Free Technology Newsletters
» All 33 InfoWorld Newsletters
Technology & Business Daily
 
InfoWorld
 

Hackers publish code for critical IE bug

All users of Internet Explorer version 5.5 and 6.x are affected by the vulnerability, security experts say

By Robert McMillan, IDG News Service
November 21, 2005
 

Security experts are warning Internet users to be careful where they click, thanks to a nasty unpatched bug in the way Microsoft Corp.'s Internet Explorer browser handles the JavaScript computer language. The bug is of particular concern because security researchers in the U.K. have now published "proof of concept" code showing how hackers could exploit the problem and possibly take over a Windows system.

Free IT resource

InfoWorld Podcast: Interview with log management expert Dominique Levin.

Sponsored by LogLogic

Free IT resource

Learn how to increase network productivity and agility without compromising security.

Sponsored by HP ProCurve

The proof of concept code (http://www.computerterrorism.com/research/ie/ct21-11-2005) was published Monday by Computer Terrorism Ltd., a London security research firm. It exploits a problem in the way Internet Explorer processes the "Window()" function in JavaScript, a popular scripting language used by Web developers to make their sites more dynamic.

Though security experts had known about this JavaScript problem for months, (http://seclists.org/lists/bugtraq/2005/May/0330.html) they did not know that it could be used to do anything more than crash a user's computer, said Russ Cooper, editor of the NTBugtraq newslist and a scientist with security vendor Cybertrust Inc. "The vulnerability has been around since May. It's only now that somebody has figured out how to turn it into something that runs exploitable code," he said.

Users would need to be tricked into clicking on a Web link in order to launch the malicious code, Cooper said. But once that was done, it could set up a chain of events that could ultimately let a hacker gain control of the user's system, he said.

All users of Internet Explorer version 5.5 and 6.x are affected by the vulnerability, Computer Terrorism said.

The problem is serious enough that Cooper believes that Microsoft will patch Internet Explorer in advance of its next monthly security update, which is scheduled to occur Dec. 13. "I would expect Microsoft to go into emergency patch mode and push something out very quickly," he said.

No one at Microsoft was available for immediate comment on the issue.

To avoid the problem, the SANS Internet Storm Center is advising users to turn off JavaScript, which can be done by disabling "Active scripting" in Internet Explorer's Internet Options menu, or to use an alternative browser like Firefox or Opera. (http://isc.sans.org/diary.php?storyid=874)




 



TOP NEWS:


» HP's Dunn, four others charged
Felony charges include using false or fraudulent pretenses, wrongful use of computer data, identity theft, and conspiracy

» Steve Jobs knew of backdating
Apple CEO apologizes after internal investigation shows he was aware of the company backdating employee stock options

» Yahoo kicks off mobile ad test
Yahoo, Google looking to expand search advertising to the mobile Web

» NSA wiretapping program can continue
Appeals court allows the Bush administration's surveillance to proceed while waiting for an appeal on an earlier ruling

» Tension envelops U.S. oversight of ICANN following extension
Strong sentiments on either side reflect a chronic, troubling tension that has enveloped ICANN since 1998

» Report: HP's Dunn, others facing state indictment
California Attorney General Bill Lockeyer is expected to indict over pretexting on Wednesday, the New York Times reports




SIMPLY YOUR MOVE TO DISK-TO-DISK BACKUP
Join this live Webcast on October 12th with NetApp and Symantec and learn how integrating VERITAS(R) NetBackup(TM)'s robust management capability with the powerful NetApp disk backup offerings can simplify your move to disk-to-disk backup in a multi-vendor storage environment.

»  Click here to view this Webcast
  EXCHANGE MANAGEMENT SPONSORED SOLUTION GUIDE
Learn about various approaches to simplifying the management of Microsoft Exchange by downloading a new Sponsored Solution guide from InfoWorld, Exchange Management.

» Click here to download now


- Special Advertising Partners -
WHITE PAPERS
 
>> WHITE PAPERS LIBRARY

WHITE PAPERS E-MAIL ALERT

Find out when the latest white paper is available:

 

»  Learn more about endpoint security - For today's computing environments, there is little question that endpoint security is a necessary yet complicated undertaking. Get a better understanding of the endpoint security problem and the ...
»  IT Strategies to Simplify, Accelerate, and Grow Your Business - Empowered by enterprise architecture with the flexibility of standardized business processes, IT is taking business to a new level of collaboration. This is what the next generation of IT is bringing. ...
»  SpringCM Whitepaper: Is On-Demand Document Management Right for You? - The right approach to document capture, retention and management is essential given your need to know – where content is located, who has access to it, who may change, copy, or delete it, and can it ...
»  Beyond BPM is the Intelligent Document.
»  Keeping Your Cool in the Datacenter: Consolidating and Virtualizing Your IT Infrastructure
»  2006 IT Compliance Benchmark Report

