Security [CENTRAL] Forum - SCforum.info
24. May 2012., 01:18:16 *
Welcome, Guest. Please login or register.

Login with username, password and session length

SCforum.info - Security [CENTRAL] Forum

↑ Grab this Headline Animator

Custom Search
News: For ultra cheap bullet proof vests, hard armor ballistic plates or for advice on body armor in general visit SafeGuardClothing.com
 
  Home Help Chess Links Login Register   *

SCforum.info


furniture store



Members
Total Members: 11256
Latest: rbraik
Stats
Total Posts: 15636
Total Topics: 4337
Online Today: 2172
Online Ever: 51419
(01. January 2010., 10:27:49)

SCF UnSpam

Top Ten Antivirus Software

Friend of WOT


SCF Feedburner

SCF Facebook

SCF Twitter

Welcome to SCforum.info - Security [CENTRAL] Forum, a home of the SCF Community devoted to provide Computer related News, Alerts, Downloads and FREE Help in such a way that even the novice computer user can understand.

Getting started using our community is extremely easy, check the two steps below:

Step 1: Create an account by clicking here and wait for approval from Administrator. It's completely free with no hidden strings attached.

Step 2: If you have a computer problem and need some help, or just want to take part in opened discussions, simply browse Forum. Once you *Register an account, you can quickly post your questions and comments.

(*Registered Members get: free support, also, they can communicate privately with other members via PM, removal of this message, see fewer ads and much more...)






Pages: 1
  Print  
Author Topic: Microsoft research very old "CSS cross-origin theft" bug in Internet Explorer  (Read 908 times)
0 Members and 2 Guests are viewing this topic.
Samker
SCF Administrator
*****

KARMA: 86
Gender: Male
Location: Europe
Posts: 5077


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« on: 07. September 2010., 16:06:32 »



Microsoft is looking into a long-known vulnerability in Internet Explorer that could be used to access users' data and Web-based accounts.

The bug can allow hackers to hijack Web mail accounts, steal data and send illicit tweets, Google security engineer Chris Evans said in a message posted on the Full Disclosure mailing list: http://seclists.org/fulldisclosure/2010/Sep/64

Evans also published a demonstration that showed how the flaw in IE8 could be used to commandeer a user's Twitter account and send unauthorized tweets: http://scary.beasts.org/misc/twitter.html

The vulnerability, known as a "CSS cross-origin theft" bug, has a long history. Researchers at Carnegie Mellon University, who recently published a paper ( download PDF: http://websec.sv.cmu.edu/css/css.pdf ) on the subject, have traced it back as far as 2002. Those researchers will present their paper at the Conference on Computer and Communications Security next month.

Even so, the flaw received little attention until Evans blogged about it in December 2009.: http://scarybeastsecurity.blogspot.com/2009/12/generic-cross-browser-cross-domain.html
He had submitted a bug report for Chrome eight months earlier: http://code.google.com/p/chromium/issues/detail?id=9877

Although Microsoft has not patched the vulnerability in IE8, other browsers, including Firefox, Chrome, Safari and Opera, have fixed the flaw. Google patched the bug in Chrome last January, while Mozilla did the same in July with Firefox 3.6.7 and Firefox 3.5.11.

IE9 includes a fix for the vulnerability. Microsoft plans to ship a public beta of IE9 on Sept. 15.

On Friday, Evans explained why he was adding to the patch pressure by crafting a proof-of-concept. "I have been unsuccessful in persuading the vendor to issue a fix," he said of Microsoft.

Microsoft issued a statement Friday saying it was investigating Evans' reports, but declined to answer questions on Monday, including whether earlier versions of IE were vulnerable or why it has not yet addressed the bug.

"We're currently unaware of any attacks trying to use the claimed vulnerability or of customer impact," said Jerry Bryant, a group manager with the Microsoft Security Response Center, in the e-mailed statement.

Microsoft should not have been surprised by Evans' disclosure. In early August, Evans blogged that IE8 was the "most vulnerable" to the flaw: http://scarybeastsecurity.blogspot.com/2010/08/internet-explorer-considered-harmful.html
In that blog, Evans also said he had a proof-of-concept able to appropriate a Web mail account. "It's a nasty attack," Evans said, "E-mail someone a link and if they click it, they are owned with a pure browser cross-origin bug."

This isn't the first time that someone from Google has released information about a bug in Microsoft software after claiming he got the cold shoulder. Earlier this summer, Tavis Ormandy -- like Evans a Google security researcher -- went public with a Windows flaw after he said Microsoft wouldn't commit to a patching deadline. Microsoft disputed Ormandy's account.

Microsoft eventually pushed up the patch date for Ormandy's bug by a month.

On Friday, Bryant reiterated Microsoft's position on early disclosures. "To minimize risk to computer users, Microsoft continues to encourage coordinated vulnerability disclosure," he said, referring to his company's new term for keeping vulnerability information secret until a patch is available.

(PCW)
Logged

Security [CENTRAL] Forum - SCforum.info
« on: 07. September 2010., 16:06:32 »



 Logged
Pages: 1
  Print  
 
Jump to:  

Enter your email address to receive daily email with 'SCforum.info - Security CENTRAL Forum' newest content:

Terms of Use | Privacy Policy | Advertising
Powered by MySQL Powered by PHP Powered by SMF | SMF © 2011, Simple Machines
TinyPortal © Bloc
Valid XHTML 1.0! Valid CSS!


Google visited last this page 20. May 2012., 14:49:15