October 22, 2002 1:21 PM PDT

IE holes open up Web booby traps

An Israeli Web-application company has warned users of Internet Explorer that nine related security flaws in the program could be used by malicious hackers to gain access to a victim's computer files.

GreyMagic Software said Tuesday that the vulnerabilities--eight of which it deemed critical--could be exploited using a specially coded Web page that would run malicious programs on a victim's computer if the victim visited the page.

"Using these flaws in combination with other known flaws that can silently deliver files to the user's disk could result in full compromise of the client's computer," said Lee Dagon, head of research and development for GreyMagic.

In addition to letting Net vandals steal private local documents, the flaws could let malicious hackers copy clipboard information, execute arbitrary programs and fool IE users by forging trusted Web sites, the company said in its advisory.

GreyMagic said Internet Explorer 5.5 and 6 are affected by the flaws but that the latest service packs to each of these versions of IE plug the holes.

The bugs appear in how Internet Explorer caches Web objects. GreyMagic found the flaws after researching three different aspects of the Internet Explorer object model earlier this month, Dagon said.

"In each session we found more vulnerabilities," he said.

Seven of the flaws can grant an attacker full access to the victim's PC, while another makes the currently loaded document readable and the last lets an attacker read and write to the clipboard.

"The attacker would need to know the name and exact path to (a) file," added Dagon, pointing out that the vulnerabilities don't let a vandal browse a victim's machine for files. "However, Windows has several sensitive files in relatively static locations, these could be grabbed and used against the victim." For example, the Windows password file is in the same location on every Windows computer and could be copied using the flaws.

Upgrading Internet Explorer 5.5 to Service Pack 2 plugs the security holes, the company said. Patching Internet Explorer 6 with Service Pack 1 will fix the problems in that version of the program as well. The latest updates for both versions of IE can be found through Microsoft's Windows Update page.

Flaw-reporting flawed?
GreyMagic Software released the news of the flaws at the same time it gave the information to Microsoft, saying that in the past "notifying Microsoft ahead of time and waiting for them to patch the reported issues proved...nonproductive."

Because Microsoft only received news of the holes on Tuesday, the software giant couldn't confirm the existence of the vulnerabilities. Testing the demo code provided by GreyMagic Software, however, showed that the flaws apparently were real.

The Israeli Web company's refusal to notify Microsoft first, however, earned it the software giant's ire.

"We are concerned by the way this report has been handled," a Microsoft representative said in a statement e-mailed to CNET News.com. "Publishing this report may put computer users at risk--or at the very least could cause needless confusion and apprehension."

For more than a year, Microsoft has been fighting to rein in the public disclosure of flaws, issuing criticism of what it deems to be irresponsible reporting and sponsoring the formation of a group to set standards for disclosing vulnerabilities.

In the past, software makers haven't been very responsive to security issues, but that's changing. Most researchers still believe that releasing information about flaws is the best way to warn the public. However, the same researchers increasingly believe that giving the software's creator a fair amount of time to create a patch is the most responsible way to handle such incidents.

Interpretations of what's fair, however, can vary--from a few days to a few months.

According to Dagon, previous advisories that the company brought to the software titan's attention took anywhere from 3 months to more than 6 months to fix. Since then, he said, GreyMagic has lost patience.

"Microsoft takes quite a while to plug even the simplest security issue, leaving users exposed to risks for months at a time instead of letting them know about temporary workarounds," Dagon said.

But Microsoft isn't the only one to voice concern about reports such as GreyMagic's. The open-source community was not happy when security company Internet Security Systems dropped a bomb by posting an advisory about a major flaw in the Apache Web server just hours after it had notified the development group.

Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
What you need in business class email.
Mailtrust

Click Here!
Never worry about email again. From mobility and shared calendaring to virus and spam protection starting at only $3 per mailbox. more>

Rackspace Mailtrust
Total Email Relief

We'll take care of your email so you can take care of your business.

14 Day Free Trial

With expert support 24x7x365 we guarentee 100% uptime. Try us for free for 14 days. Never worry about your email again.

Just $3 per mailbox

Choose the plan that is right for your company and only pay for what you need.

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Outside the Lines

    EIC Squared: Chrome, iPods, and a Dell-Salesforce union

    On this week's EIC Squared podcast CNET's Dan Farber and ZDNet's Larry Dignan discuss Google's latest rocket launch--the Chrome browser--as well as Apple's iPod event next week and a Dell-Salesforce.com union.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    At 10 years old, whither Google?

    Daniel Sieberg of CBS News looks at how the company grew exponentially from start-up to superstar and part of our culture, but what's ahead?

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Webware

    At the TechCrunch50, an unfair advantage?

    Inside baseball: How Webware and other blogs can compete with TechCrunch in covering the TechCrunch50 event.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.