A rendering bug

Published: 30 September 1999 y., Thursday
Microsoft_s Internet Explorer 5 (IE5) browser got hit with another one-two punch of coding bugs this week, as reports surfaced of a bug that allows documents to be stolen even through a firewall, and of the altering of HTML tags by the browser_s rendering engine. Security Expert Georgi Guninski, who has posted numerous reports of bugs and security issues with several Microsoft products, is warning users of a bug that would allow malicious hackers to steal and read data off of an IE5 machine, even through a firewall. The attack would take the form of HTML JavaScript that would be activated when a user visits an Internet site or through other means. Once activated, the JavaScript would then begin downloading files not out to another computer, which would be detected by a firewall, but rather back to the computer itself. This one is a spoofing attack. It downloads a file, and it downloads it from your computer to your computer. Once it_s downloaded the file from itself to itself, that information is downloaded to any IP address," said Steve Anderson, vice president of marketing at BigFix, a bug fixing service in Berkeley, Calif., which is assisting Guninski in warning users. "It_s kind of like a submit button on an HTML. The reason it can get through the security is cause it_s downloading to itself. Which it really shouldn_t be able to do," Anderson said. Microsoft is aware of the bug and has issued an alert at www.microsoft.com/security/bulletins/MS99-040faq.asp, which recommends that users disable the active scripting aspect of IE if they so desire. "We_re recommending as a work-around that customers who are worried about this vulnerability disable active scripting, while we develop a patch for this," said Scott Culp, security product manager on the security response team at Microsoft. Culp also stressed that the bug will not allow hackers to steal or alter information; they will only be able to read it. "The only thing that a Web site can do with this is read selected files from a users machine if they know the name of the file," Culp said. BigFix_s Anderson, however, said Microsoft_s advice belies the importance of the bug. Microsoft is currently working on a patch for the problem. Also this week, BugNet and its parent company KeyLabs, in Lindon, Utah, have confirmed the existence of a rendering bug with IE5 that could impact web developers.
Šaltinis: InfoWorld Electric
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

The Slovak electronic vignette brought a significant increase in the revenues from collection for the government

The electronic vignette system in the Slovak Republic has become unique in the world thanks to the speed of implementation and increase in the revenues from the collection carried out by SkyToll a.s. on behalf of the Slovak government. more »

Unisys Names Perla Do Amral as New Managed Services Executive in Latin America

Unisys has promoted Perla Do Amral to a key leadership role, becoming director of service desk operations for the U.S.-based IT company’s managed services centers in Latin America. more »

Microsoft names a new Corporate Vice President for Latin America

Cesar Cernuda is a Microsoft veteran of 19 years, and has served in several senior leadership positions for Microsoft Business Solutions, including overseeing Microsoft’s ERP and CRM business worldwide. more »

Unisys Wins Contract to Provide IT Support for NASA Langley Flight Simulations

Unisys received a contract from NASA Langley Research Center (LaRC) to continue to deliver advanced hardware, software, and systems integration for flight simulation projects at the agency. more »

Unisys Announces Third-Quarter 2015 Financial Results

Unisys Corporation reported third quarter 2015 results. more »

IBC 2015 will introduce the novelties in the electronic media and entertainment industry

On the 10th–15th, this September, RAI Exhibition and Congress Centre in Amsterdam will hold the 48th international exhibition-conference dedicated to electronic media and entertainment industry IBC 2015. more »

Unisys Helps Customs and Border Protection Test Facial Recognition System at Dulles Airport

Unisys Corporation announced the completion of the initial phase of testing of a facial recognition system at Dulles International Airport, Virginia, to help Customs and Border Protection (CBP) to identify imposters attempting to enter the United States using passports that are fraudulent or do not belong to them. more »

Past and Future of Television: from Mechanical to IPTV

Television was invented back in 1884, when German Paul Gottlieb Nipkow came up with the idea to scan images using a rotating metal disc with a spiral pattern of holes in it. When the disc was spinning, each hole would scan one brightly lit line of the image. more »

SuperCom Reports Organic Year-over-Year Growth of 45% in Revenue and 76% in EBITDA for the First Quarter of 2015

SuperCom, a leading provider of secure solutions for e-Government, Public Safety, HealthCare, and Finance sectors, announced its results for the quarter ended March 31, 2015. more »

Unisys Corporation Names Tom Patterson to Lead Global Security Solutions Business

Unisys Corporation today announced that Tom Patterson has joined the company as vice president for global security solutions, responsible for leading Unisys' security solutions business worldwide. more »