April 19, 2000 10:25 AM PDT

Microsoft browser bug may access private files

Related Stories

Microsoft miscues come in bunches

April 17, 2000

Browser bugs abound

January 28, 1999

Microsoft fixes IE security hole

September 8, 1998

IE hole exposes local files

October 17, 1997
Microsoft is looking into a newly discovered security hole in its browser that could expose people's private files to malicious Web site operators.

The security flaw surfaces as the software giant reels from a series of miscues involving security breaches and software leaks.

The latest bug has to do with the way Microsoft's Internet Explorer browser handles the Java programming language, according to veteran browser-bug hunter Georgi Guninski.

The flaw lets a malicious Web site operator use a script to open a new browser window. That window opens with the computer owner's security safeguards.

Because IE normally lets the local computer user find files on the hard drive as well on the Web, the maliciously scripted window can display any file on a person's computer.

Scripts are lines of computer code that give browsers instructions to execute actions without a person's interaction. Scripts can open pop-up windows, run tickers across a screen, or double-check information entered in online forms.

Internet Explorer comes equipped with a security mechanism that should prevent Web authors from using scripts to peek from one window into another with the minimum security safeguard. But Guninski's exploit takes advantage of what he described as flaws in IE's Java implementation to circumvent those mechanisms.

This isn't the first time Microsoft has grappled with weaknesses in IE's cross-frame security. Microsoft tackled one such problem in January, another in October and a third in September.

The Achilles' heel of cross-frame security in this case is a combination of Microsoft's Java implementation, the JavaScript scripting language, and the document object model (DOM), a specification for transforming each element of a Web page into an independent object that a script can manipulate.

According to Guninski, IE's Java implementation normally restricts the use of JavaScript URLs so they cannot be used to get around cross-frame security. But IE's Java implementation interacts with the DOM in such a way that JavaScript can get away with that trick.

"The Java JSObject allows setting DOM properties from Java and allows setting a hostile JavaScript URL to (a frame's) location," Guninski wrote in a description of the bug posted to the Bugtraq security mailing list. "This leads to circumventing cross-frame security policy."

Guninski posted a demonstration of the exploit and recommended disabling Java or disabling scripting of Java applets pending Microsoft's fix.

Microsoft said it was investigating the problem, which it learned of yesterday morning, and declined to comment further on the security hole pending its investigation.

Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    IBM's EMEA revenue growth shaping up with same past path

    IBM announces its third quarter revenue growth in Europe, the Middle East and Africa is shaping up to post a similar growth pattern as the first half of the year - a.k.a. a moderate IT spending environment.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • The Open Road

    Disservice to partners may bite Apple

    The Mac maker does many things right, but partner management is not one of them. Delays in App Store updates and general lack of communication is frustrating developers.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Want top search results? Tread carefully

    In the business of promoting Web sites to top search results, some push limits to find what tricks are allowed. But there's evidence the trade is getting more respectable.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Say Where brings voice recognition to iPhone apps

    Forthcoming iPhone app from Dial Directions aims to give users a way to get information from sites like Yelp, MapQuest and others by speaking instead of typing.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Webware

    TechCrunch50: the day 1 schedule

    The organizers of the vent have been playing their start-up cards close to the vest, but now we know who'll be presenting Monday.

  • Green Tech

    TI does energy efficiency on a chip

    Its line of Piccolo microcontrollers can reduce power consumption significantly of home appliances, hybrid cars, LED lighting, and even solar panels.