bk99.de entertain the web since 1997

Internet Explorer has a security hole in JavaScript

Summary

In January 2002 the Bulgarian security researcher Georgi Guninski published a hole in Internet Explorer through which JavaScript could read local files and start programs. The cause was an incorrect interpretation of the GetObject() function; the patched IE 6.0 and IE 5.5 SP2 under Windows 2000 were affected. According to Guninski, Microsoft had been informed three weeks earlier and had not responded.

Ideas

  • A script function in the browser could access the local file system.
  • When the vendor did not respond, the discoverer published the details.
  • Even fully patched browsers were affected.

Insights

  • Publication after a deadline has passed puts pressure on tardy vendors.
  • In early browsers the boundary between web content and the local system was permeable.

Facts

  • The hole was discovered in the second week of December 2001.
  • Guninski recommended permanently disabling Active Scripting in Internet Explorer.

References

Critique

  • The report reproduces Guninski’s account without obtaining a statement from Microsoft.

Recommendations

  • Disable active content for untrusted sites when a browser has unpatched holes.
  • With known, open browser holes, temporarily use an alternative browser.

Read the original article

Search the Web Archive