IT, INTERNET NEWS, E-COMMERCE GUIDE back 
 

Microsoft on Sunday confirmed it's investigating an unpatched bug in VBScript that hackers could exploit to plant malware on Windows XP machines running Internet Explorer (IE).


The flaw could be used by attackers to inject malicious code onto victims' PCs, said Maurycy Prodeus, the Polish security analyst with iSEC Security Research who revealed the vulnerability and posted attack code on Friday.


Users running IE7 or the newer IE8 are at risk, said Prodeus.


Microsoft noted it's already on the case. "Microsoft is investigating new public claims of a vulnerability involving the use of VBScript and Windows Help files within Internet Explorer," said Jerry Bryant, a senior manager with the Microsoft Security Response Center (MSRC), in an e-mail Sunday. *The current state of our investigations shows that Windows Vista, Windows 7 ,
Windows Server 2008, and Windows Server 2008 R2, are not affected."


Bryant added that Microsoft has not yet seen any evidence of attacks exploiting the vulnerability.


Prodeus called the bug a "logic flaw," and said attackers could exploit it by feeding users malicious code disguised as a Windows help file -- such files have a ".hlp" extension -- then convincing them to press the F1 key when a pop-up appeared. He rated the vulnerability as "medium" because of the required user interaction.


"First an attacker needs to force a victim to visit a malicious Web page," Prodeus said in an e-mail Sunday. "The victim must be using Windows XP [and] Internet Explorer. A bit of social engineering is required to persuade the victim to push F1 button when [a] VBScript pop-up is displayed."


Another security researcher, Cesar Cerrudo, confirmed that Prodeus' proof-of-concept exploit works. "I tried the exploit and I can confirm it reliably works on IE8 with Windows XP fully patched," said Cerrudo, the head of Argeniss Information Security, an Argentinean security consultancy.


Cerrudo thought that the flaw was more serious than did Prodeus. "I would say the vulnerability is 'high severity,' not 'medium,'" said Cerrudo in an e-mail. "It's not critical since it needs user interaction, the user pressing F1 key when a message dialog is displayed. [But] I would say that there is a high probability a regular user will press F1 key if asked, since an attacker can annoy the user with hundred of messages telling the user to press F1 to continue."


According to Cerrudo, Prodeus' attack is successful because it abuses the VBScript "MsgBox()" function.


"Windows Help files are included in a long list of what we refer to as 'unsafe file types'," acknowledged Microsoft's Bryant in a follow-up on the MSRC blog later on Sunday. "These are file types that are designed to invoke automatic actions during normal use of the files. While they can be very valuable productivity tools, they can also be used by attackers to try and compromise a system."


Bryant didn't provide a timeline for a fix, but used Microsoft boilerplate in his e-mail to say that the company might address the vulnerability with a regularly-scheduled fix, a so-called "out-of-band" update or other guidance.


Microsoft's next scheduled security release date is March 9.


Although Microsoft has not yet recommended any defensive steps Windows XP users can take until a patch is available, Prodeus said blocking the outbound TCP port 445 would stymie attacks. "However, it is worth to note that blocking this port doesn't solve the problem, because there might be [an]other attacking vector, for example, uploading an arbitrary file to the victim's machine at known path location using some third-party browser plug-ins," he said.


Another workaround, said Cerrudo in a Friday tweet , is to ditch IE for another browser.

 

Source: ITNews

IT, Internet News and E-commerce guide

TYPICAL CUSTOMERS

CUSTOMER SUPPORT

 
Payment methods
Domain FAQs
Web design FAQs
Web hosting FAQs
E-commerce FAQs
Domain configuration
Microsoft Outlook Mail
Outlook Express Mail
Web mail
Create new email account
Terms of use
Privacy
Request support

PARTNERS

 
VNNIC Onlinenic Icann Icann FPT Paypal NganLuong

Online support

Sales

Technical

sales @ TTO .vn

Free web design consultant

IF YOU

need website, web-based application but don't know where to start?
are worry about how to make your website or web application meet all requirements!
can not find any web packages suitable!
Please do not hesitate to phone us or contact us via email
to get free advices

E-commerce guide

What is Ecommerce?
Myths And Realities
Boost E-commerce Site Appeal with Web Widgets
10 Questions to Ask an Ecommerce Hosting Provider
7 Steps to E-Business Launch
Top Tips for Online Store Success
How to Twitter for E-commerce Success
10 safe online shopping tips
5 Crucial Email Marketing Tips
Update Your Website to Help Increase Online Sales
Top ten e-commerce myths

Search      Tin Thanh Online (WebDesignVN.com)    Internet   

Home page  |   Introduction  |   Web template  |   Quotation  |   Contact us  |   Web programming forum

Tin Thanh Online Techonology Company Limited (Tin Thanh Online - TTO)

Address: 32 Street No.11, Binh Hung Residential Area, Binh Chanh District Ho Chi Minh City

Website: www.WebDesignVN.com - www.TinThanhOnline.com - www.LapTrinhWeb.com - www.TTO.vn

Telephone:  +84 (08) 6266 4088    Fax: +84 (08) 6266 4279 :: Email: sales @ webdesignvn.com - info @ webdesignvn.com

Valid XHTML 1.0

Valid CSS!

Internet Expolorer FireFox Netscape

Screen resolution
1024 x 768