Quantcast

Researchers Warn of IE6 Hole

Gregg Keizer, Computerworld

  • 0 Yes
  • 0 No

Security researchers are warning users about an unpatched cross-site scripting bug in Internet Explorer 6 (IE6) that could be used by hackers to capture keystrokes and steal other information.

The vulnerability appears to be a variation of a vulnerability first discussed by researchers Manuel Caballero and Fukami at Microsoft Corp.'s on-site BlueHat security conference early last month, Yichong Lin, an analyst at McAfee Inc., said in an entry to the company's blog.

At BlueHat, Caballero, who has worked for Microsoft as an independent penetration tester, said he had found a way to capture every browser action, including keystrokes used to type passwords. In a videotaped interview that Microsoft conducted during BlueHat, Caballero said that the combination of Flash and any browser, not just IE, could be hacked with a malicious script to give attackers full access to the browser.

Details of the recent variant, as well as proof-of-concept code, were posted to a Chinese-language security e-zine by a group calling itself "Ph4nt0m Security Team," according to another alert issued by the Danish vulnerability tracking firm Secunia.

Secunia outlined the threat: "The vulnerability is caused due to an input validation error when handling the 'location' or 'location.href' property of a window object. This can be exploited by a malicious website to open a trusted site and execute arbitrary script code in a user's browser session in context of the trusted site."

IE7, the current version of Microsoft's browser, does not contain the vulnerability, both Secunia and McAfee said. Until Microsoft produces a patch for the older browser, users should update to IE7, they added.

Yichong of McAfee said that the security company had notified Microsoft about the vulnerability. Microsoft representatives, however, did not immediately reply to a request for confirmation and additional comment.

  • Recommend this story?
  • 0 Yes
    0 No

"Researchers Warn of IE6 Hole" Comments

Print 65% more pages than with refilled inks. Trust Original HP Inks. Hit Print Reliably.

Featured APC Accessories For Your System
10% Off Entire Cart at Online Store

  • APC Back-UPS ES Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
  • APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.

People who read this also read:

  • 2007 Microsoft Office Suites Comparison This paper compares and contrasts four suites of the 2007 Microsoft Office system: Microsoft Office Standard 2007, Microsoft Office Professional Plus 2007, Microsoft Office Enterprise 2007 and Microsoft Office Ultimate 2007. This paper is intended to help organizations understand the applications and capabilities offered, and to identify the suite that best fits their needs.
  • Windows Vista Migration: The Business Proposition It's not so much a matter of "if" but "when" for most organizations regarding migration to Windows Vista. Laying the groundwork now for this migration can yield higher ROI than waiting until later. This Computerworld Technology Briefing explains it all.

PC World's Marketplace