On CNET: New features in OpenOffice 3 beta
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers, News.com
Posted on ZDNet News: Dec 2, 2005 9:31:00 PM

A security researcher in Israel has found a way to steal information from unwitting users of Google's desktop search tool by exploiting an unpatched flaw in Microsoft's ubiquitous Internet Explorer.

There is a bug in the way the Web browser processes CSS rules, Matan Gillon wrote in a description of his hack posted on Wednesday. CSS, or Cascading Style Sheets, is a method for setting common styles across multiple Web pages. The Web design technique is widely used on many sites across the Internet.

The proof-of-concept method is an example of how security flaws in software can offer all kinds of access to programs on vulnerable PCs, including to Google Desktop.

"This design flaw in IE allows an attacker to retrieve private user data or execute operations on the user's behalf on remote domains," Gillon wrote in his description of the attack method. He crafted a Web page that--when viewed in IE on a computer with Google Desktop installed--uses the search tool and returns results for the query "password."

To exploit the flaw, an attacker has to lure a victim to a malicious Web page. "Thousands of Web sites can be exploited, and there isn't a simple solution against this attack, at least until IE is fixed," Gillon wrote.

Microsoft is investigating the issue, which it described in a statement as a problem affecting the cross-domain protections in Internet Explorer. "This issue could potentially allow an attacker to access content in a separate Web site, if that Web site is in a specific configuration," Microsoft said in the statement.

Microsoft is not currently aware of malicious code that takes advantage of the flaw, but is monitoring the situation, the company said. A security update or an advisory on the problem may be coming, it said.

Google is also investigating Gillon's findings. "We just learned of this issue and are looking into it," Sonya Boralv, a spokeswoman for the search giant, wrote in an e-mailed statement.

While Gillon in his example uses the IE flaw as a means to get to Google Desktop, this flaw and other software bugs could be used to covertly access virtually any application on a compromised computer.

"It is like any other flaw within IE, but he got creative and used it to launch Google Desktop to retrieve data," security researcher Tom Ferris said. "You can bet we will see this one being used to steal users' Quicken data, database files, etc."

Steve Manzuik, a security product manager at eEye Digital Security, agreed. "This definitely looks like a flaw in IE and not a Google bug. He is using Google Desktop as to retrieve data, but it is IE that makes it possible," he said.

While IE is vulnerable, Gillon found that Firefox and Opera are not. For protection, Internet users could use one of those browsers or disable JavaScript in IE, Gillon suggested.

It has been a busy week on the Microsoft security front. Four examples of attack code were released for flaws in the Windows operating system, and a Trojan horse is finding its way onto PCs through another yet-unpatched flaw in IE.

  • Talkback
  • Most Recent of 59 Talkback(s)
voice of officer barbarady
ok people, nothing to see here, lets move along now. (Read the rest)
Posted by: linuxoverwindows Posted on: 12/06/05 You are currently: Logged In | Log out
Ho Humm toadlife   | 12/02/05
This isn't dangerous at all!! NonZealot   | 12/02/05
There IS an exploit wackoae   | 12/02/05
yes but.. Jeff Spicoli   | 12/02/05
Be carefull Jeff toadlife   | 12/02/05
Using one's own argument against them... jasonp@...   | 12/02/05
I agree... toadlife   | 12/02/05
thankie Jeff Spicoli   | 12/02/05
I don't believe in that nonsense Jeff Spicoli   | 12/02/05
ok toadlife   | 12/02/05
Matter of conception georgep_z   | 12/03/05
I am aware of what you just said, but... toadlife   | 12/03/05
Shame on you toadie... jasonp@...   | 12/03/05
Shame on you toadie... jasonp@...   | 12/03/05
Yet another person that completely misses the point toadlife   | 12/03/05
Matter of conception georgep_z   | 12/03/05
because...... NemesisNL   | 12/04/05
one thing funny to mention... linuxoverwindows   | 12/06/05
one thing funny to mention... linuxoverwindows   | 12/06/05
how about both>? linuxoverwindows   | 12/06/05
Dangerous to Microsoft credibility whisperycat   | 12/05/05
Posting attempt 2 : Dangerous to Microsoft credibility whisperycat   | 12/05/05
glad to know it isnt just me... linuxoverwindows   | 12/06/05
This isn't dangerous at all!! NonZealot   | 12/02/05
keep it in your pants Jeff Spicoli   | 12/02/05
I think you responded to a double post. osreinstall   | 12/03/05
I realized it Jeff Spicoli   | 12/03/05
voice of officer barbarady linuxoverwindows   | 12/06/05
I thought he was being sarcastic??? zdn@...   | 12/05/05
How long? broper   | 12/02/05
Here we go again ,,,,, I'm Ye, the MS SHILL .   | 12/02/05
This is true. Cardinal_Bill   | 12/02/05
Message has been deleted. Cardinal_Bill   | 12/02/05
re: How long? hk165   | 12/03/05
If they are silly enough jackie40d@...   | 12/03/05
IE again hahaha jackie40d@...   | 12/03/05
Oh really? Haterock Davidsfather   | 12/03/05
Nope NemesisNL   | 12/04/05
Interesting. Haterock Davidsfather   | 12/04/05
PS. Haterock Davidsfather   | 12/04/05
No move to Linux yet mikeybrass   | 12/03/05
No move to Linux yet mikeybrass   | 12/03/05
Have you notified them yet? Cardinal_Bill   | 12/03/05
Thing is mikeybrass   | 12/04/05
You like using a browser without JavaScript? Haterock Davidsfather   | 12/04/05
What are you on about? mikeybrass   | 12/05/05
Java is NOT JavaScript mtifo@...   | 12/05/05
And your point is what... mikeybrass   | 12/05/05
What are you on about? mikeybrass   | 12/05/05
Use FIREFOX and be done with it! IT-sys   | 12/03/05
And they are moving into your neighborhood Boot_Agnostic   | 12/04/05
Use FIREFOX and be done with it! IT-sys   | 12/03/05
Their Answer ipfresh@...   | 12/04/05
Message has been deleted. nix_os_fan   | 12/04/05
Another IE security flaw jackofalltradesmasterofnone   | 12/04/05
IE flaw lets intruders into Google Desktop jackofalltradesmasterofnone   | 12/04/05
IE flaws are not news Chad_z   | 12/05/05
Will only move when mikeybrass   | 12/05/05
A flaw in IE ??? realitycheck101   | 12/05/05

What do you think?

advertisement
advertisement

Whitepapers & Webcasts

advertisement
Click Here