Skip to main content

Researcher: IE Flaw Allows Data Theft

A security researcher has published information showing that a previously unknown design flaw in Microsoft's Internet Explorer could be used by malicious Web sites to steal sensitive information from IE users' computers.

Israeli hacker Matan Gillon says he's discovered that an unpatched security hole in IE could allow a Web site to see files on the visitor's computer that store data about the user's relationship with other Web sites.

In a detailed analysis published on his Web site, Gillon demonstrates how the hack could be leveraged to steal data on the victim's machine indexed by Google Desktop Search, a free program that allows users to quickly find a variety of files on their computers. The problem is not with Google's software, which contains several built-in security measures to ensure that data cached by its software cannot be read by anyone other than the user.

Gillon's research shows that if an IE user is already logged on to a Web-based service -- such as Gmail or Hotmail, for example -- a malicious Web page could execute certain operations in the user's account, such as opening e-mails and relaying them back to the site's owner for remote viewing.

"This discovery has implications that go far beyond the Google trick," said Tom Liston, a senior analyst for Intelguardians, an information security consulting group in Washington. "Over the next few days I think we’re going to see a lot of people coming out and saying the Google Desktop thing was kinda cool, but that there are far more dangerous implications."

According to Gillon, the hack works because IE does not properly parse cascading style sheet (CSS) files, a Web design language used by thousands of Internet sites.

The exploit demonstrated on Gillon's site works on a fully patched IE browser with default security and privacy settings. Gillon said other browsers, such as Firefox, are sufficiently locked down that the hack doesn't work on them.

This is yet another IE flaw that cannot be exploited if the user disables scripting. (For instructions on how to do that, see this post.) However, given the danger presented by this and other recent discoveries of IE security holes, I would strongly recommend that IE users consider downloading and using another browser, like Firefox, Opera or Netscape. Last month, security researchers released instructions demonstrating how Web sites could use another serious, unpatched, script-related flaw in IE to seize control of computers.

Microsoft said in a statement that it was investigating the problem, saying the exploit detailed by Gillon "could potentially allow an attacker to access content in a separate website if that website is in a specific configuration." The company said it was not aware of any "active attacks or of customer impact," and said it may issue a security advisory on the matter or provide an update through its monthly patch release process to fix the problem.

News of this research was first reported by eWeek, which has a more technical description of how the attack works.


By Brian Krebs | December 2, 2005; 03:35 PM ET

Comments

Popular posts from this blog

Credit card debt catches up with Britons

By Cesar G. Soriano, USA TODAY USAToday.com - London : "This Christmas season, the hottest-selling gifts in Europe are pricey American products such as iPods, the Xbox 360 and celebrity-inspired fashions. That kind of shopping has led to a very American problem: credit card debt." Nationwide, 34% of Britons say they will use credit cards or store cards to pay for their holiday purchases this year. And one in five say they are still paying off their gifts from last Christmas, according to a December poll by Zopa, an online lending agency. "The UK has adopted the American habit of credit with vigor, and consequently consumers are rapidly getting in over their heads," says Steve Rhode, president of Myvesta.org, a non-profit, debt-relief group. In August, U.S.-based Myvesta opened an office in Britain to deal with the growing number of Britons in debt. The number of people filing for bankruptcy or insolvency in England and Wales rose 46% from 2004 to 2005 to a record, a

Learn What is Search Engine Optimization & How to Optimize Your Website For Search Engines

SEO is an action from a webmaster/owner of the website to optimize the website for search engines, to receive maximum traffic and increase ranking in the search engine result pages(SERPs). There are different types of SEO. Some are very specific, trying to dominate very targeted audience, and some are for targeting wide and general audience. Search Engine Optimization is quite long process, and it requires from a webmaster constant testing and tracking, to see what works and what doesn't. If you are a webmaster, then it's vital to know SEO, because it's a free, effective and clever way to get traffic to your website. There are many guides available on SEO, so you can read them and learn, if you want to be an expert. Why Does A Website Needs SEO? Most of the websites on the Internet get their main traffic from search engines, like Google, Yahoo & MSN. If you website cannot be located by search engines, or your content is not indexed in their database, then you are missin

Google Trends: Building Links with the Correct Keywords Makes All the Difference

The most important part of SEO is building great links to your content. The most common mistake is targeting the wrong keywords. The question at hand is, how do I choose my keywords? I have a great suggestion that should help you out. Google trends is a great help with choosing what you should target. Google trends will show you how much traffic a search term in Google is getting. The power is not in knowing how much traffic it gets, but how much traffic it gets relative to a similar term. Because you get no hard numbers you must remember to keep everything relative. I like to do a common search with every query so I know how much traffic I get relative to the keyword I learn about. For example, if I want to write an article for an article website, I may try to test Free Content, and Free Articles. To compare these two searches I separate them with a comma and hit search. Then I see that Free Articles is very close to Free Content. I can also choose to add a third keyword if I would li