All the latest UK technology news, reviews and analysis

Microsoft slammed over IE flaws

by Andy McCue

08 Nov 2002

Be the first to comment

  • Tweet this

Microsoft is still investigating flaws found last month in Internet Explorer that could allow malicious hackers to access users' passwords for e-commerce and online banking sites.

Israeli security consultancy GreyMagic has criticised Microsoft for its slow response to the nine vulnerabilities in Internet Explorer versions 5.5 and 6.0, eight of which were rated 'critical'.

Customers with the affected version of Microsoft's browser could be fooled into thinking that a forged web page is from a trusted e-commerce site, and an attacker could steal private local documents and cookies.

"Stealing cookies and forging website content could help the attacker get hold of the victim's password in an email service, bank or other sensitive domain, regardless of Secure Sockets Layer [encryption]," said Lee Dagon, head of research and development at GreyMagic.

Microsoft has hit back at the company for disclosing the flaws before they were validated, and claimed that it is still investigating the vulnerabilities.

Simon Conant, of the product support services group at Microsoft, said: "First we have to find out if these claims really are true and that we don't already know about them or have already fixed them.

"Then we will begin the process of fixing them and getting the fix out."

He admitted that several customers had enquired about the vulnerabilities, but said that Microsoft had not issued any formal alert.

"I cannot begin to hazard a guess at the time scale for this, but it is far too early to give any more details because we have to validate it ourselves first," explained Conant.

But Dagon dismissed Microsoft's response. "Anyone can plainly see that the vulnerabilities exist by using the proof-of-concept demonstrations we supplied when we released the advisory," he said.

Customers with up-to-date Internet Explorer security patches are unlikely to be at risk, and GreyMagic has admitted that there is no proof of any exploitation of the flaws outside its test labs.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

27%

1%

11%

61%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Systems Analyst/Architect

Systems Analyst/Architect £30,000 - £40,000 + excellent...

Software Developer

Software Developer Up to £27,000 + excellent...

Software Engineer/Developer (C#, C++)

Software Engineer/Developer (C++) £25,000 - £40...

Web Developer

Web Developer £25,000 - £40,000 (DOE)+ excellent...

To send to more than one email address, simply separate each address with a comma.