Slashdot Mirror


New Attack Fells Internet Explorer

alphadogg writes "Attack code has been identified that could be used to break into a PC running older versions of Microsoft's Internet Explorer browser. The code was posted Friday to the Bugtraq mailing list by an unidentified hacker. According to security vendor Symantec, the code does not always work properly, but it could be used to install unauthorized software on a victim's computer."

9 of 202 comments (clear)

  1. What the world needs by hey! · · Score: 4, Interesting

    is a definitive software engineering treatise on the history of IE security exploits.

    It is certainly true that there is a kind of economic network effect going here. For many years we saw so many web sites that only worked properly with IE because IE was so dominant. The same factor naturally attracts black hats looking for systems to exploit. Once we factor that out, what can we learn from how IE was conceived and maintained?

    Did clumsy code-reuse and maintenance play a significant role? That is did they stretch existing code to do things it hadn't been designed to do because it was close enough to pass the demo test on time? That's a decision we all face; we'd all *like* to rewrite things better when we take a look at them, but in the real world we've got to ship good enough code on a deadline to justify our salary. I think MS might be particularly vulnerable to the "killer demo" imperative. They are a business that is dependent on organizations choosing entire MS product stacks because they *anticipate* something they're going to need in the future will be dependent on something else in that stack.

    Did "business strategy" considerations confuse priorities for system requirements? E.g., The decision to make IE a fundamental part of the OS allowed MS to gain control of (destroy) the browser market while evading anti-trust regulation. Did that result in undesirable coupling of IE to the underlying system? Did the desire to leverage browser market dominance to give other MS products a competitive advantage create confusion in requirements or priorities?

    Were there cultural attitudes that made security and quality secondary? E.g. Did MS value having shiny new features soon before doing a quality implementation? Did their success at achieving effective control of the browser market cause them to under-invest in maintenance because they had no competition worth worrying about?

    These are the kinds of things I'd like to know. It's almost past the point where any individual security flaw in IE is interesting to me, because there have been so many and will be so many more. It's time for a really first rate summing up by somebody who knows what he's talking about.

    --
    Post may contain irony: discontinue use if experiencing mood swings, nausea or elevated blood pressure.
    1. Re:What the world needs by DoofusOfDeath · · Score: 2, Interesting

      is a definitive software engineering treatise on the history of IE security exploits.

      Yup. We definitely need a "Truth and Reconciliation Commission" for what Microsoft has done to us. Whether or not to prosecute them later is a political decision. ;)

  2. Re:A great reason to choose Firefox by Zero__Kelvin · · Score: 3, Interesting

    "It sounds like the root flaw actually lies in your own login implementation."

    "Second, special casing code for IE is a fact of life in the web development world, and you should just get used to it."

    It looks like there is a root flaw in your logic implementation there jbacon. You are right about the special casing needs, but a simple redirection to a page explaining that they are using a non-standards compliant virus sink with links to getfirefox.com and articles backing up the claim would be much more effective in the long run. In fact, if there weren't so many web designers with root flaws in their logic akin to yours, it would benefit in the short run. About the third or fourth time the user had to choose to use a standards compliant web browser or stop visiting the site(s) they want to visit, they would get the message.

    --
    Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
  3. Re:Is that supposed to be news?? by lord_rob+the+only+on · · Score: 4, Interesting

    Using SAP by any chance ?

    In my former company, they use SAP and it's absolutely an IE only application for its web interface. It doesn't work *at all* with Firefox. At least that was the case when I was working there (We were using SAP ECC6)

  4. Re:Is that supposed to be news?? by MillionthMonkey · · Score: 3, Interesting

    I'm tired of constantly upgradng everything. I drive an old car built in 1997, and I don't understand why I can't keep running the same browser at least a few years. Yeah I know - constant updating keeps programmers employed.

    Drat, improving technology keeps programmers employed.
    Double drat- your reluctance to update combined with a propensity to complain keeps additional people employed just to make sure things continue to look pretty on your screen.

  5. MSIE version 8 is not known, according to TFA. by jbn-o · · Score: 2, Interesting

    The problem isn't anything Microsoft doing, it's users who don't upgrade their OS. Did you notice the part where this only affects IE6 and IE7? Upgrade to IE8, and, presto, you're immune!

    Some users, like office workers, are not in control of the computers they use and cannot switch away from what they were given. Sometimes they were set up with particular versions of software to suit other programs. The "Banner" system some universities use, for instance, requires MSIE7 and a particular old version of Sun's Java runtime. Certain sections of Banner don't work properly with non-MSIE browsers like Firefox. I understand this is an extremely costly system and switching away is considerably complicated. I'm not endorsing these choices or claiming any of these choices is wise, but it is there.

    The article also says the status of MSIE8 is not mentioned by the researchers: "Neither company [Symantec and Vupen] was able to confirm that the attack worked on Microsoft's latest browser, IE 8.". What part of what article were you referring to?

  6. Re:Is that supposed to be news?? by Max+Littlemore · · Score: 2, Interesting

    Care to name the bank? That should be public knowledge - or at least available to all customers and any potential customers.

    --
    I don't therefore I'm not.
  7. Re:Is that supposed to be news?? by Nefarious+Wheel · · Score: 2, Interesting

    Software doesn't wear out.

    Yes it does.

    When the world around a piece of running software changes, that piece of software in the middle often doesn't work like it used to. Yes, it's contextual, but it's also mostly true. It's often (humourously) referred to as the "principle of bit decay".

    Basically, if it works, it's obsolete.

    --
    Do not mock my vision of impractical footwear
  8. Re:Is that supposed to be news?? by http · · Score: 2, Interesting

    HTML 4 has not changed in over a decade.. EMCA 262 (Javascript) was released almost exactly a decade ago. Version 4 died on the table, and 5 isn't out for a while yet.
    What is the improving technology?

    --
    If opportunity came disguised as temptation, one knock would be enough.
    3^2 * 67^1 * 977^1