Original URL: http://www.theregister.co.uk/2002/03/05/poison_applet_blights_browsers/
Poison applet blights browsers
Hijack risk to IE and Netscape
Posted in Security, 5th March 2002 16:06 GMT
Free whitepaper – Optimizing the data center for cost and efficiency
Crackers can use a malicious Java applet to hijack Internet sessions - leaving victims not so blissfully unaware.
Exploiters can re-direct Web traffic once it has left the proxy server to a destination of the attacker's choice, Microsoft warns (http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS02-013.asp).
Because of the vulnerability, a variety of man-in-the middle attacks are possible; attackers could also use the bug to filch session information, such as user names or passwords sent without using SSL encryption. Sensitive information sent using SSL will be protected from potential attackers exploited the vulnerability in unpatched systems, Microsoft advises.
A system is vulnerable only if IE is used in conjunction with a proxy server; this limits the risk to home users but isn't much help to businesses, where the proxy server architecture is very common.
The software giant has issued a patch which it describes as "critical" for client systems. Netscape advises users to upgrade to either version 6.2 and 6.2.1 of its browser (which includes an updated Sun JVM plug-in) that guards against this potential risk. ®
External link
Security advisory by Harmen van der Wal, who discovered the bug (http://www.xs4all.nl/~harmwal/issue/wal-01.txt)
MS advisory: Java Applet Can Redirect Browser Traffic (http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS02-013.asp)
Sun JVM (Java Virtual Machine) Issue (http://home.netscape.com/security/)
Related stories
IE, Outlook run malicious commands without scripting (http://www.theregister.co.uk/content/55/24274.html)
Three new MS security holes - two nasty (http://www.theregister.co.uk/content/55/24168.html)
MS releases mother of all IE security patches (http://www.theregister.co.uk/content/archive/23410.html)
Who needs hackers when we've got MS? (http://www.theregister.co.uk/content/archive/23496.html)
