Welcome | Sign In
TechNewsWorld.com
Exploits & Vulnerabilities

Microsoft Debuts IE8, Only to Have It Hacked

Print Version
E-Mail Article
Reprints
Microsoft Debuts IE8, Only to Have It Hacked

Microsoft introduced its new version of Internet Explorer on Thursday, touting its new security features such as the SmartScreen phishing filter. However, the new features weren't enough to keep a the browser from being hacked at the CanSecWest conference.


Tech Industry Paper - Finding Strength Through Customer Service
Poised to capitalize on an upturn in the economy, technology companies are focused on retention & service. This paper, from Convergys, provides the latest research on customer experience for B2B & B2C technology customers. Learn more.

Microsoft's (Nasdaq: MSFT) unveiling of Internet Explorer 8 on Thursday was marred by news that the browser, touted to be its most secure ever, already has been hacked.

The launch has also kicked off a new round of browser wars, with Google (Nasdaq: GOOG) unveiling a new beta of its Chrome browser, and Mozilla releasing Fennec, the mobile version of its Firefox browser, in beta.

IE8 was cracked at the 10th annual CanSecWest conference in Vancouver, Canada, Wednesday by a hacker who identified himself only as "Nils." To be fair, the first browser to go down at the hacking contest at CanSecWest was Apple's (Nasdaq: AAPL) Safari.

"Microsoft is investigating reports of a possible vulnerability in Internet Explorer 8," a Microsoft spokesperson said. "While we're not aware of any actual attacks using this possible vulnerability or of any customers affected, if the vulnerability is confirmed, we'll take action to help protect our customers."

Security and IE8

This is not the first time a security vulnerability has been discovered in IE8 --in February, Microsoft released a security bulletin for IE8.

Announcing IE8's release Thursday, Microsoft said it "offers leading-edge security features in direct response to people's increasing concerns about online safety," and quoted CEO Steve Ballmer as saying that IE8 "provides protection that no other browser can match."

Does that square with the facts? Probably, Jason Miller, security and data team manager at network security and patch management vendor Shavlik Technologies, told TechNewsWorld. "They have SmartScreen Filter, which they haven't had before, and there are reports that it's catching a lot of malware," he explained.

SmartScreen Filter is an extension of IE7's phishing filter. When a user visits a site that has been labeled harmful, IE8 will put up a warning and suggest the user not visit the site.

Still, all software has vulnerabilities and is prone to hacking, Miller said.

Browser Wars Reignite

IE8 has lots of nice new stuff. These include accelerators, a version of selection-based search that lets users invoke an online service from any other page using just the mouse. IE8 also has Web Slices, which are snippets of a page that a user subscribes to. The browser will automatically update the snippets, which users can view directly from the Favorites bar.

This could kick off a new round of browser wars, as other firms offering Web browsers have revved up their efforts recently.

Google has just unveiled a new beta of Google Chrome, which it claims in a blog is almost twice as fast as the original beta. It also has several new features, including form autofill, full page zoom and autoscroll, and lets the user drag tabs out to get a side-by-side view of Web pages.

Meanwhile, Mozilla rolled out the mobile version of its Firefox browser, called "Fennec." This has impressed reviewers at first sight because of the variety of features it offers.

More Trouble Coming?

The browser wars could lead to more security issues, Shavlik's Miller warns. "As you add new features, there will be new areas for vulnerabilities to exist," he said. "The more bloated these browsers get, the more areas there are to attack."

Miller predicts that hackers will unleash a torrent of attacks on IE8 over the next few weeks. "There's a lot of money in this for the hackers, and they'll want to find a way in."

The situation won't be helped by the fact that hackers are now targeting browsers more heavily. "Over the past couple of years, browsers have overtaken e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse as the area where users spend the most time, and attackers are putting out traps on Web sites," Paul Judge, chief technology officer at Web security application vendor Purewire, told TechNewsWorld.

"There's no shortage of vulnerabilities out there," Judge added.


Print Version E-Mail Article Reprints More by Richard Adhikari


Talkback: Join the Discussion.
IE8 Accelerators and KallOut Accelerators for Firefox
LeeLorenzen
Posted 2009-03-20
Richard, ...

More by Richard Adhikari

New Pogoplug Brings Mobile Devices Into the Cloud
November 20, 2009
The Pogoplug allows a user to run a personal cloud server from a home network. The data resides on hard drives and thumb drives that plug directly into the Pogoplug device; from there, the data can be accessed from anywhere via the Internet. Keep in mind that some ISPs forbid customers from hooking servers up to residential connections, though those rules are rarely enforced.
Google Spills Chrome OS' Guts
November 19, 2009
Google has made public the source code for its upcoming Chrome operating system. The OS will begin appearing on consumer-targeted netbooks next year. Chrome is built to live completely on the Web -- very little data is stored directly on the user's hard drive. This could make for much faster boot times and enhance security.
Cyberfraud Arrests Unlikely to Stem ZeuS Rampage
November 18, 2009
Two alleged cybercrooks have been nabbed in the UK on suspicion of using a well-know Trojan to commit banking fraud. The malware in question in known as "ZeuS" or "Zbot," and althought it's quite common, it's also sometimes difficult for antivirus applications to nail. Simple software kits exist online for relatively inexperienced hackers to create unique malware for the purpose of fraud.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network