Register

To become a member of ITProPortal Register here.

Already a member? Login here

Please register below. All we need is a valid email address and a password.

Please use a real email address as we need to email you to confirm your account.
Must be at least 6 characters long.

Benefits of joining ITProPortal:

  • Unlimited Access to Special Reports and White Papers
  • Exclusive offers and discounts
  • Free entry to all competitions
  • Access to beta sections of ITProPortal.com

Login to your account

Forgot your password?


Submit Register Cancel

Israeli security researcher develops IE superhack

Author: Steve Gold| Date: 14 May 2008| Tags:  Hacking, Security
Israeli security researcher develops IE superhack
  • IconText size Icon Icon

I was intrigued to read over on the IDG newswire that Israeli security research Aviv Raff claims to have developed a zero-day attack methodology against Internet Explorer.

Except that, although he plans to reveal his methodology later today (and he has -Ed) his example attack - which reportedly works well - is currently hidden from Netters.

"Somewhere in my blog, I embedded a proof-of-concept code which exploits this zero-day vulnerability," Raff wrote in his blog last week.

The security flaw, which reportedly affects IE 7.x and 8.x, is claimed to allow a hacker to install any piece of code on the user's PC.

Raff claims to have informed Microsoft of his findings last week, but - guess what - the software giant we all love to hate has not patched it yet.

From what I can gather, for Raff's attack to work, the hacker must first install a small HTML code applet on a Web site and then persuade the victim to use a specific Internet Explorer feature on that page.

Clever stuff. Read more here...

 

advertisement

Web Threat Level
brought to you by Trend Micro.