
Patched then unpatched
Published: 1 July 2004 09:05 BST
A security flaw that had been fixed in older versions of Microsoft Internet Explorer has reappeared in the latest version of the browser software.
Security company Secunia issued a bulletin warning of the flaw in versions 5.01, 5.5 and 6.0 of Internet Explorer (IE). The problem had been fixed six years ago, when it appeared in versions 3.0 and 4.0 of the IE browser.
Thomas Kristensen, chief technology officer of Secunia, said: "It's a concern that a company like Microsoft has a problem that's already been fixed in older versions resurface in newer ones,."
Microsoft has been plagued by a recent spate of IE vulnerabilities. The latest attack was reported Tuesday. Through a flaw in IE, victims can pick up a program through a pop-up ad that is used to read keystrokes and steal passwords when people visit any of nearly 50 banking sites.
Vulnerabilities in IE have become so common that some security researchers are recommending that people adopt alternate browsers. The US Computer Emergency Response Team, the official US body responsible for defending against online threats, also advised security administrators to consider moving to a non-Microsoft browser among six possible responses.
According to the latest bulletin, the vulnerability affects people who have multiple IE browsers open. Through one of the open browsers, hackers can change the content of another website without users ever knowing that it has been altered.
Using this attack method, hackers could insert links into legitimate web pages and direct people to malicious sites where they could solicit personal information such as bank account or credit card information. Because the link comes from a legitimate and trusted site, victims may not realise they have been redirected to a harmful site. Hackers could also insert links that would trick users into downloading malicious software.
"It's a major problem when people can't trust what they are seeing in their browser," Kristensen said.
Another flaw discovered last week turns some websites into points of digital infection. The vulnerability was nipped in the bud on Friday, when internet engineers shut down a server in Russia that had been the source of the malicious code.
Another flaw, discovered earlier this month, installed a toolbar on victims' computers that triggered pop-ups.
CNET News.com's Robert Lemos contributed to this report.
Marguerite Reardon writes for CNET News.com
Act as the charitys Data Protection Officer. Provide appropriate links with our Head Office (London) on IT matters 8. Job Purpose: 1. Ensure the IT ...
Huxley Associates are looking for a Communications Officer to join a leading investment bank client. You will be joining the IT and Corporate Real ...
Senior QA (Quality Assurance) Officer, Biopharmaceutical Company, Staffordshire/Oxfordshire Senior QA (Quality Assurance) Officer: My client is a ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...