Web Design - Publish.com
Publish.com Ziff-Davis Enterprise  
SEARCH · ONLINE MEDIA · MOBILE · WEB DESIGN · GRAPHICS TOOLS · PRINTING · PHOTO · TIPS · OPINIONS
Home arrow Web Design arrow DoS Flaw Flagged in IE7 Beta 2
DoS Flaw Flagged in IE7 Beta 2
By Ryan Naraine

Rate This Article:
Add This Article To:
Updated: A private researcher finds a denial-of-service bug just minutes after installing and testing the new browser for potential security holes.

An independent security researcher has pinpointed a denial-of-service flaw in Microsoft's brand new Internet Explorer 7 Beta 2 Preview just moments after installing the security-centric browser makeover.

Tom Ferris said could hardly believe his eyes when the new browser crashed less than 15 minutes after he started using a homemade fuzz testing tool to poke around for potential security issues.

Ferris, known online as "badpack3t," found that specially crafted HTML could cause IE7 to crash because "urlmon.dll" does not properly parse the "file://" protocol.

"I've confirmed a denial-of-service at this point, but I'm sure someone malicious could research this some more to control memory at some point to cause code execution," Ferris said in an interview with eWEEK.

A proof-of-concept demonstration has been published on the Security-Protocols site, along with a screenshot with proof of the browser crash.

Click here to read about how Microsoft is courting security researchers.

On the Internet Explorer blog, Microsoft program manager Tony Chor confirmed the bug causes a browser crash but said initial investigations did not find that it was exploitable by default to elevate privilege and run arbitrary code.

"This bug had already been found during our code review and analysis that is a mandatory part of our development process. It was scheduled to be fixed before our next public release. We do not believe this bug is easily exploitable," Chor said.

The Redmond, Wash. software maker typically downplays a denial-of-service browser bug that fixes itself when the browser is restarted, but Ferris said it's dangerous to assume the risk cannot be escalated with additional research.

"We've seen in the past where [malicious hackers] took a denial-of-service issue and created a zero day," he said, citing a case in November 2005 when a U.K.-based group called "Computer Terrorism released a nasty exploit for a bug that was reported simply as a browser crash issue.

Even though the IE7 browser is still in beta, which allows time to fix bugs before the final release, Ferris said something as serious as a potential code execution hole should have been found by Microsoft's software engineers.

"This is Beta 2. The next step is full release," he added. A final release of Internet Explorer 7 for Windows XP is expected sometime during the second half of 2006.

Zero-day exploit targets IE. Click here to read more.

The latest iteration of the beta is meant specifically as a final preview for third-party developers building Web sites or applications that run on Windows XP, and that a second beta version of IE 7 for Windows Vista, the firm's next-generation operating system, will also arrive sometime during the first half of this year.

Vista is scheduled to debut sometime before the end of 2006.

Among the features touted by Microsoft in the preview are the added security and privacy controls it has long promised in the software, along with a tabbed browsing interface and expanded tools for application developers.

Editor's Note: This story was updated to include information and comments from Microsoft.

Check out eWEEK.com's for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzer's Weblog.


Discuss DoS Flaw Flagged in IE7 Beta 2
 
I think that to receive the <a href="http://goodfinance-blog.com">loan</a> from...
Do you recognize that it is correct time to get the personal loans, which can make...
It's known that money makes us independent. But what to do when someone doesn't have...
>>> Post your comment now!
 

 
 
>>> More Web Design Articles          >>> More By Ryan Naraine
 


Buyer's Guide
Explore hundreds of products in our Publish.com Buyer's Guide.
Web design
Content management
Graphics Software
Streaming Media
Video
Digital photography
Stock photography
Web development
View all >

ADVERTISEMENT


FREE ZIFF DAVIS ENTERPRISE ESEMINARS AT ESEMINARSLIVE.COM
  • Dec 10, 4 p.m. ET
    Eliminate the Drawbacks of Traditional Backup/Replication for Linux
    with Michael Krieger. Sponsored by InMage
  • Dec 11, 1 p.m. ET
    Data Modeling and Metadata Management with PowerDesigner
    with Joel Shore. Sponsored by Sybase
  • Dec 12, 12 p.m. ET
    Closing the IT Business Gap: Monitoring the End-User Experience
    with Michael Krieger. Sponsored by Compuware
  • Dec 12, 2 p.m. ET
    Enabling IT Consolidation
    with Michael Krieger. Sponsored by Riverbed & VMWare
  • VTS
    Join us on Dec. 19 for Discovering Value in Stored Data & Reducing Business Risk. Join this interactive day-long event to learn how your enterprise can cost-effectively manage stored data while keeping it secure, compliant and accessible. Disorganized storage can prevent your enterprise from extracting the maximum value from information assets. Learn how to organize enterprise data so vital information assets can help your business thrive. Explore policies, strategies and tactics from creation through deletion. Attend live or on-demand with complimentary registration!
    FEATURED CONTENT
    IT LINK DISCUSSION - MIGRATION
    A Windows Vista® migration introduces new and unique challenges to any IT organization. It's important to understand early on whether your systems, hardware, applications and end users are ready for the transition.
    Join the discussion today!



    .NAME Charging For Whois
    Whois has always been a free service, but the .NAME registry is trying to change that.
    Read More >>

    Sponsored by Ziff Davis Enterprise Group

    NEW FROM ZIFF DAVIS ENTERPRISE


    Delivering the latest technology news & reviews straight to your handheld device

    Now you can get the latest technology news & reviews from the trusted editors of eWEEK.com on your handheld device
    mobile.eWEEK.com

     


    RSS 2.0 Feed


    internet
    rss graphic Publish.com
    rss graphic Google Watch

    Video Interviews


    streaming video
    Designing Apps for Usability
    DevSource interviews usability pundit Dr. Jakob Nielsen on everything from the proper attitude for programmers to the importance of prototyping in design to the reasons why PDF, Flash and local search engines can hurt more than they help.
    ADVERTISEMENT