 
MORE SECURITY WHITE PAPERS


WHITE PAPERS BY TOPIC


Application development
Applications
Business
Hardware
Networking
Platforms
Security
Standards
Storage
Telecom
Web services
Wireless
» Prevent Information Leaks from your Network
The GTB Inspector is a hardware appliance, preventing leaks of confidential data from a network. ...
» Introducing Intel� vPro" Technology
Need a better game plan for managing your desktop fleet? Go Pro. Intel� vPro" Technology has ...
» Identify, Solve Supply Chain Issues
Yankee Group analysts show you how market-leading companies are aligning shared processes to ...
» Network Security for Small to Medium Size Business
The more your small- to medium-sized business relies on information and an Internet connection, the ...
» Kaspersky: Sell The Best. Make the Most!
Kaspersky's Channel Partner Program was designed to maximize our VARs margins while giving the ...

 
SPONSORED LINKS  

»  Sun Event - Our latest innovations for your IT challenges. View Now
»  HP - Empower your business with the new HP BladeSystem c-Class.
»  Novell - Your Linux is ready(TM). Get SUSE Linux Enterprise 10 from Novell(R)
»  Citrix - Learn to deliver any app securely at Citrix iForum 06.
»  HP - It's Your Business on Paper. Make it Look Good. Brilliantly Simple. HP
 


INFOWORLD MARKETPLACE


» Introducing Intel� vPro" Technology
Need a better game plan for managing your desktop fleet? Go Pro. Intel� vPro" Technology has ...
» Setting Business Email & Web Usage Policies
October 11, 2006, 11:30am EST Attend this webinar to gain an insight into strategies that could help ...
» Citrix iForum 2006
Industry leaders help solve your business challenges - Citrix iForum!
» Report illegal software use -- $200,000 reward
Report illegal software use confidentially and you may be eligible for a reward of up to $200,000.
» Want to know your CIS security score?
The CIS has developed detailed IT security benchmarks which will help make your computer more ...


 

FREE SUBSCRIPTION


Order today to get your FREE subscription (a $195 value!) to InfoWorld magazine, the weekly publication that provides indispensable product information to IT professionals.


NOTE: Complimentary subscriptions sent only to those applicants who qualify.

First Name:
Last Name:
Company Name:
Title:
Mailing Address:
City:
State/Province:
Zip/Postal Code:
Email Address:


NOTE: Offer valid in U.S. and Canada only
Non-U.S. click here


FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


AJAX issues debated
Multiple issues around AJAX (Asynchronous JavaScript and XML) were raised at the AJAXWorld Conference and Expo on Wednesday, including debate over lightweight vs. heavy development frameworks. Lightweight frameworks are those considered to be ...

Getting a feed on the competition
Keeping tabs on the competition just got a little snazzier, thanks to a new competitive intelligence service from Dream This, as reported by Marshall Kirkpatrick at TechCrunch. Sporting a moniker right out of Andrew Wooldridge's Web Two Point Oh! ...

JON UDELL'S CORNER 


Jon Udell's Column and Blog Evolving Amazon's services into products
(InfoWorld) - The announcements from Amazon Web Services LLC just keep on coming. The latest news flash is...

Jon's Blog | Jon's Column

COLUMNISTS

IT's virtual asset economy
Tom Yager's Column and Blog (InfoWorld) - The phrase “kid in a candy store” conjures up a dazzling dreamscape of treats and an...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Security Adviser 
Great book for new PGP or GPG users
I just got through reveiewing a great book on PGP and GPG on email encryption. It's called PGP & GPG: Email for the ...

Virtualization Report 
PHD Technologies Creates First Virtual Backup Appliance for VI3
PHD Technologies, Inc. (PHD), announced the release of esXpress v3 for VMware VI3. The company has created patented ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Jon's Radio
• Open Sources
• ProdBlog
• Real World SOA
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
Five to Face Charges in HP Scandal
Computer Science Professor Argues For a Paper Trail With E-Voting
Foley Lawyer Cites Alcohol, Childhood Abuse



 HOME  NEWS  COLUMNS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS  IT EXEC-CONNECT   About | Advertise | Awards | Store | Contact Us 

Copyright © 2006, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

ComputerWorld :: LinuxWorld :: Network World :: CIO :: PC World :: CSO
IT Careers :: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp
ITWorld Canada :: Computerwoche :: Techworld UK :: tecChannel :: IDG.se :: IDG.no :: IDG.pl