Exploits for IE security hole circulate on the internet
Summary
In January 2010 exploits were circulating for the Internet Explorer hole through which attackers had previously attacked Google and other companies. According to The Register, both Metasploit and Immunity Canvas had the code, which allowed control of the computer through an invalid pointer access. In tests it worked in IE 6 and 7 under Windows XP SP3, while IE 8 initially only crashed.
Ideas
- An exploit used in targeted attacks spread into open tools within days.
- Older browser versions were the first to be vulnerable.
- A crash often indicates that an exploit will soon be adapted.
Insights
- Targeted attacks are usually followed by broad exploitation by others.
- Outdated browsers considerably extend the window of opportunity for attackers.
Facts
- The code first appeared on the sandbox service Wepawet.
- Immunity developer Kostya Kortchinsky confirmed how it worked.
References
Critique
- The report does not name the wave of attacks on Google and does not put it into context.
Remarks
- The attacks became known as “Operation Aurora”; Microsoft closed the hole shortly afterwards in an unscheduled update.
Recommendations
- Consistently replace outdated browsers, even in corporate environments with legacy applications.
- After targeted attacks become known, check your own exposure before broad exploits follow.
- Enable protective features such as DEP when there is no patch yet for a browser hole.
Links to the original source and the Web Archive open in a new tab.