Cross-browser Firefox/IE flaw worsens

IM app used to launch attack

Written by Shaun Nichols in California

The browser flaw which allows attackers to hijack a computer by using Internet Explorer to launch Firefox is affecting other applications as well. 

Security researchers Nate McFeters, Billy Rios and Raghav Dube have disclosed information and working exploit code for a similar vulnerability in Trillian

Like the Firefox attack, the Trillian exploit uses a Uniform Resource Identifier (URI) function as the point of attack. 

The URI allows the browser to launch a third-party application on the user's system in much the same way that a URL is used to access a web page.

When the user visits a specially-crafted page, the application is launched and attack code is run to crash the application and execute code. The attack could be used to remotely install malware on a user's system.

The researchers claim that, while this attack only affects AIM clients, any application that allows for URI access could be targeted with similar attacks.

McFeters, Rios and Dube recommend that developers disable any unnecessary URI functions from their applications.

A Microsoft spokesperson told vnunet.com that the company is "investigating new public claims of a possible vulnerability in Internet Explorer" but would not elaborate further. 

Microsoft has not received reports of any attacks targeting the vulnerability.

Tags:

Further reading

Firefox attack uses Internet Explorer

Microsoft browser can pass on attack to rival   More...

Related articles

Firefox gets security tune-up

Flaws patched for versions 2 and 3   More...

Attackers take aim at IE7 flaw

Microsoft reports new URI attacks   More...

Security flaw hits MSN Messenger

Vulnerability puts users at risk of arbitrary code execution   More...

Microsoft comes clean on URI holes

Company vows to fix address handling flaw   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement