December 23, 1999 1:35 PM PST
IE suffers security hole
- Related Stories
-
Software security firm claims flaw in Netscape email
December 15, 1999 -
Microsoft, Netscape facing browser bugs
December 13, 1999 -
IE 5 bug could let Web hackers see files
November 23, 1999 -
Outlook vulnerable to masquerade attack
November 8, 1999 -
Microsoft fights handful of IE holes
October 18, 1999 -
Microsoft admits browser security hole
October 12, 1999
The vulnerability involves JavaScript, a versatile Web scripting language for executing actions on a Web page without user input. JavaScript is widely used on the Web and has proved a boon for bug hunters, who have turned up dozens of ways to use it to circumvent browsers' security checks.
The IE search command NavigateAndFind directs the browser to find a Web page and highlight a specified portion of text there. Normally, IE will perform a security check to make sure the command does not specify a file on the Web surfer's computer.
But if NavigateAndFind is directed toward a JavaScript URL within a frame, a smaller window within a Web page, that security check fails to kick in and code within the JavaScript URL can be executed to spy on any file on the user's computer that could be opened in a browser window. These include .doc, .html and .jpeg files.
Microsoft said that while the files could be examined by an attacker, they could not be changed or deleted.
The bug's discoverer, Bulgarian security enthusiast and JavaScript bug hunting champion Georgi Guninski, recommended that users disable Active Scripting in IE. He posted a demonstration of the exploit, which he warned could be executed by sending an HTML message.