• On MovieTome: Megan Fox on TRANSFORMERS 2!

July 5, 2006 5:15 PM PDT

Security expert dubs July the 'month of browser bugs'

Related Stories

Browser bugs hit IE

June 29, 2006

Microsoft releases final IE 7 beta

June 29, 2006

Microsoft meets the hackers

June 16, 2005
Each day this month, a prominent security expert will highlight a new vulnerability found in one of the major Internet browsers.

HD Moore, the creator of Metasploit Framework, a tool that helps test whether a system is safe from intrusion, has dubbed July the Month of Browser Bugs. Already, the security researcher has featured five security flaws, three for Microsoft's Internet Explorer and one apiece for Mozilla's Firefox and Apple Computer's Safari.

Moore noted that one of the IE bugs appeared to have been recently patched.

"This blog will serve as a dumping ground for browser-based security research and vulnerability disclosure," Moore said on his blog. "The hacks we publish are carefully chosen to demonstrate a concept without disclosing a direct path to remote code execution."

Browser security holes are nothing new, but Moore's repository of flaws shines a light on the problem.

Moore says on his site that he reported two of the IE bugs to Microsoft last March. Microsoft acknowledged that it had been in contact with Moore but downplayed the seriousness of the flaws Moore is publicizing.

"(Microsoft's) investigation has revealed that most issues relating to Internet Explorer in particular will result in the browser closing unexpectedly," the company said in an e-mail statement.

Moore doesn't indicate how many of his published vulnerabilities are critical, but security company Secunia has rated one of the flaws, which Moore calls Internet.HHCtrl Image Property, as highly critical.

See more CNET content tagged:
security, vulnerability, Microsoft Internet Explorer, Web browser, flaw

Add a Comment (Log in or register) 8 comments
IE
by Roman12 July 5, 2006 9:34 PM PDT
It's obviously true that no browser is perfect, but I think you're always best off using the less popular browsers. Microsoft can barely keep up releasing all these patches to cover up the flaws because of IE's default popularity. I often check my web site's statistics to find that 80% of the visitors are IE users, I bet if Opera or Firefox became super popular it would suddenly become a dangerously "insecure" browser much like IE now. So in my opinion the real reason why Opera and Firefox are a better choice for an average user isn't because of security policies or other security features, but because they aren't targeted as much by people that wish to do damage, to affect the most amount of users possible it just makes sense to target IE.
__________________________________
R.K.
http://www.Remove-All-Spyware.com/
Reply to this comment
IE
by Roman12 July 5, 2006 9:34 PM PDT
It's obviously true that no browser is perfect, but I think you're always best off using the less popular browsers. Microsoft can barely keep up releasing all these patches to cover up the flaws because of IE's default popularity. I often check my web site's statistics to find that 80% of the visitors are IE users, I bet if Opera or Firefox became super popular it would suddenly become a dangerously "insecure" browser much like IE now. So in my opinion the real reason why Opera and Firefox are a better choice for an average user isn't because of security policies or other security features, but because they aren't targeted as much by people that wish to do damage, to affect the most amount of users possible it just makes sense to target IE.
__________________________________
R.K.
http://www.Remove-All-Spyware.com/
Reply to this comment
IE's problem isn't its popularity...
by i_made_this July 6, 2006 7:23 AM PDT
...most of its security-related problems devolve to the browser's use of ActiveX which seems to be the component that most aggressively attracts malware. MSFT can *update, improve, assign a new higher level product number* etc all they want to IE, but until ActiveX becomes an optional component and not part of the Windows bundle, IE will remain as holey as swiss cheese. I assure you that Redmond knows this better than we do, and I doubt they'll remove ActiveX in the foreseeable future.
Reply to this comment View reply
IE's problem isn't its popularity...
by i_made_this July 6, 2006 7:23 AM PDT
...most of its security-related problems devolve to the browser's use of ActiveX which seems to be the component that most aggressively attracts malware. MSFT can *update, improve, assign a new higher level product number* etc all they want to IE, but until ActiveX becomes an optional component and not part of the Windows bundle, IE will remain as holey as swiss cheese. I assure you that Redmond knows this better than we do, and I doubt they'll remove ActiveX in the foreseeable future.
Reply to this comment View reply
News.com (hearts) security company PR.
by M C July 6, 2006 10:33 AM PDT
One more regurgitated press release. Please.
Reply to this comment
News.com (hearts) security company PR.
by M C July 6, 2006 10:33 AM PDT
One more regurgitated press release. Please.
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right