Showing posts with label Internet Explorer. Show all posts
Showing posts with label Internet Explorer. Show all posts

Thursday, December 06, 2007

New Exploit Targets Internet Explorer

Article by Jabulani Leffall
One week before the last Patch Tuesday of 2007 and two weeks after a researcher in New Zealand discovered holes in Microsoft's Web Proxy Automatic Discovery (WPAD) program, Redmond this week issued its latest in a long line of security advisories. Tim Rains of Microsoft's Security Response Center wrote in a blog post on Monday that Windows XP SP2, Windows Server 2003 SPs 1 and 2 and Windows Vista are all vulnerable to WPAD server manipulation.
This vulnerability also affects all supported versions of Internet Explorer, a browser which most commonly uses the WPAD function to locate an automatically configured proxy file to determine settings on offsite servers and by extension affecting Internet traffic flow through server indentification and authentication.
Potential vulnerabilities first came to light around Thanksgiving weekend when Redmond's software engineers responded to the results of a presentation made by Beau Butler, a New Zealander and self-described "ethical" hacker. Butler's work revealed that a hacker can use WPAD files to intercept and manipulate all Internet traffic on a given network. Butler said 160,000 computers in New Zealand alone could be seized with just one attack.

Media reports have claimed that U.S. computers are not vulnerable to the attack. However, it appears Microsoft isn't taking any chances, as the software giant said it released the security advisory as it investigates "new public reports of a vulnerability in the way Windows resolves hostnames that do not include a fully-qualified domain name." Thus an issue that was supposed to have been resolved in 2005 has become a 2007 fix as the minute technical overhaul made back then only addressed the ".com" domain name, and not other suffixes such as ".org," ".tv," and non-U.S. country tags -- in the case of the hacker's findings, "nz."

This week, Microsoft added a new specification to the vulnerability profile stating that "Customers whose domain name begins in a third-level or deeper domain, such as "contoso.co.us," are at risk. Conversely, among those not at risk are IT shops where a manually specified proxy server is in place for IE. Additionally, those who have disabled the "Automatically Detect Settings" command in IE can also work around the issue.

Jabulani Leffall is an award-winning journalist whose work has appeared in the Financial Times of London, Investor's Business Daily, The Economist and CFO Magazine, among others.

Friday, May 18, 2007

Google Research Finds 10 Percent of Web Pages Hold Malware

According to research from Google, 10 percent of web pages contain malicious code. Google closely analyzed 4.5 million web pages over the course of a year and found that approximately ten percent, or 450,000, had the capability of installing malware without users' knowledge. An additional 700,000 pages are believed to be infected with code that could harm users' computers. The company says it has "started an effort to identify all web pages in the Internet that could be malicious."
Most entice users to visit the dangerous pages through tempting offers, and exploit holes in Microsoft Internet Explorer (IE) to install themselves on users' computers. Google also examined the vectors used by attackers to infect these web pages; most malicious code was located in elements beyond the control of website owners, such as banner advertisements and widgets.

References:
Google Searches Web's Dark Side
The Ghost in the Browser: Analysis of Web-based Malware
[SANS.org Editor's Note (Skoudis): This is a very good piece of research, and contributes significantly to our understanding the malware threat better. I recommend that you read it. Also, it shows that today's Internet is a cesspool of malware. Using mainstream browsers with patches that often follow weeks after exploits are in the wild is an increasingly dangerous proposition.]
Source: SANS NewsBites Vol. 9 Num. 39


CORRECTION: 05.21.07
From SANS.org -- Regarding the story we ran in the last edition of NewsBites about Google's Web-Based Malware study: The researchers identified 450,000 URLs launching drive-by downloads from a set of 4.5 million, which in turn had been culled from a larger set of 7 billion URLs, giving a much lower rate of malware incidence than we indicated. We regret any confusion this may have caused.

Tuesday, February 13, 2007

Internet Explorer Multiple Vulnerabilities

TITLE: Internet Explorer Multiple Vulnerabilities
SECUNIA ADVISORY ID:
SA24156
VERIFY ADVISORY: http://secunia.com/advisories/24156/
CRITICAL: Highly critical
IMPACT: System access
WHERE: From remote
SOFTWARE:
Microsoft Internet Explorer 6.x
http://secunia.com/product/11/
Microsoft Internet Explorer 7.x
http://secunia.com/product/12366/
DESCRIPTION:
Some vulnerabilities have been reported in Internet Explorer, which can be exploited by malicious people to compromise a user's system.
1) An error within the instantiation of COM objects (Imjpcksid.dll and Imjpskdic.dll) not intended to be instantiated in Internet Explorer can be exploited to cause a memory corruption.
2) Another error within the instantiation of COM objects (Msb1fren.dll, Htmlmm.ocx, and Blnmgrps.dll) not intended to be instantiated in Internet Explorer can be exploited to cause a memory corruption.
3) An error within the parsing of FTP server responses can be exploited to cause a memory corruption via a specially crafted response sent to the FTP client in Internet Explorer.
Successful exploitation of the vulnerabilities allows execution of arbitrary code.
SOLUTION: Apply patches.
Internet Explorer 6 for Windows XP SP2
Internet Explorer 7 for Windows XP SP2

PROVIDED AND/OR DISCOVERED BY:
1) Reported by the vendor.
2) The vendor credits H D Moore, BreakingPoint Systems.
3) The vendor credits iDefense Labs.

ORIGINAL ADVISORY: MS07-016 (KB928090)

EDITORIAL: The revolution in Internet browsing, Microsoft's secure browser, Internet Explorer 7 is... a flop. Just a few months after the much-heralded release of IE7, we find that it's just as full of holes as IE6. The Trustworthy Computing initiative hasn't worked. Internet Explorer is still a huge problem for network security admins around the world.