subject: (Fwd) [ISN] IE bug could open the gates for hackers posted: Sat, 31 Mar 2001 11:14:24 +0100
M$: Just Say N0
------- Forwarded message follows -------
Date sent: Wed, 28 Mar 2001 23:51:17 -0600
Send reply to: InfoSec News <[email protected]>
From: InfoSec News <[email protected]>
Subject: [ISN] IE bug could open the gates for hackers
To: [email protected]
A newly discovered bug in Microsoft's Internet Explorer Web browser
could let malicious hackers read the e-mail and computer files of some
unsuspecting people.
Bug tracker Georgi Guninski said the exploit is activated when a
surfer using Internet Explorer 5 loads a malicious Web page. The
surfer's network also must be running Microsoft's Exchange 2000 server
for the bug to show up.
The bug lists the directories of some servers the Web surfer can
access, which could enable viewing of the person's e-mails or folders
if they are stored on a Microsoft Exchange 2000 server. The malicious
hacker would have to know some of the Web surfer's usernames.
Guninski has rated the bug's risk as "high," and he said people can
alleviate the problem by disabling Active Scripting, a browser setting
that offers enhanced functions but has been repeatedly associated with
potential security risks.
Microsoft did not immediately return requests for comment. But in a
message posted on Guninski's site that apparently comes from
Microsoft's Security Response Center, the company asked him for a
further explanation of the bug "so you are not just scaring people."
The message also said that "visiting malicious Web sites is not a real
exploit scenario."
Microsoft has come under fire in recent years for allegedly valuing
interoperability between its products over security. In its quest to
provide many pieces of software that interact with each other, some
security experts say the company has been lax in addressing possible
holes that could allow malicious hacker exploits.
Most notably, Microsoft's Outlook messaging software, which is used by
millions of people throughout the world, played a key role in the
rapid spread of viruses including I Love You and Melissa.
ISN is hosted by SecurityFocus.com
---
To unsubscribe email [email protected] with a message body of
"SIGNOFF ISN".
------- End of forwarded message -------
generated by msg2page 0.06 on Jul 21, 2006 at 19:04:46