Microsoft combats another IE 5 bug

By Erich Luening, CNET News.com, CNET.com
Wednesday, September 29, 1999 11:30 PM
Microsoft continues to battle security problems in Internet Explorer 5.0 that make computers vulnerable to attack by malicious Web site operators.

The latest security issue involves an IE 5 feature called "download behavior" that allows a Web page to download files for use in client-side scripting.

By design, a Web site should be able to download files that reside in its domain, preventing client-side code from exposing files on the user's machine. The problem is that a server-side redirect can be used to bypass this restriction, enabling a malicious Web site operator to read an unsuspecting user's local files, according to Microsoft.

As a result of the problem, text files from the user's disk, or local Web server, may be read and then sent to an arbitrary server on the Internet, allowing the user's files to be "stolen," according to Bulgarian programmer Georgi Guninski, who has been credited with discovering numerous security holes in Microsoft and America Online's Web browsers.

"This vulnerability would chiefly affect workstations that are connected to the Internet," Microsoft said in a security alert released yesterday.

The company said it is working on a patch for the problem. "As an immediate measure, customers can prevent the download behavior function from operating by disabling ActiveScripting," according to the security bulletin.

The security hole is the latest in a series of bugs plaguing the software giant's IE browser.

Guninski reported a similar hole in IE in August. Microsoft patched yet another hole in IE's armor around the same time.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Calculate IOPS in a storage array

Enterprise Servers & Storage

What drives storage performance? Is it the iSCSI/Fiber Channel choice? The answer might surprise you. Scott Lowe provides insight into IOPS.


Read more »



When journalists become lil' Twittering birds

Blog thumbnail

It was bound to happen eventually. Love it or hate it, the entire ZDNet team is now on Twitter.

We created a general account over a year ago that we..... by Eileen Yu

Read more »

Tags

  1. battery
  2. camera
  3. graphics
  4. hard drive
  5. hewlett - packard co.
  6. high tech computer corp.
  7. intel corp.
  8. keyboard
  9. microsoft windows
  10. microsoft windows mobile
  11. mobile
  12. network
  13. notebook
  14. performance
  15. screen
  16. server
  17. storage
  18. touchpad
  19. usb
  20. vat