Feeds

Poison applet blights browsers

Hijack risk to IE and Netscape

  • alert
  • submit to reddit

Top 5 reasons to deploy VMware with Tegile

Crackers can use a malicious Java applet to hijack Internet sessions - leaving victims not so blissfully unaware.

Exploiters can re-direct Web traffic once it has left the proxy server to a destination of the attacker's choice, Microsoft warns.

Because of the vulnerability, a variety of man-in-the middle attacks are possible; attackers could also use the bug to filch session information, such as user names or passwords sent without using SSL encryption. Sensitive information sent using SSL will be protected from potential attackers exploited the vulnerability in unpatched systems, Microsoft advises.

A system is vulnerable only if IE is used in conjunction with a proxy server; this limits the risk to home users but isn't much help to businesses, where the proxy server architecture is very common.

The software giant has issued a patch which it describes as "critical" for client systems. Netscape advises users to upgrade to either version 6.2 and 6.2.1 of its browser (which includes an updated Sun JVM plug-in) that guards against this potential risk. ®

External link

Security advisory by Harmen van der Wal, who discovered the bug
MS advisory: Java Applet Can Redirect Browser Traffic
Sun JVM (Java Virtual Machine) Issue

Related stories

IE, Outlook run malicious commands without scripting
Three new MS security holes - two nasty
MS releases mother of all IE security patches
Who needs hackers when we've got MS?

Internet Security Threat Report 2014

Whitepapers

Designing and building an open ITOA architecture
Learn about a new IT data taxonomy defined by the four data sources of IT visibility: wire, machine, agent, and synthetic data sets.
5 critical considerations for enterprise cloud backup
Key considerations when evaluating cloud backup solutions to ensure adequate protection security and availability of enterprise data.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Business security measures using SSL
Examines the major types of threats to information security that businesses face today and the techniques for mitigating those threats.