The Register® — Biting the hand that feeds IT

Feeds

MS probes mystery IE bug

URL shortening shenanigans

Customer Success Testimonial: Recovery is Everything

Microsoft is investigating reports of a new bug in Internet Explorer.

Redmond's Security Response Team (MSRT) said on Friday that it was aware of a "publicly disclosed issue involving Internet Explorer", and promised an investigation, without going into details.

Circumstantial evidence suggests Microsoft is referring to a post by security researcher Chris Evans, of Google, to a Full Disclosure mailing list on Friday, hours before MSRT's tweet.

"A nasty vulnerability exists in the latest Internet Explorer 8," Evans wrote. "I have been unsuccessful in persuading the vendor to issue a fix."

"The bug permits — for example — an arbitrary web site to force the victim to make tweets," he added.

The vulnerability may exist in other versions of IE and appears to be an extension of a cross-browser cross domain theft first documented by Evans via his scarybeastsecurity blog last December. Evans claims Microsoft has been aware of the bug since 2008, producing a harmless proof-of-concept exploit to illustrate his concerns.

Rik Ferguson, a senior security consultant at Trend Micro, explained that the exploit works by stealing the (supposedly secret) credentials for an already authenticated browser session, for example Twitter. "Those credentials are then abused to send arbitrary forged content," Ferguson writes.

The vulnerability might just as easily be used by other services that use URL shortening, according to Ferguson, who says that Opera, Chrome, Firefox and Safari have all already fixed this vulnerability. ®

Bootnote

A huge row kicked off back in June when another Google researcher, Tavis Ormandy, posted details of a Windows XP Help Center bug. Ormandy had given Microsoft just five days to fix the bug before going public. The incident reignited the long-running debate about the disclosure of security vulnerabilities, with spirited defences of their positions from both the full and responsible co-ordinated disclosure camps.

In the latest case, Evans apparently gave Redmond far longer to get its gear together before going public, and he only acted after other browser developers had issued patches, factors that mean it would be very hard to argue that he "jumped the gun".

Agentless Backup is Not a Myth

""The bug permits — for example — an arbitrary web site to force the victim to make tweets"

Dear god they're making Twitter compulsory now.

2
0

RE: ya reepz wot yaz sow, moe!

News Report: Thousands starving in Africa

Anonymous Wanker: Dun fect me cuz i dun liv in Afreaka!!!!!! lolz lolz lolz looooool!!!!

1
0

Firefox, gimme a break

Pffft - Opera had this bug years ago - it's taken this long for MicR0$0ft to copy them, and now they are trying to claim they invented it - typical.

0
0

More from The Register

SCO vs. IBM battle resumes over ownership of Unix
Zombie lawsuit back and wants to suck the brains out of Linux
Bjarne Again: Hallelujah for C++
Plus: Now officially OK to admit you never used STL algorithms
Interwebs taunt Sir Jony over Apple eye candy makeover
Hey Ive, Ive... add more unicorns, willya?
Apple: iOS7 dayglo Barbie makeover is UNFINISHED - report
Plus: You don't like the icons? Blame marketing
Red Hat to ditch MySQL for MariaDB in RHEL 7
So long, Oracle! Don't let the door hit you on the way out
Shy? Socially inadequate? Fiddling with your phone could help
App 'tells the brutal truth' about social inadequates' chatup lines
Java EE 7 melds HTML5 with enterprise apps
New release arrives with GlassFish, NetBeans support
 breaking news
'Office Facebook' firm Tibbr wants you to PAY for mobe-meetings app
Great idea. Punters won't cough for it though
 breaking news
The only Waze is Google: Ad giant tipped to gobble map app 'for $1.3bn'
Pac-Man-satnav-ish upstart in bidding war with Apple, Facebook
 breaking news
PM Cameron calls for modern, programmable computers! (We think)
IT education musings to G8 chiefs to mystify IT industry