emulator, specifically for IE, and run it in a sandbox environment (similar to Java).

That would at least stop the spread of viruses and adware.
________________________
(Read the rest)
Posted by: Me_too Posted on: 07/11/04 You are currently: a Guest | | Terms of Use
Is this new?  Spoon Jabber | 07/07/04
Of course it's new... new day, new flaw..!  Xunil_Sierutuf | 07/07/04
Mozilla is great, love tabbed browsing  FilledOut | 07/07/04
I don't like tabbed browsing  FirstNLastN | 07/07/04
Done that... didn't like it.  el1jones | 07/07/04
Opera is another choice  rbochan | 07/07/04
Me neither..  d_jedi | 07/07/04
Opera can do that  randomletter | 07/08/04
Poof!  Yagotta B. Kidding | 07/07/04
I love tabbed browsing  carmanintx | 07/07/04
Don't use it then.  Immanuel Tranz-Mischen | 07/07/04
Terrorist Researchers  dend | 07/07/04
8.0  Martin Marvinski | 07/07/04
tabbrowser extension  dend | 07/07/04
Why?  Linux User 147560 | 07/07/04
Umm...  Martin Marvinski | 07/07/04
MS is the energizer bunny of flaws!  Xunil_Sierutuf | 07/07/04
This is why...  Michael Kelly | 07/07/04
Flaws fixed faster  Linux User 147560 | 07/07/04
Flaws In MS  agottschald | 07/07/04
Why not just release SP2 early?  soma@... | 07/07/04
No it's not better  Linux User 147560 | 07/07/04
Umm... can it get any worse?  Xunil_Sierutuf | 07/07/04
True, why break a tradition now..  Xunil_Sierutuf | 07/07/04
Beta testing...  Martin Marvinski | 07/07/04
Everyone is expecting SP2...  bjbrock | 07/07/04
Joe and Jane internet user  rbochan | 07/07/04
I believe you are quite right.  agottschald | 07/07/04
Another layer of unsecure computers will be created & unaddressed  Squawkbox | 07/07/04
why not just do a better job of educating Joe and Jane?  ryusen | 07/07/04
The Drum Roll Is Getting Stronger - CLASS ACTION CLASS ACTION  RobertoSalazar | 07/07/04
Bring on the common sense instead  SublimeDaze | 07/07/04
There is nothing sensical about...  bjbrock | 07/07/04
The problem with class action lawsuits  ryusen | 07/07/04
The problem with class action lawsuits  richdave | 07/07/04
chicken or egg?  ryusen | 07/07/04
Hmm..  d_jedi | 07/07/04
Lawsuit might be baseless  Allstar_z | 07/10/04
Switching Would Be Stupid....  chrislovesdana | 07/07/04
Hey, can I get some of that...  Spoon Jabber | 07/07/04
I think that "stuff"...  bjbrock | 07/07/04
After 10 years...  bjbrock | 07/07/04
Ugh, I can'e believe how wrong people are  jsilve1 | 07/07/04
Awww what is a few years amongst friends?  Squawkbox | 07/07/04
You are being overly critical  SilentTygur | 07/07/04
the problem  eLurker | 07/07/04
Mozilla's been around longer  OhMyGosh | 07/07/04
actually...  ryusen | 07/07/04
You're right, but...  Immanuel Tranz-Mischen | 07/07/04
good point but...  ryusen | 07/07/04
NOT switching would be stupid  jsilve1 | 07/07/04
Reliability is FAR more important than innovation  martyj | 07/07/04
LOL  Linux User 147560 | 07/07/04
2 apps  SC-man | 07/07/04
Really  cdjmattmiller@... | 07/07/04
debugging  rbochan | 07/07/04
Again: You don't know what you're talking about  escoles@... | 07/07/04
Yes, but look at the facts...  riff7raff | 07/07/04
Yes, but look at the facts...  richdave | 07/07/04
Is that you, Mike?  Daisy Fontana | 07/07/04
I just get some ID10+ error...  php_developer | 07/07/04
Wanna be Mike Cox  bchesmer | 07/07/04
Switch browsers -yes!  mhoyle | 07/08/04
Business as usual  tic swayback | 07/07/04
Re: Business as usual  issthatso | 07/07/04
i think you are holding apple in too high a light...  ryusen | 07/07/04
