Security Site Forum  

Go Back   Security Site Forum > Technology > Internet and Computer Security

Reply
 
Thread Tools Display Modes
Major IE8 Flaw Makes 'Safe' Sites Unsafe
Old
  (#1 (permalink))
SSF Active Member
 
Sardonicus's Avatar
 
Status: Offline
Posts: 3,142
Join Date: May 2002
Major IE8 Flaw Makes 'Safe' Sites Unsafe - 11-20-2009, 09:56 PM

Exclusive The latest version of Microsoft's Internet Explorer browser contains a bug that can enable serious security attacks against websites that are otherwise safe.

The flaw in IE 8 can be exploited to introduce XSS, or cross-site scripting, errors on webpages that are otherwise safe, according to two Register sources, who discussed the bug on the condition they not be identified. Microsoft was notified of the vulnerability a few months ago, they said.

Ironically, the flaw resides in a protection added by Microsoft developers to IE 8 that's designed to prevent XSS attacks against sites. The feature works by rewriting vulnerable pages using a technique known as output encoding so that harmful characters and values are replaced with safer ones. A Google spokesman confirmed there is a "significant flaw" in the IE 8 feature but declined to provide specifics.
It's not clear how the protections can cause XSS vulnerabilities in websites that are otherwise safe. Michael Coates - a senior application security engineer at Aspect Security who has closely studied the feature but was unaware of the vulnerability - speculates it may be possible to cause IE 8 to rewrite pages in such a way that the new values trigger an attack on a clean site.

"If the attacker can figure out a flaw in the way IE 8 is actually doing that output encoding and then create a specific string the attacker will know will be transformed into an actual attack, they could use that to input a value ... that actually results in an attack firing on the page," he said. "This could be a way to introduce an attack into a page that didn't have a vulnerability otherwise."

XSS attacks are a way of manipulating a site's URL to inject malicious code or content into a trusted webpage. Many security watchers have come to view the IE 8 protections as Microsoft's answer to NoScript, a popular extension that helps prevent XSS and other types of attacks against users of the Firefox browser.

Late on Thursday afternoon, Microsoft told The Register: "Microsoft is investigating new public claims of a vulnerability in Internet Explorer. We're currently unaware of any attacks trying to use the claimed vulnerability or of customer impact."

Once its investigation is finished, the company will "take appropriate action," including issuing a patch or guidance on how users can protect themselves against exploits.

When Microsoft introduced the protections, it also created a way for webmasters to override the feature (by adding the response header "X-XSS-Protection: 0"). A review of the top 50 most visited websites shows that only web properties owned by Google have actually opted to do so. The small number of sites blocking the protection calls into question how widespread the vulnerability is.

Asked why Google was forgoing the protection, a company spokesman wrote in an email:

"We're aware of a significant flaw affecting the XSS Filter in IE8, and we've taken steps to help protect our users by disabling the mechanism on our properties until a fix has been released." He didn't elaborate.

In addition to potentially introducing serious vulnerabilities into webpages, the XSS protections can bring other undesirable results. That's because its engine frequently flags perfectly acceptable characters as potentially harmful. An examples of such a false positive is here.

David Ross, a senior software security engineer for Microsoft, has saiddevelopers designing the feature aimed to strike strike a pragmatic balance between protecting users and not breaking the web.

"We needed to find a way to make the filtering automatic and painless and thus provide maximum benefit to users," he wrote. "In summary, the XSS Filter will prove its worth by raising the bar and mitigating the types of XSS most commonly found across the web today, by default;, for users of Internet Explorer 8." ®



[Only registered and activated users can see links. ]
   
Reply With Quote
 
Old
  (#2 (permalink))
SSF Invited Gold Monitor
 
veteran's Avatar
 
Status: Offline
Posts: 1,586
Join Date: Apr 2008
Location: Southeast/Southwest Asia
11-20-2009, 10:01 PM

Nice ad, but run stealth and run long.
[Only registered and activated users can see links. ]









"Death Before Dishonor"
"Lock & Load"
   
Reply With Quote
Old
  (#3 (permalink))
SSF Active Member
 
holaschaus's Avatar
 
Status: Offline
Posts: 205
Join Date: Apr 2008
Location: On a spiral in the sky
11-22-2009, 05:33 AM

Luckily for me i use Opera, so i don't have to worry about all these security problems...


There's nothing here, move on!
   
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
What torrents sites left are safe deadman4lyfe Discussions & Debates 67 04-10-2008 04:32 AM
Personal storage sites are a 'safe haven for hackers' Barney Gumble Internet and Computer Security 0 08-03-2005 06:46 PM
WHAT IS THE SAFE LEVEL OF DRINKING -- some tips on safe drinking chongwah Chatter Box 10 10-18-2003 08:27 AM
It just makes me mad REALLY MAD ! Tweety Opinion 46 04-09-2003 06:10 PM



Powered by vBulletin® Version 3.6.8 PL2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.

...... XXX adult password pass board forum
Stand With Haiti

Page generated in 0.08021307 seconds (68.27% PHP - 31.73% MySQL) with 16 queries