Internet Explorer Still Vulnerable

By David Worthington | Published July 7, 2004, 4:58 PM

A self-appointed security sleuth has uncovered a new vulnerability in Microsoft's Internet Explorer web browser that bears a close resemblance to the Download.Ject exploit. Although Microsoft patched Download.Ject last week, Dutch security expert Jelmer Kuperus found that Microsoft's efforts to fix the problem did not go far enough.

By making slight modifications to the Download.Ject source code Jelmer has successfully bypassed the browser's latest security update. Jelmer's technique draws on a hole in the Shell.Application ActiveX object - similar to ADODB.Stream - to gain unrestricted access to Windows machines.

Jelmer has posted sample code to the Web.

A Microsoft Spokesperson acknowledged that the software giant was aware of the problem and working diligently to correct it; however, the spokesperson claimed that Microsoft did not know of any instances where customers were impacted by the exploit.

In the meantime, before Microsoft delivers a series of updates to Internet Explorer in the coming weeks, customers can read up on Microsoft's safe browsing tips and practice safe computing to protect their PCs.

"This is disturbing but not surprising," said Yankee Group Senior Analyst Laura DiDio. "In the 21st century computing security updates are the most fleeting of all. Hackers are getting better at their craft and collaborating more."

DiDio continued, "When it comes to Microsoft there are clearly unassailable facts: Microsoft is the world's number one software maker and the first target of hackers. If anyone is subject to repeated attacks there will be a success rate. This will not change anytime soon."

Comments

View comments by with a score of at least

I LOVE knifed IE icon btw it is pretty hilarous.

Score: 0

|

I agree that FireFox is the way to go. In fact, I try to stay away from IE6 as much as possible now because it just plain suck. They use to update this browser frequently when battling Netscape and once the battle was won they turned it off! What about IE 7.0? Tabbed-browsing? stable Pop-up blocker? That's what users want now.

Score: 0

|

Geeze,
What's it going to take? Everytime you turn around there's anoter bug in IE that allows a person to "Gain access to your system" or "Makes your system Vernable to attack".. Using a Mozilla Based browser (Mozilla, Firefox, etc) is the cure, hopefully soon the Mozilla orginization gets started on the Windows explorer shell replacement soon.

When Will MS learn their stuff is crap ?

Score: 0

|

Look at MSN. It has be updated 3-4 times in the last 2 years (the same amount of time since they last updated IE). It has the pop-up blocker, spam filter (OE can use it) and other things. I think Mircosoft is just trying to be the first co. to make it to the $1,000,000,000,000 mark (like they need it).
They were going to send IE 7 out with XP SP2, but I haven't seen it.

Score: 0

|

Guys its not like firefox is immune to secutiry holes, 0.9.2 was released becuase a shell exploit security hole was discovered. (this vulnerablity is similar to Download.Ject)

Score: 0

|

I don't think anyone is arguing with you on that. What we are saying is that Mozilla development is much more responsive than Microsoft's IE development. Mozilla appears to be constantly doing something: adding useful features, reducing uneeded bloat, fixing security issues in a *timely* manner, and in general optimizing their code.

Score: 0

|

Yeah it was released because Windows shell protocol is a security risk. And all that Mozilla is doing now is that they block this from runing with their products. For exmaple Firefox 0.9.1 on other OSes like Linux and Mac OS are still safe. So it is nothing wrong with Mozilla, only that it left to run some insecure Windows component to run with it.

Score: 0

|

Microsoft need to work more harder to make IE more better. after abandoned for 2 years.

Microsoft also need to update the IE download which still use the 2002 versions.
otherwise it will affecting the windows and other product images.

Score: 0

|

Who cares if IE is vulnerable when the alternatives are better faster and MORE SECURE

Score: 0

|

Because users do not always have a choice in deciding what browser to use. Sites sometimes require IE. Good example of a high profile heavily visited website? MSNBC. To access the entire site you need to be running IE on Windows. Seems ridiculous since up until recently this restriction didn't exist. IE on a Mac doesn't even qualify.

Score: 0

|

Does it surprise you that only IE will work on MSNBC? They surely don't want FIREFOX loading the MSNBC website faster than IE. Got to give Microsoft credit tho they keep trying whenever they can. Gatesism at it's best. Peace out.

Score: 0

|

i don't get it, what part of MSNBC doesn't work in firefox? i just test 0.9.1 and it worked fine. i also fired up safari on my mac and it ran fine, too.

Score: 0

|

I second that. I have Firefox 0.9.1 and I had no problems on MSNBC.

Score: 0

|

MSNBC works fine in Firefox, I'm on it right now, checkin' out the latest headlines...

I've been using Fox for awhile now, and have yet to find a website that I couldn't browse. There are a couple of features that don't work here and there, but I can live with that knowing I'm not using a slice of swiss cheese for a web browser.

Score: 0

|

You cannot access any of the video content. This wasn't the case before the redesign. Other MSNBC features that were accessible before such as the popular This Week in Pictures became only compatible with IE on Windows for like a month, but they finally caved on that.

Note that this was a fairly recent change to their website (December 2003 I believe). Sorry, I did mention being unable to access the "entire site," but in hindsight I probably should have emphasized it.

Edit: So what I find odd is that in a time where most sites out there are trying to become more compatible with various browsers and operating systems, you have a site like MSNBC that purposely added additional restrictions on content access. So, like I said, sometimes a user doesn't have a choice on what browser they can use. For me, I sometimes have to walk from my Mac to my PC / or walk from my Mac and turn on my PC / or reboot from Linux into Windows just so I can watch a specific NBC News video.

Score: 0

|

Sorry, I go more indepth above in my response to Akirhol.

Score: 0

|

Just to claify, only parts of MSNBC is not accessible to browsers other than Windows IE.

Score: 0

|

Sorry for my ambigious comment. Please see my response to Akirhol above.

Score: 0

|

Just another example of badly coded site. And even on purpose. No wonder Microsoft gets sued for unfair competition all the time.

Score: 0

|

While you are right in saying that some pages on msn bc don't always work properly in other browsers I think that for many people that is a non issue. I think many people generally have other news sites that they enjoy going to. When push comes to shove I think many people will prefer the inconvenience of finding another news page than having to deal with the problems that are brought on by internet explorer. I don't really think that there is enough exclusive content there keep most people from abandoning internet explorer if they dislike the browser.

Score: 0

|

Quoted from their FAQ: MSNBC supports the most popular browsers and operating systems as measured by viewer usage.

In other words, MSNBC only fully supports IE on Windows. You're right, of course. But I can't help ponder if their stats are partially skewed towards one browser and OS simply because they do not fully support anything else.

Score: 0

|

Do you people actually read what you type, or you just spouting bad informtion again? Did you try MSNBC with Firefox or Mozilla, or even Netscape. I have all 3. It works fine. WTF are you talking about? You should really stick being a user, and trying to get attention for yourself, because you don't know what you are talking about. And another thing, all you microsoft haters out there, if you don't like it so much, and all you can do is piss on it, and bad mouth it, QUIT USING IT! Its real simple. You don't like it, great, you and your circle of 50 friends that use something else, should be very happy, the only reason Microsoft gets press, is because they are huge, and you are jealous. So quit being a ranting baby, use your *OTHER* browser, and shut the hell up.

Score: 0

|

All time time? Where did you read this, your local school newspaper? That's old, jackass. They were sued ONCE. And the justice department dismissed all charges. Yeah, way to keep up with current events there, mr. wizard.

Score: 0

|

So if I am to follow your lame logic, and quoting that site "most popular browsers" that tells me that People actually *prefer* internet explorer. Maybe if Mozilla can actually conform to A standard, they might get somewhere. And, like i mentioned before.. it works fine. Maybe you are just so blinded by the fact that you like Mozilla, and have a problem with Microsoft, you are overlooking the obvious. The fucntionality for MSNBC works fine for Netscape AND Mozilla.. been working for years. What you blind? Show me a specific example of what DOESN"T work. I am switching between both right now.. I don't even see a difference, perhaps you need to just calm down, and actually give useful information, instead of propagating more Microsoft lies, there buddy.

Score: 0

|

Yeah, your post.. ignorance at IT's best.

Score: 0

|

Do any of you guys realize that IE 6 is WAY better with WindowsXP SP2.

Ever since I installed the SP2 I have yet to get a adware, spyware or Popups.

SP2 IE has a GREAT Built-in popup blocker...(IMHO better than any ADDON) updated Firewall that's really useful.

I believe with its finally released it will be real secure.

Score: 0

|

Still good to get Quik-Fix.
http://www.pivx.com

Score: 0

|

lol not bad

I think Mozilla is still good though :P

Score: 0

|

Yea, SP2 is still too buggy in my opinion. Firefox works just fine, thank you.

Score: 0

|

I am not a Microsoft hater, so please don't label me as such. If Microsoft produced the best web browser available, then I would use it in a second. In fact, I DID use IE for quite a while until Mozilla began to mature and overtook IE.

Regarding your other comment, read my comment below for more information on exactly what part of MSNBC does not work on Firefox. Thanks.

Score: 0

|

Try to watch a NBC News video in Firefox. You can't. I already stated this above of course, but I'll assume you skimmed over it and repeat it for your sake.

My conclusion still stands. Sometimes people do not have a choice to not use IE.

Score: 0

|

PDC 2009: What have we learned this week?

There was the freebie that no one will forget, the heebie-jeebies courtesy of Scott Guthrie, and a teensy bit clearer picture of how this cloud thingie should work.

Live report: Will Google Chrome OS change Linux?

The mysteries of just what Chrome OS is, and how much of an operating system it truly is, may be resolved today.

PDC 2009: Microsoft cares about Web browser performance

The effort to give users of the world's dominant Web browser the impression of quality, is a personal one for the man who leads that battle.

Nokia re-affirms its commitment to Symbian, sort of

Maemo won't necessarily be replacing Symbian in the Nokia N-Series, but that's definitely a place where it will be found.

E-book readers will be in short supply this holiday season

E-readers are hot this year, and a lot of compelling new products have been released, but are there enough electrophoretic displays to go around?

Sony looks to finally open a single storefront for downloads

Sony has had many different download portals for movies, music, e-books, and games, and now it's looking to make a single shop for all of it.

Tuning out the tablet: Time to give the endless speculation a rest

Wide Angle Zoom: Wishing and hoping and thinking and praying....won't put an iTablet on the market.

Five improvements for IT managers in 2010

If businesses are to improve their efficiency for next year, they need to stop and reassess the basic tenets of their job.

AOL's spinoff from Time Warner to shed 2,500 jobs

As AOL moves toward become an independent company again, it will cut nearly a third of its workforce.

Gartner: SMS-based money transfer will be bigger than mobile browsing, search

Gartner issues its predictions for the 10 things our phones will be doing in 2012.

Don't forget to upgrade to Firefox 3.6 beta 3 today

Mozilla has released the latest beta its Firefox 3.6 browser software, just over one week after beta 2.