You're right.  Immanuel Tranz-Mischen | 07/07/04
you missed my point...  ryusen | 07/08/04
SP2 won't fix a basic design flaw  issthatso | 07/07/04
If it did fix XP's problems what about the legacy ware out there?  Squawkbox | 07/07/04
Every move by MS just opens more holes!  George Mitchell | 07/07/04
MS wasn't allowed to fix certain "security holes"  toomuchgreeatea@... | 07/07/04
Microsoft : The hackers target of choice  riff7raff | 07/07/04
Hmmm  Spoon Jabber | 07/07/04
MS products are still easier to use  Eggs Ackley_z | 07/07/04
Than *what*?!  escoles@... | 07/07/04
...I don't think so!  settantta | 07/07/04
RTFP  Eggs Ackley_z | 07/08/04
Switching Browsers  tgrkss | 07/07/04
Aww c'mon - think of something more stupid  Eggs Ackley_z | 07/07/04
If this is Mike Cox, then you get 1.5 score (NT)  Judas I. | 07/07/04
Just to prove it, anecdotally ...  Eggs Ackley_z | 07/07/04
Re: Switching browsers and Mozilla  rkelleher_1 | 07/07/04
Sorry, man, you don't know what you're talking about.  escoles@... | 07/08/04
Ya right...  bchesmer | 07/07/04
At first I thought you were  skeptic tank | 07/07/04
more is not alway the right reason.  agottschald | 07/08/04
Alright, one more time: IE IS FUNDAMENTALLY INSECURE  escoles@... | 07/08/04
The answer is don't use IE  woody_z | 07/07/04
BINGO  Partisan | 07/08/04
Microsoft is MACRO INCOMPETENT!  martyj | 07/07/04
Six year-old child needed  andy88488 | 07/07/04
which websites?  toadlife | 07/07/04
Incompatible Websites  andy88488 | 07/08/04
More please  zen_dogen | 07/08/04
Then use IE for those sites. Next?  escoles@... | 07/08/04
If....  Monkey_MCSE | 07/07/04
The M$ way  DarthRidiculous | 07/07/04
Utopian Thinking  andy88488 | 07/08/04
A fully-compatible emulation of IE  Me_too | 07/07/04
Maybe not...  Allstar_z | 07/10/04
Re: Maybe not...  Me_too | 07/11/04
Fully Compatible  Yagotta B. Kidding | 07/07/04
Internet Explorer  tazwalker@... | 07/07/04
IE Favorites  Eggs Ackley_z | 07/07/04
Exactly  Monkey_MCSE | 07/07/04
Microsoft recommends what?  Me_too | 07/07/04
"They should have seen this one coming."  Yagotta B. Kidding | 07/07/04
Only a Crackhead would switch at this point.  chrislovesdana | 07/07/04
I think I may have found the true definition of Idiot...  Monkey_MCSE | 07/07/04
I sure won't switch  TWRX | 07/07/04
You finally got one right!  IT_User | 07/07/04
Thank you...  Partisan | 07/08/04
Enterprise Analyst  Expatriate US Geek | 07/07/04
IE is still the main browser  Enterprise Analyst. | 07/07/04
By all means, keep using it, please.  Immanuel Tranz-Mischen | 07/07/04
Only if we were so lucky!  Linux User 147560 | 07/07/04
IE is the main browser ... ONLY because MS ILLEGALLY tied it to the OS.  Plain Logic | 07/07/04
Main browser for what?  IT_User | 07/07/04
You left out....  Partisan | 07/08/04
Not as good as your usual posts  Expatriate US Geek | 07/08/04
IE - A security hole pretending to be an app  wonderbored | 07/07/04
CLASS ACTION LAWSUIT for GROSS NEGLIGENCE !!!  Plain Logic | 07/07/04
The Final Solution.  agottschald | 07/07/04
of course its never the hackers fault...  zijiang | 07/07/04
Who said it cleared them?  IT_User | 07/07/04
Wake up  agottschald | 07/07/04
Computer Emergency Response Team,  jgoodman_z | 07/08/04
What's new?  tslocum7 | 07/08/04
FireFox 0.9 ROCKS...IE SUCKS!!!  itanalyst | 07/08/04
May I have the envelope please?  Squawkbox | 07/09/04
Even Slate recommends FireFox/Mozilla. . .  boomslang_z | 07/09/04
Blame the web developers...  Allstar_z | 07/10/04

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads