IE5 Bug Circumvents Passwords
Security hole may threaten those who share PCs.
Matthew Nelson and Bob Trott, InfoWorld Electric
The bug occurs when one user accesses a Web site that does not employ standards-based HTTP cache controls, thereby enabling another user on the same machine to view the same password-protected site visited by the first user and cached on the PC--without entering the original user's log-in and password.
The password itself would not be viewed.
Some users believe the bug has the possibility of being an annoying problem.
"If the [local] cache is compromised in such a way as to allow secure data to be accessed without using proper credentials--or in this case, without any credentials at all--then you have a big problem," said Scott Schnoll, a Portland, Oregon-based Windows developer.
Manual Work-Arounds
Schnoll said work-arounds exist for the bug, such as manually emptying the local cache, or configuring IE5 to automatically purge the cache when it is closed.
"The best solution would be in the form of a patch from Microsoft," Schnoll said. "It would be nice if IE5 users were able to take advantage of the benefits of a local Web cache without having to worry about security breaches such as this."
Microsoft is investigating ways to address this issue in a future release, the company said.
For more IT analysis and commentary on emerging technologies, visit InfoWorld.com. Story copyright © 2007 InfoWorld Media Group. All rights reserved.
Microsoft Office Home and Student 2007
Perfect Print Solutions
People who read this also read:
- Perfect Printing Solutions Find just the right All-in-One Printer for you from HP. Visit the HP Resource Center.
- Acer Laptop Center Forget the Mouse...check out the next generation multi-gesture touch screen technology from Acer.
- Dell Shopping Center Check out great deals from Dell!
Cameras
Camcorders
Cell Phones
Components
Desktops
HDTV
Home Theater
GPS
Laptops
Monitors
MP3 Players
Networking &
Printers
Storage





