PDA

View Full Version : Internet Explorer: Gates open to hacker attacks


Paul Wilders
February 25th, 2002, 08:08 AM
{QUOTE-> Leading firm in Internet ExplorerÔ and XML technology based software development, Ivy Hungary Ltd. found a critical security fault in Internet ExplorerÔ. The deficiency was discovered during development of a new component for their key product IVYŇ, which would manage data of remote web sites from a central location, allowing the consolidation of data gained from various Internet sources.

Abusing this security loop, hackers and ill-intentioned web site operators can open a gate to the user’s computer or install a worm script on it. Through the gate, the intruder can steal any file from the cracked computer and read the cookies, containing the owner’s personal data, at will, without the victim even detecting it. It is possible to write a worm script that snoops the internet traffic of the attacked machine and redirects sensitive information, including passwords and credit card numbers, to the hacker’s mailbox.

To be susceptible of such an attack, one does not have to download files from the Internet, a simple visit to a corrupted web page suffices. There are only very few completely safe web pages: hackers can smuggle in the harmful code to any web site they have cracked.

Any Internet ExplorerÔ installation is affected, regardless of version or operating system, thus 97 % of the world’s Internet users are in continuous danger. Following the alert of Ivy Hungary Ltd., Microsoft has issued a hotfix. It is strongly recommended for everyone to urgently download this hotfix from the Windows Update site. <-QUOTE}

read the whole story here: http://w3.ivy.hu/

spy1
February 25th, 2002, 09:43 AM
I don't know about anyone else, but I'm pretty much ready to un-install IE altogether - I'm not even sure anymore if just not using it is enough of a safety precaution! :) *Pete

Detox
February 25th, 2002, 04:05 PM
crap.. and that's the only browser I use too :-( Well I am about to get a copy of an older Netscape.. 4.xx...
for my silly computer science class...

BlitzenZeus
February 25th, 2002, 04:16 PM
Gee thanks Billy..... *Thanks for making our computers more insecure *:P

javacool
February 25th, 2002, 05:06 PM
It's quite simple to prevent these problems in the future - get that team of security people at Microsoft combing through the IE code and Windows code a lot faster!

Or MS could always re-build IE from scratch *;) ...

javacool
February 25th, 2002, 05:08 PM
{QUOTE-> I don't know about anyone else, but I'm pretty much ready to un-install IE altogether - I'm not even sure anymore if just not using it is enough of a safety precaution! :) *Pete <-QUOTE}

Unfortunately, that's the sad truth...

Given how much IE is tied in with Windows, I don't see how it would be much of a problem for someone to make a program that would use those exploits to cause havok on your system(s)...

And it's sad that users with Windows XP (which I must admit, is an improvement over previous versions) may not be able to get rid of IE at all... (please point me to some information discrediting my assumption...I beg you...)