SP2 security weakness
SP2 security weakness
R E L A T E D   C O N T E N T
ADVERTISEMENT

Researchers spot XP SP2 security weakness

IE drag and drop feature could be exploited by hackers

Iain Thomson, vnunet.com 20 Aug 2004
ADVERTISEMENT

Security researchers believe they have discovered a weakness in the new security given to Windows XP by the recently unveiled Service Pack 2 (SP2).

Since XP SP2 was released, activists have been searching for weaknesses in the security-focused service pack. Microsoft yesterday dismissed claims by German researchers to already have discovered a flaw.

Now a group has claimed that exploit code could bypass the new security procedures in XP by using the 'drag and drop' features of Internet Explorer.

In an advisory, consultant Secunia said researchers http-equiv had demonstrated that "the vulnerability is caused due to insufficient validation of drag-and-drop events issued from the 'Internet' zone to local resources.

"This can be exploited by a malicious website to e.g. plant an arbitrary executable file in a user's startup folder, which will get executed the next time Windows starts up."

But Microsoft believes that any hacker looking to exploit this issue would have to rely on considerable help from users.

The company said an attacker would need to first entice the user to visit a specific website and then entice them to drag and drop the malicious file in a specific location within that website.

"Given the significant amount of user action required to execute an attack, Microsoft does not consider this to be a high risk for customers," the firm said in a statement.

"Microsoft is not aware of any customer impact at this time. However, we will continue to investigate the issue to determine the appropriate course of action to protect our customers."

But Secunia argued that the flaw is "highly critical", as much of the work the user needs to follow could be masked into a single click.

"Even though the 'proof of concept' depends on the user performing a drag-and-drop event, it may potentially be rewritten to use a single click as user interaction instead," the consultant warned.

Meanwhile, Microsoft has published the first 'hotfix' for XP following the release of SP2, to deal with a loopback addressing problem.

A loopback address is a special internet protocol (IP) number (127.0.0.1) designated for the software loopback interface of a machine.

It allows IT professionals to test IP software without worrying about broken or corrupted drivers or hardware.

Microsoft is working towards a better patch for the problem, which showed up in Release Candidate versions of SP2.

See also:

IE open to hackersSecurity firm advises get another browser  11 Jan 2005
Windows XP SP2What IT managers need to know about XP SP2  15 Sep 2004
Alleged SP2 flawsNo plans to develop patches or workarounds for 'theoretical' holes  19 Aug 2004
Windows XP SP2XP Service Pack 2 provides some security improvements which users cannot afford to ignore, but some existing apps may need to be tweaked to run at their best  17 Aug 2004
Windows XP Service Pack 2We give you a guided tour of some of SP2's major new features.  17 Aug 2004

All Operating Systems

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Senior C# Agile Web Developer, Online Gaming, London My Client provides adult customers with high quality gambling and gaming services in an environment that is convenient, entertaining, fair, regulated and secure. My Client is one ... more >
| Aston Carter
EMC, NetApps, West London, Media • NetApps FAS ... more >
| Abraxas
Data Analyst / MI Analyst – Leading Online Gaming Company A Data Analyst / Trafficker is sought by a leading online gaming company. The role encompasses all aspects of online advertising including data handling, communicating ... more >
| JAM Recruitment
Field Applications Engineer Power Electronics/Supplies Europe/Based Surrey Permanent Position £35-45k Basic+Bonus 10-15%+Car/Car allowance A global organisation involved with the design and development of power supplies actively requires a Field Applications Engineer to strengthen it existing ... more >
More job opportunities