Welcome to YLOAN.COM
yloan.com » Internet » A vulnerability in the way Internet Explorer parses MHTML content
Games Personal-Tech Data Entry registry cruise torrent mac code virus storage uninstaller systems cisco bugs wireless codes maintenance dell update communication trojan atlanta Data Backup Data Storage Data Protection Data Recovery Anti-Virus Windows Linux Software Hardware Mobil-Computing Certification-Tests Computers & Internet Internet

A vulnerability in the way Internet Explorer parses MHTML content

A vulnerability in the way Internet Explorer parses MHTML content


A vulnerability in the way Internet Explorer parses MHTML contenta method for combining multiple file types and HTML content into a single fileis now targeting users as part of a "drive-by" browser attack.

It's called that due to the process by which attackers exploit the loophole: They'll create a malicious website, lure a user in, and then force the user's browser to run Javascript code. This code can access information from a user's browser or, worse, entice a user to install additional code that opens up his or her system to additional hacks.

"The end result of this type of vulnerability is script encoded within the link executed in the context of the target document or target web site," writeDave Ross and Chengyun Chu in Microsoft's Security Research & Defense blog.


The MHTML exploit was originally published on a website called WooYun, and Microsoft acknowledged the issue ina January security advisory. A recent update to the advisory by Microsoftlater verified by Googleindicates that the exploit is now being put to use.

"We've noticed some highly targeted and apparently politically motivated attacks against our users," writes members of the Google Security Team ina blog post. "We believe activists may have been a specific target. We've also seen attacks against users of another popular social site."

Neither Google nor Microsoft went into any additional detail as to the exact kinds of users the exploit has targeted. Microsoft has itself released a "Fix It" solution to combat the issue, but there's been no timeline set for a full-fledged patch to the browser.

According to Qualys' Wolfgang Kandek, the attack only works against those running Internet Explorerand Microsoft has verified that statement by noting that the attack actually works due to a specific Windows vulnerability, making one's version of Internet Explorer irrelevant as part of a fix. However, a quick fix beyond the downloadable "Fix It" pack is to switch over to an alternate browser for the time beingChrome or Firefox to name a few.


"Firefox and Chrome are not affected in their default configuration, as they do not support MHTML without the installation of specific add-on modules,"Kandek writes.

Microsoft itself has previously posteda test scenario that users can run to determine whether their browsers support the MHTML vulnerability. All that one needs is access to a web server in order to upload a single .MHT test file. For unprotected browsers, accessing the file will result in a little pop-up box that says, "hello," whereas protected versions of Internet Explorer will instead receive a notification that the site is trying to "communicate with your computer" in a method disallowed by one's security settings.

Other Business News:Acer aspire 5520 Batteries,Acer as07b41 Batteries,Acer as07b31 Batteries

Read More:http://bestlaptopbattery.co.uk/battery-wiki/geminus-genius-case-for-ipad-reviews-by-bestlaptopbatterycouk
Pros and Cons of Outsourcing - Every Internet Marketer Should Read This Moonwalking with Einstein by Joshua Foer (free download) T1 Internet - It's Not Just About Speed Save with Premium Movie Pack on DISH Network Sneak Peek into DISH Network Packages Internet Marketing Advantages - Simple Truths Behind The Hype SEO UK - The Best In Internet Based Marketing Backlinks from blogs & Internet Marketing Agencies Reasons For Choosing Fiber Cable For Network Cabling Everybody Wants Your Money by David W. Latko (free download) Unique Online Internet Marketing Tips for Your Online Busines Internet Online Marketing strategy is following up with your prospects With Internet Marketing the Benefits You Can Span Are Numerous
print
www.yloan.com guest:  register | login | search IP(3.148.241.210) / Processed in 0.020404 second(s), 7 queries , Gzip enabled , discuz 5.5 through PHP 8.3.9 , debug code: 22 , 3109, 49,
A vulnerability in the way Internet Explorer parses MHTML content