Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Internet Explorer

May 30th, 2011, 10:25 GMT · By

No Attacks against Internet Explorer Cookiejacking 0-Day Vulnerability, but Patch Coming

SHARE:

Adjust text size:


IE9
Enlarge picture
Microsoft will plug a zero-day security hole in Internet Explorer that can allow potential attackers to steal session cookies from users even though it has made it clear that it doesn’t consider the vulnerability as posing a high risk to customers, and without having detected active attacks in the wild.

The only attack created around a working exploit targeting the IE-zero day was demoed at the recent Hack in the Box security conference in Amsterdam by Italian security researcher Rosario Valotta.

Stealing session cookies, also referred to as cookiejacking, is similar in nature to another type of attack dubbed clickjacking, but with a different target.

As far as I’m concerned, the complexity of this type of attacks, in combination with the efforts attackers need to invest when it comes down to successfully tricking victims into handing over their data, means that the Redmond company’s assessment that the particular IE 0-day uncovered by Valotta is not a high risk to customers is not without merit.

At the same time, given the publicity that the new IE security vulnerability has achieved in the past week, it’s best for the hole to be plugged, especially since working attacks can be built.

And although, no attacks have so far been detected in the wild, Microsoft’s Brandon LeBlanc stressed that the Redmond company is already hard at work building a patch for the IE cookiejacking 0-day.

The lack of attacks, combined with the low risk assessment that the software giant has given this flaw means that it’s very unlikely that Microsoft will provide an out of band patch.

Most likely, the security update designed to patch the IE cookiejacking 0-day will be included among the next batch of IE updates, after the company will be done cooking it.

LeBlanc provided additional insight into why the company is not exactly rushing to patch this new IE 0-day:

“In order to be exposed to risk a number of things would need to happen. You’d need to be tricked into interacting with malicious content on a website. Only after this could a third party steal cookies from a website that you were previously logged into. While this threat has been demonstrated by a security researcher, to date we are not aware of any actual attacks online.”

Essentially, even in scenarios in which an attacker exploits the vulnerability successfully, no session cookies are stolen.

In addition to the working exploit, users also need to be tricked via social engineering to copy their session data and hand it over, with the attack only working if the username and Windows version ran by the victims are known to the attacker.

“This is a form of social engineering attack and these kinds of threats will remain a concern for Internet users on all browsers. Software vulnerabilities are not needed for these kinds of threats to be successful so it is always a good idea to follow best practices – regardless of the browser you are using - in order to stay safe,” LeBlanc added.

TELL US WHAT YOU THINK:

1,289 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Custom IE9 Packages in 93 Languages with Internet Explorer Administration Kit 9

IE9 vs. IE8 - More, Better and Faster

Download IE9 RTM Language Packs for Windows 7 SP1

IE9 Superior to Firefox 4, Chrome 11, Opera 11, Safari 5 - Language Support

IE9 on Windows Phone Mango

READER COMMENTS:


Comment #1 by: Anthony on 06 Jun 2011, 20:24 UTC reply to this comment

I think it's * that Microsoft is pretty much allowing this to happen. They should definitely come out with a patch BEFORE releasing Zero-day. I mean look out for your loyal customers! If you're like me use Google Chrome...at least until the Zero-day issue with Internet Explorer is solved.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM