rami's profileChess MasterPhotosBlogListsMore Tools Help

Blog


    October 24

    Microsof news

     

    IE 7 Fails Its First Security Test

    Internet Explorer 7 for Windows XP is Now Available
    Microsoft has released for download the newest upgrade for its Web browser, Internet Explorer 7, which is also the browser built into Windows Vista.

    but it seems that Microsoft's brand-new Internet Explorer 7 browser, which was just released Oct. 18 for Windows XP, has already failed a security test.

    Microsoft's spanking-new Internet Explorer 7 browser has failed already failed a security test.

    According to an advisory from Secunia, the gold version of IE 7 was shipped with an information disclosure flaw that could be used in spoofing attacks. The vulnerability is due to an error in the handling of redirections for URLs with the "mhtml:" URI handler.

    "This can be exploited to access documents served from another web site," Secunia warned.

    Here is a test page that demonstrates the bug on a fully patched version of Windows XP SP2, running Internet Explorer 7.

    Curiously, Secunia first raised an alert for this vulnerability in April 2006. It was never fixed in IE 6 and ignored again in IE 7.

    In fairness to Microsoft, it is nearly impossible to exploit this flaw to launch a spoofing or phishing attack. An attacker would first have to lure an IE user to a fake Web site and know for sure which other secure site might be open in an IE tab in the same browser session.

    Still, it's strange that Redmond allowed this to slip through the cracks in what is largely a security-centric browser makeover.

    UPDATE: Microsoft offers a somewhat dismissive response that this is not an IE vulnerability:

    "These reports are technically inaccurate: the issue concerned in these reports is not in Internet Explorer 7 (or any other version) at all. Rather, it is in a different Windows component, specifically a component in Outlook Express. While these reports use Internet Explorer as a vector the vulnerability itself is in Outlook Express.

    While we are aware that the issue has been publicly disclosed, we’re not aware of it being used in any attacks against customers.

    We do have this under investigation and are monitoring the situation closely and we’ll take appropriate action to protect our customers once we’ve completed the investigation.

    -------------------------------------------------------------------------------------------------------------------------------

    Windows Vista on Track for Global Release

    Microsoft has settled its differences with the European Commission and South Korea, meaning that Windows Vista is on track for worldwide release to volume license business customers in November and for consumers worldwide in January 2007.

    Comments

    Please wait...
    Sorry, the comment you entered is too long. Please shorten it.
    You didn't enter anything. Please try again.
    Sorry, we can't add your comment right now. Please try again later.
    To add a comment, you need permission from your parent. Ask for permission
    Your parent has turned off comments.
    Sorry, we can't delete your comment right now. Please try again later.
    You've exceeded the maximum number of comments that can be left in one day. Please try again in 24 hours.
    Your account has had the ability to leave comments disabled because our systems indicate that you may be spamming other users. If you believe that your account has been disabled in error please contact Windows Live support.
    Complete the security check below to finish leaving your comment.
    The characters you type in the security check must match the characters in the picture or audio.

    To add a comment, sign in with your Windows Live ID (if you use Hotmail, Messenger, or Xbox LIVE, you have a Windows Live ID). Sign in


    Don't have a Windows Live ID? Sign up

    Trackbacks

    The trackback URL for this entry is:
    http://chessmaster1978.spaces.live.com/blog/cns!51520D303982C633!310.trak
    Weblogs that reference this entry
    • None