A rendering bug

Published: 30 September 1999 y., Thursday
Microsoft_s Internet Explorer 5 (IE5) browser got hit with another one-two punch of coding bugs this week, as reports surfaced of a bug that allows documents to be stolen even through a firewall, and of the altering of HTML tags by the browser_s rendering engine. Security Expert Georgi Guninski, who has posted numerous reports of bugs and security issues with several Microsoft products, is warning users of a bug that would allow malicious hackers to steal and read data off of an IE5 machine, even through a firewall. The attack would take the form of HTML JavaScript that would be activated when a user visits an Internet site or through other means. Once activated, the JavaScript would then begin downloading files not out to another computer, which would be detected by a firewall, but rather back to the computer itself. This one is a spoofing attack. It downloads a file, and it downloads it from your computer to your computer. Once it_s downloaded the file from itself to itself, that information is downloaded to any IP address," said Steve Anderson, vice president of marketing at BigFix, a bug fixing service in Berkeley, Calif., which is assisting Guninski in warning users. "It_s kind of like a submit button on an HTML. The reason it can get through the security is cause it_s downloading to itself. Which it really shouldn_t be able to do," Anderson said. Microsoft is aware of the bug and has issued an alert at www.microsoft.com/security/bulletins/MS99-040faq.asp, which recommends that users disable the active scripting aspect of IE if they so desire. "We_re recommending as a work-around that customers who are worried about this vulnerability disable active scripting, while we develop a patch for this," said Scott Culp, security product manager on the security response team at Microsoft. Culp also stressed that the bug will not allow hackers to steal or alter information; they will only be able to read it. "The only thing that a Web site can do with this is read selected files from a users machine if they know the name of the file," Culp said. BigFix_s Anderson, however, said Microsoft_s advice belies the importance of the bug. Microsoft is currently working on a patch for the problem. Also this week, BugNet and its parent company KeyLabs, in Lindon, Utah, have confirmed the existence of a rendering bug with IE5 that could impact web developers.
Šaltinis: InfoWorld Electric
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

Sony Ericsson internet store has been attacked

It was reported that yesterday Canadian Sony Ericsson internet store was attacked more »

Sales of mobile communication devices grew by 19%

Worldwide mobile communication device sales to end users totaled 427.8 million units in the first quarter of 2011, an increase of 19 percent from the first quarter of 2010, according to Gartner, Inc. more »

New ZeroTouch Interface is a Touchscreen Without the Screen

At the Computer Human Interaction conference in B.C. this week, a team from Texas A&M University unveiled a touch screen technology they’ve been incubating for a couple of years that isn’t really a screen at all. more »

Osaka University’s Unveil an Autonomous Robot

A fully autonomous robot, Pneubron 7-11 has been created at the Hosoda Labs in Osaka University. The Pneubron robot was designed to find the link between human interactions and motor development. more »

Japan brings brainwave technology to a head

The ability to control objects simply by thinking about them is the subject of serious research in laboratories around the world with wheelchairs and even cars now being driven by the power of the mind. It's all very serious science, but in Japan, technologists are demonstrating that mind control can also be a lot of fun. more »

Microsoft says Skype "will have more adverts"

Microsoft is planning on ramping up the amount of advertising free users of Skype see while they are making video calls and using the rest of the service. more »

The biometrics technology that helped ID bin Laden

How certain was the U.S. Navy Seal team that it was Osama Bin Laden they shot, killed and buried at sea? According to a Florida company that makes biometric identification equipment, there's no doubt the Seals got their man. more »

Minicomputer the size of USB drive has been developed

David Braben, the founder of Frontier Developments from Great Britain, has developed a small and very cheap computer "Raspberry Pi". more »

Spotify aims to take market share from iTunes

Online music service Spotify is turning up the heat on Apple as it aims to create an alternative to iTunes. more »

Canadian researchers presented a "PaperPhone - flexible minicomputer prototype

Kingston Queen's University specialists have developed the world's first prototype of flexible minicomputer. more »