We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
80,259 News Articles

Warning over dangerous Internet Explorer bug

IE6 users open to keystroke-logging hack

An unpatched cross-site scripting bug in Internet Explorer 6 (IE6) could be used by hackers to capture keystrokes and steal other information, according to security researchers.

The vulnerability appears to be a variation of a vulnerability first discussed by researchers Manuel Caballero and Fukami at Microsoft's BlueHat security conference last month, Yichong Lin, an analyst at McAfee, said in an entry to the company's blog.

At BlueHat, Caballero, who has worked for Microsoft as an independent penetration tester, said he had found a way to capture every browser action, including keystrokes used to type passwords. In a videotaped interview that Microsoft conducted during BlueHat, Caballero said that the combination of Flash and any browser, not just IE, could be hacked with a malicious script to give attackers full access to the browser.

Details of the recent variant, as well as proof-of-concept code, were posted to a Chinese-language security e-zine by a group calling itself 'Ph4nt0m Security Team', according to another alert issued by the Danish vulnerability tracking firm Secunia.

Secunia outlined the threat: "The vulnerability is caused due to an input validation error when handling the 'location' or 'location.href' property of a window object. This can be exploited by a malicious website to open a trusted site and execute arbitrary script code in a user's browser session in context of the trusted site."

IE7, the current version of Microsoft's browser, does not contain the vulnerability, both Secunia and McAfee said. Until Microsoft produces a patch for the older browser, users should update to IE7, they added.

Yichong of McAfee said that the security company had notified Microsoft about the vulnerability. Microsoft representatives, however, did not immediately reply to a request for confirmation and additional comment.


IDG UK Sites

Very best Black Friday 2014 tech deals UK: Latest bargains on phones, tablets, laptops and more...

IDG UK Sites

Tech trends 2015: 3D printing grows up

IDG UK Sites

Will I be affected by VAT MOSS? Here are the facts for designers and artists

IDG UK Sites

Black Friday 2014 UK: Apple deals, Amazon deals & Black Friday tech offers