Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Microsoft To Plug Devastating Browser Download Hole
Newsbytes ^ | 12/12/2001 | Brian McWilliams

Posted on 12/11/2001 9:11:38 PM PST by toupsie

  Microsoft To Plug Devastating Browser Download Hole

By Brian McWilliams, Newsbytes
REDMOND, WASHINGTON, U.S.A.,

11 Dec 2001, 1:09 PM CST Microsoft [NASDAQ:MSFT] will patch a flaw in its Web browser that could allow an attacker to silently download and execute malicious programs on the computers of users who view a specially constructed Web page or e-mail message.

The patch for Internet Explorer (IE) is currently in testing and could be released soon, according to Jouko Pynnonen, a security researcher with Finland's Oy Online Solutions. Pynnonen reported the IE vulnerability to Microsoft on Nov. 19 and recently tested the software fix at the company's request.

The vulnerability affects IE for Windows versions 5, 5.5, and 6, said Pynnonen. Citing the severity of the flaw, he refused to release technical details about the method he found for bypassing the browser's system for securely handling downloaded files.

A Microsoft spokesperson said the company does not currently have any information to share on the issue and declined to discuss the status of the browser patch.

By design, IE should warn users when they attempt to download and open an executable file. But as a result of the security flaw, a malicious Web site could "relatively easily and unnoticeably ... spread virii, install DDoS zombies or backdoors, format hard disks, and so on," wrote Pynnonen in an advisory posted Nov. 26 to Bugtraq, a mailing list for security experts.

Pynnonen revealed that the bug lies in IE's processing of Internet addresses and "header" information that tells the browser what type of file it is handling. The flaw is particularly dangerous because it can be exploited using ordinary Web page code, without help from JavaScript or other scripting programs, he said.

Oy Online Solutions offered to demonstrate the flaw at a private Web site only if recipients of the demo signed an agreement not to disclose information about the exploit.

Chris Wysopal, director of research and development for AtStake, a security consulting firm, characterized the IE download flaw as "a very serious problem" and potentially one of the most severe ever to affect the browser.

However, to exploit the vulnerability, "attackers would probably need control of a Web server so that they could control the information sent in the HTTP header," Wysopal said. As a result, attacks could be traced to the malicious site.

According to Pynnonen, the vulnerability also may affect users of Microsoft's Outlook and Outlook Express e-mail readers, which rely on IE to display messages in Web-page or HTML format. Qualcomm's Eudora e-mail reader, which optionally uses IE for HTML display, could also be vulnerable, he said.

Until the patch is available from Microsoft, Pynnonen said concerned users can temporarily disable IE's ability to download files. To do so, users should select Internet Options from the Tools menu. Then select the Security tab and click on Custom Level. Scroll down to the listing for Downloads and disable file downloads.

Pynnonen's initial advisory on the flaw did not describe the automatic downloading vulnerability and was concerned instead with the browser's failure to properly differentiate between file types.

A subsequent message sent to Microsoft and Bugtraq Nov. 28 described the more serious issues but was not published on Bugtraq by joint agreement between Pynnonen and the list's moderator, the security researcher said.

Microsoft initially denied that the ability to "spoof" file types in IE represented a security vulnerability, but the company later changed its position, according to Pynnonen.

Last month Microsoft patched a security flaw in IE's handling of browser cookie files after Pynnonen reported the vulnerability to the company.

Pynnonen's original report on the IE download spoofing flaw is at http://www.solutions.fi/index.cgi/news_2001_11_26?lang=eng

Microsoft security information site is at http://www.microsoft.com/technet/security/default.asp

Reported by Newsbytes, http://www.newsbytes.com .

13:09 CST
Reposted 13:33 CST

(20011211/WIRES ONLINE, LEGAL, PC/HOLE/PHOTO)


TOPICS: Breaking News; News/Current Events
KEYWORDS:
Navigation: use the links below to view more comments.
first previous 1-20 ... 201-220221-240241-260261-269 last
Comment #261 Removed by Moderator

To: Timothy N Riordan
BTW scripting is set on by default as is the preview pane.

Not any more Beavis. Preview pane yes, scripting no. I prefer to leave the preview pane on, and made double sure that scripting was disabled. I get prompted by Outlook if there is an attachment, and that's after Norton's already quarantined the attachment.

BTW Beavis, I also use Linux Mandrake 8.1 (and plan to play with Debian V4 this coming weekend). With LM, I have to check Cooker for security patches all the time. I also use Smoothwall (Linux again) as my router/firewall/web proxy software, and had to download five updates from their web site as soon as I installed it.

Any more comments, Beavis?

262 posted on 12/13/2001 4:40:55 AM PST by peabers
[ Post Reply | Private Reply | To 260 | View Replies]

Comment #263 Removed by Moderator

To: Timothy N Riordan
Until M$ can produce a product which does not require a system upgrade to use it they are not doing it right..

And, Linux kernel and secuirty updates are...?

Both systems have their place. It just happens that Linux isn't ready yet for prime time desktop duty. However, it rocks as server, firewall, and router software. Better than any affordable commercial package I've tried under windows.

And, you are being petty when you post untrue statements and conveniently avoid facts to make a point.

264 posted on 12/13/2001 5:14:38 AM PST by peabers
[ Post Reply | Private Reply | To 263 | View Replies]

Comment #265 Removed by Moderator

If you care, I really like a lot of stuff you post. Even the clear and correct explanation of MS v the world. But, I must say, your symbolism exegesis of Apple's logos reminds me of college English classes trying to analyze Bob Dylan's lyrics or current professors looking for symbolism in movies. But, it IS interesting.

P.S. I love Dylan's music, so that's a debate for another day. I just disagree that it's good poetry. He didn't even know of rhyming dictionaries until the '70s and some of the rhymes yield pretty tortured "meaning".

266 posted on 12/13/2001 5:41:00 AM PST by jammer
[ Post Reply | Private Reply | To 111 | View Replies]

To: jammer
college English classes trying to analyze Bob Dylan's lyrics

We must have been in the same class.... LOL
I don't know who your post was directed to, but I would like to add a note to Timothy N Riordan and peabers, who are *really* restraining from personal insults :)
Don't type so fast, spell check first....take a deep breath, and transmit.

267 posted on 12/13/2001 6:11:00 AM PST by bwteim
[ Post Reply | Private Reply | To 266 | View Replies]

To: RadioAstronomer
When I first joined FR, a kind soul told me about Zone Alarm and I've been running it since. Some of the other programs you mentioned look very interesting, especially Spyblocker. Thank you again for pulling all these resources together!
268 posted on 12/13/2001 6:50:08 AM PST by Scully
[ Post Reply | Private Reply | To 248 | View Replies]

To: Timothy N Riordan
I downloaded 6.2 yesterday after using IE forever. If I did like the program, how does one transfer email?
269 posted on 12/13/2001 8:32:36 AM PST by Tumbleweed_Connection
[ Post Reply | Private Reply | To 261 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-20 ... 201-220221-240241-260261-269 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson