Microsoft
All current versions of Windows and Internet Explorer are affected by the flaw

Microsoft warns of web proxy flaw

Possible risk of 'man-in-the-middle' attack

Written by Shaun Nichols in California

Microsoft has reported a flaw in the way Windows and Internet Explorer handle web proxy auto discover (WPAD) connections.

WPAD servers are used to deliver connecting computers with web proxy information.
Microsoft said that the problem occurs when the WPAD servers for third-level domains (such as .co.uk) and deeper cannot be found. The user is then redirected to a WPAD server for a higher domain.

This can eventually lead the user to access a WPAD server outside the intended domain, possibly to one that has been compromised by a hacker.

All current versions of Windows and Internet Explorer are affected by the flaw, which was discovered by researcher Beau Butler. Microsoft has not received any reports of attacks targeting the vulnerability in the wild.

Users can mitigate the problem by disabling 'automatically detect settings' in Internet Explorer. Microsoft noted that users whose ISP uses a connection specific DNS suffix are not affected.

Sites which use a top-level domain, such as .com or .gov, are not at risk neither are those with a trusted WPAD server.

Microsoft said that it is investigating the issue, but did not say when a patch would be released. The company's next scheduled security update is on 11 December.

Tags:

Further reading

Microsoft puts spotlight on Silverlight

Major update planned for web-app builder next year   More...

Microsoft sends staff to Siberia

Presumably the ones who bought iPhones   More...

McAfee warns of typo-squatting epidemic

Old trick still haunting the web   More...

Domain Name System still at risk

Global DNS is 'as vulnerable as ever', reports Infoblox   More...

Related articles

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Vista updates headline Patch Tuesday

Three 'stability' fixes for latest Microsoft OS   More...

SQL attack hits thousands of sites

Automated bot program on the rampage   More...

Hackers eye open source coding tools

Security firm warns of 'cross-build injection vulnerability'   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement