28 January 2004
New Explorer hole could be devastating
A little imagination could undermine browserBy Kieren McCarthy, Techworld
A security hole in Microsoft’s Internet Explorer could prove devastating.
Following the exposure of a vulnerability in Windows XP earlier this week, “http-equiv” of Malware has revealed that Explorer 6 users (and possibly users of earlier versions) could be fooled into downloading what look like safe files but are in fact whatever the author wishes them to be - including executables.
A demonstration of the hole is currently on security company Secunia’s website and demonstrates that if you click on a link, and select “Open” it purports to be downloading a pdf file whereas in fact it is an HTML executable file.
It is therefore only a matter of imagination in getting people to freely download what could be an extremely dangerous worm - like, for instance, the Doom worm currently reeking havoc across the globe.
However what is more worrying is that this hole could easily be combined with another Explorer spoofing problem discovered in December.
more...
http://www.techworld.com/news/index.cfm?fuseaction=displaynews&NewsID=944Security firm warns of new IE flawLast modified: January 28, 2004, 2:20 PM PST
By David Becker
Staff Writer, CNET News.com
A security services company warned of a new vulnerability in Microsoft's Internet Explorer Web browser that could allow Web surfers to be tricked into downloading malicious files.
Danish company Secunia posted details of the alleged flaw, which could be used in combination with an earlier "spoofing" flaw reported by the company.
Microsoft representatives did not immediately respond to a request for comment.
The new flaw could allow the owner of a malicious Web site to deliberately misidentify a downloadable file, so a malicious program file could be made to appear as if it were a secure file. Visitors might think they were downloading a document based on Adobe's portable document format (PDF), for instance, but actually receive a malicious, self-executing program such as the new MyDoom worm.
more...
http://news.com.com/2100-1002_3-5149583.html